The Containment Era is here. →Explore

Executive Summary

In April 2026, Evan Tangeman, a 22-year-old from Newport Beach, California, was sentenced to 70 months in prison for laundering at least $3.5 million in stolen cryptocurrency. This was part of a larger criminal enterprise that, between October 2023 and May 2025, stole over $263 million through social engineering tactics, including impersonating customer support to gain access to victims' cryptocurrency wallets. The stolen funds financed extravagant lifestyles, with expenditures on luxury cars, high-end real estate, and lavish parties. (justice.gov)

This case underscores the growing sophistication of cybercriminals in exploiting social engineering techniques to execute large-scale financial thefts. It highlights the urgent need for enhanced security measures and user education to prevent such attacks, especially as the cryptocurrency market continues to expand and attract both legitimate investors and malicious actors.

Why This Matters Now

The sentencing of Evan Tangeman highlights the increasing prevalence and sophistication of social engineering attacks targeting cryptocurrency assets. As the digital currency market grows, individuals and organizations must remain vigilant against such schemes to protect their investments and maintain trust in the financial system.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The criminals employed social engineering tactics, such as impersonating customer support representatives, to trick victims into revealing access credentials to their cryptocurrency wallets.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Aviatrix Zero Trust CNSF is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate sensitive data by enforcing strict segmentation and controlled egress policies.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: While Aviatrix Zero Trust CNSF may not prevent initial user deception, it could limit the attacker's subsequent actions by restricting unauthorized access paths within the network.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Aviatrix Zero Trust Segmentation could likely restrict unauthorized access to sensitive resources, thereby limiting the attacker's ability to escalate privileges.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Aviatrix East-West Traffic Security could likely limit the attacker's ability to move laterally by enforcing strict controls on internal communications.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Aviatrix Multicloud Visibility & Control could likely detect and limit unauthorized remote access, thereby constraining the attacker's command and control capabilities.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Aviatrix Egress Security & Policy Enforcement could likely limit unauthorized data exfiltration by controlling outbound traffic.

Impact (Mitigations)

While Aviatrix Zero Trust CNSF may not prevent the laundering of stolen funds, it could likely limit the initial theft by restricting unauthorized access and data exfiltration.

Impact at a Glance

Affected Business Functions

  • Cryptocurrency Transactions
  • Customer Account Management
  • Financial Operations
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: $230,000,000

Data Exposure

Private keys and sensitive financial information of the victim, leading to unauthorized access and theft of cryptocurrency assets.

Recommended Actions

  • Implement multi-factor authentication (MFA) to prevent unauthorized access.
  • Utilize zero trust segmentation to limit lateral movement within systems.
  • Deploy egress security and policy enforcement to monitor and control outbound traffic.
  • Enhance threat detection and anomaly response capabilities to identify and respond to suspicious activities.
  • Educate users on recognizing and reporting social engineering attempts to reduce the risk of initial compromise.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image