Individual Who Compromised Over 1,000 Email Accounts At A New York City University Sentenced To 6 Months In Prison
Jonathan Powell, a 30-year-old from Phoenix, Arizona, was sentenced to six months in prison for computer fraud after exploiting a university’s password reset system to compromise over 1,000 email accounts and download sexually explicit content from linked personal accounts.
Jonathan Powell was sentenced to six months in prison for computer fraud after gaining unauthorized access to more than 1,000 email accounts at a New York City university by abusing its password reset utility. He used these compromised accounts to reset passwords for linked services—including iCloud, Gmail, Facebook, and LinkedIn—and downloaded sexually explicit photos and videos of students and affiliates. Powell attempted nearly 18,600 password changes across over 2,000 accounts, succeeded in compromising 1,035 university accounts, also breached 15 accounts at a second university, and admitted to targeting institutions in Arizona, Florida, Ohio, and Texas; he was ordered to pay $278,855 in restitution and serve two years of supervised release.
Jonathan Powell, a 30-year-old from Phoenix, Arizona, was sentenced to six months in prison for computer fraud after systematically exploiting the password reset utility of a New York City-area university to gain unauthorized access to over 1,000 student and affiliate email accounts between October 2015 and September 2016. Using these compromised accounts, he triggered password resets for linked services such as Apple iCloud, Google Gmail, Facebook, LinkedIn, and Yahoo!, intercepting reset emails to take control of those accounts and search for private, sexually explicit content. Records show he attempted approximately 18,600 password changes across 2,054 unique university accounts, successfully changing passwords for 1,035 accounts, with some accounts compromised multiple times. Powell also admitted to breaching 15 email accounts at a second university in Pennsylvania and additional institutions in Arizona, Florida, Ohio, and Texas. His actions were uncovered through forensic analysis of password reset logs and led to a federal investigation by the FBI. He pleaded guilty on August 9, 2017, and was sentenced on January 24, 2018, by Judge Alison J. Nathan in Manhattan federal court. In addition to his prison term, Powell was ordered to pay $278,855 in restitution and serve two years of supervised release, with the case prosecuted by the Southern District of New York’s Complex Frauds and Cybercrime Unit.
Extracted insights
- $279K $278,855 $100K–$1M
- person alison j. nathan
- person computer fraud
- person Geoffrey S. Berman
- person jonathan powell
- Jonathan Powell sentenced to six months in prison
- Jonathan Powell pled guilty to computer fraud
- Jonathan Powell compromised over 1,000 email accounts at New York City-area university
- Jonathan Powell obtained unauthorized access to email accounts hosted by University-1
- Jonathan Powell accessed password reset utility approximately 18,640 times
- Jonathan Powell downloaded sexually explicit photographs and videos
- Geoffrey S. Berman announced Jonathan Powell's sentencing
- Alison J. Nathan imposed Jonathan Powell's sentence
- Jonathan Powell pled guilty on August 9, 2017
- Jonathan Powell accessed unauthorized accounts from October 2015 to September 2016
Press Release Individual Who Compromised Over 1,000 Email Accounts At A New York City University Sentenced To 6 Months In Prison Thursday, January 25, 2018 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, announced that JONATHAN POWELL was sentenced yesterday to six months in prison for computer fraud in connection with his scheme to obtain unauthorized access to more than 1,000 email accounts maintained by a New York City-area university in order to download sexually explicit photos and videos. POWELL previously pled guilty to the charge on August 9, 2017, in Manhattan federal court before United States District Judge Alison J. Nathan, who also imposed POWELL’s sentence. U.S. Attorney Geoffrey S. Berman said: “Jonathan Powell used his computer skills to breach the security of a university to gain access to their students’ personal accounts. Once Powell had access, he searched the accounts for compromising photos and videos. No college student should have to fear that personal, private information could be mined by strangers for potentially compromising material.” According to the allegations in the Information to which POWELL pled guilty, a criminal complaint filed against POWELL and other filings made in the case, and statements made during the plea and other proceedings in the case: From October 2015 up to September 2016, POWELL obtained unauthorized access to email accounts hosted by a U.S.-based university, which has its primary campus in New York, New York (“University-1”). POWELL obtained unauthorized access to these accounts by accessing the password reset utility maintained by the email servers at Univeristy-1, which was designed to allow authorized users to reset forgotten passwords to accounts. POWELL utilized the password reset utility to change the email account passwords of students and others affiliated with University-1. Once POWELL gained access to the compromised email accounts (the “Compromised Accounts”), he obtained unauthorized access to other password-protected email, social media, and online accounts to which the Compromised Accounts were registered, including, but not limited to, Apple iCloud, Facebook, Google, LinkedIn, and Yahoo! accounts. Specifically, using the Compromised Accounts, POWELL requested password resets for linked accounts hosted by those websites (the “Linked Accounts”), resulting in password reset emails being sent to the Compromised Accounts, which allowed POWELL to change the passwords for the Linked Accounts. POWELL then logged into the Linked Accounts and searched within the Linked Accounts, gaining access to private and confidential content stored in the Linked Accounts. In one instance, POWELL searched a University-1 student’s linked Gmail account for digital photographs and for various lewd terms. The Government’s investigation ultimately revealed that POWELL accessed the Compromised and Linked Accounts in order to download sexually explicit photographs and videos of college-aged women. An analysis of University-1 password reset utility logs and other data revealed that POWELL accessed the University-1 password reset utility approximately 18,640 different times between October 2015 and September 2016. During that time, POWELL attempted approximately 18,600 password changes in connection with approximately 2,054 unique University-1 email accounts, and succeeded in making approximately 1,378 password changes in connection with approximately 1,035 unique University-1 email accounts, in some cases compromising the same email account multiple times. Additional investigation revealed that POWELL had also compromised 15 email accounts hosted by a second university located in Pennsylvania. In a post-arrest statement made to investigating agents, POWELL additionally admitted to compromising email accounts at several other educational institutions located in Arizona, Florida, Ohio, and Texas. * * * In addition to the prison term, POWELL, 30, Phoenix, Arizona, was sentenced to two years of supervised release and ordered to pay $278,855 in restitution. Mr. Berman praised the investigative work of the Federal Bureau of Investigation. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant United States Attorney Christopher J. DiMase is in charge of the prosecution. Updated January 25, 2018 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 18-025
Press Release Individual Who Compromised Over 1,000 Email Accounts At A New York City University Sentenced To 6 Months In Prison Thursday, January 25, 2018 Share FacebookLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. XLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. LinkedInLinks to other government and non-government sites will typically appear with the “external link” icon to indicate that you are leaving the Department of Justice website when you click the link. Email For Immediate Release U.S. Attorney's Office, Southern District of New York Geoffrey S. Berman, the United States Attorney for the Southern District of New York, announced that JONATHAN POWELL was sentenced yesterday to six months in prison for computer fraud in connection with his scheme to obtain unauthorized access to more than 1,000 email accounts maintained by a New York City-area university in order to download sexually explicit photos and videos. POWELL previously pled guilty to the charge on August 9, 2017, in Manhattan federal court before United States District Judge Alison J. Nathan, who also imposed POWELL’s sentence. U.S. Attorney Geoffrey S. Berman said: “Jonathan Powell used his computer skills to breach the security of a university to gain access to their students’ personal accounts. Once Powell had access, he searched the accounts for compromising photos and videos. No college student should have to fear that personal, private information could be mined by strangers for potentially compromising material.” According to the allegations in the Information to which POWELL pled guilty, a criminal complaint filed against POWELL and other filings made in the case, and statements made during the plea and other proceedings in the case: From October 2015 up to September 2016, POWELL obtained unauthorized access to email accounts hosted by a U.S.-based university, which has its primary campus in New York, New York (“University-1”). POWELL obtained unauthorized access to these accounts by accessing the password reset utility maintained by the email servers at Univeristy-1, which was designed to allow authorized users to reset forgotten passwords to accounts. POWELL utilized the password reset utility to change the email account passwords of students and others affiliated with University-1. Once POWELL gained access to the compromised email accounts (the “Compromised Accounts”), he obtained unauthorized access to other password-protected email, social media, and online accounts to which the Compromised Accounts were registered, including, but not limited to, Apple iCloud, Facebook, Google, LinkedIn, and Yahoo! accounts. Specifically, using the Compromised Accounts, POWELL requested password resets for linked accounts hosted by those websites (the “Linked Accounts”), resulting in password reset emails being sent to the Compromised Accounts, which allowed POWELL to change the passwords for the Linked Accounts. POWELL then logged into the Linked Accounts and searched within the Linked Accounts, gaining access to private and confidential content stored in the Linked Accounts. In one instance, POWELL searched a University-1 student’s linked Gmail account for digital photographs and for various lewd terms. The Government’s investigation ultimately revealed that POWELL accessed the Compromised and Linked Accounts in order to download sexually explicit photographs and videos of college-aged women. An analysis of University-1 password reset utility logs and other data revealed that POWELL accessed the University-1 password reset utility approximately 18,640 different times between October 2015 and September 2016. During that time, POWELL attempted approximately 18,600 password changes in connection with approximately 2,054 unique University-1 email accounts, and succeeded in making approximately 1,378 password changes in connection with approximately 1,035 unique University-1 email accounts, in some cases compromising the same email account multiple times. Additional investigation revealed that POWELL had also compromised 15 email accounts hosted by a second university located in Pennsylvania. In a post-arrest statement made to investigating agents, POWELL additionally admitted to compromising email accounts at several other educational institutions located in Arizona, Florida, Ohio, and Texas. * * * In addition to the prison term, POWELL, 30, Phoenix, Arizona, was sentenced to two years of supervised release and ordered to pay $278,855 in restitution. Mr. Berman praised the investigative work of the Federal Bureau of Investigation. The case is being prosecuted by the Office’s Complex Frauds and Cybercrime Unit. Assistant United States Attorney Christopher J. DiMase is in charge of the prosecution. Updated January 25, 2018 Topic Cybercrime Component USAO - New York, Southern Press Release Number: 18-025