Alabama Man Sentenced for Orchestrating High-Profile SEC Twitter Hack to Spread False Bitcoin News
A federal judge sentenced Eric Council Jr., 26, of Huntsville, Alabama, to 14 months in prison on May 16, 2025, after he admitted to playing a central role in the breach of the U.S. Securities and Exchange Commission’s official X (formerly Twitter) account. In addition to the prison term, Council will serve three years of supervised release.
The breach, which unfolded in January 2024, stemmed from a complex SIM swapping operation that enabled the posting of a bogus message falsely claiming the SEC had approved Bitcoin exchange-traded funds (ETFs). The fake announcement caused immediate chaos in the crypto markets—briefly pushing Bitcoin prices up by more than $1,000 before crashing by over $2,000.
Council pled guilty in February 2025 to conspiracy charges involving identity theft and the unauthorized use of access devices. The scheme hinged on stolen personal data and a fraudulent SEC employee ID created using a mobile ID printer. This counterfeit credential allowed Council to impersonate an SEC staffer and deceive an AT&T worker into transferring control of a government-issued phone number to a SIM card under the attackers’ control.
This maneuver gave the perpetrators access to two-factor authentication codes, including those required to reset the SEC’s X account credentials. With the account compromised, the group published a tweet in the name of the SEC Chairman, triggering immediate market manipulation.
Investigators from the FBI later raided Council’s home in Athens, Alabama, recovering a trove of digital evidence: the fake ID printer, forged identification templates, and a laptop containing incriminating search history. He was arrested in October 2024.
As part of the sentencing, Council must also surrender $50,000, which prosecutors allege he received in Bitcoin as compensation for enabling the SIM swap.
The Department of Justice and federal officials underscored the significance of the case. “Cyberattacks that undermine the credibility of regulatory institutions and manipulate financial markets will be met with full prosecutorial force,” said Matthew R. Galeotti, head of the DOJ’s Criminal Division.
U.S. Attorney Jeanine Pirro warned that SIM swapping remains a growing threat not just to individuals but also to government systems, noting that those who exploit such vulnerabilities will be relentlessly pursued.
Although the SEC formally approved several Bitcoin ETFs the day after the attack, the incident raised alarms about the robustness of cybersecurity protections at one of the nation’s top financial regulators.
Security professionals say this case is a stark reminder of the risks associated with SMS-based two-factor authentication. To counter SIM swap threats, experts recommend using app-based authentication, adding carrier-level PINs, minimizing the public exposure of personal details, and regularly monitoring account activity for red flags.




