U.S. prosecutors charged Kwamaine Jerell Ford, a 34-year-old Georgia man, with running a long-term social-engineering and account-takeover scheme that targeted NBA and NFL players by stealing their Apple/iCloud credentials and, in some cases, multifactor authentication codes. According to the indictment described by multiple reports, Ford allegedly impersonated a well-known adult film actress on social media to lure athletes into sharing access to their accounts, then used stolen financial and personal data to conduct unauthorized purchases and other fraud. Authorities say the activity ran from November 2020 through September 2024, involved more than 2,000 unauthorized transactions, and led to charges including wire fraud, computer fraud, access device fraud, aggravated identity theft, and sex trafficking; Ford has pleaded not guilty and is being held without bail.
The case is notable because prosecutors say Ford resumed similar criminal activity while still serving a sentence for an earlier phishing campaign that had also targeted athletes and celebrities. One report says evidence from seized devices showed he began phishing professional athletes again within days of being released to home confinement during the pandemic, while another says some of the alleged conduct occurred while he was still in federal prison. Prosecutors also allege the scheme escalated beyond financial theft: Ford is accused of coercing a woman into sexual encounters with several players, recording hidden videos, and hacking at least one victim's home security cameras. The reporting consistently portrays the operation as a repeat-offender credential theft and fraud campaign centered on compromised Apple accounts and social-engineering of high-profile sports figures.

Get the infrastructure and lures behind it.
8 events from the most recent confirmed update back to the earliest known activity.
Authorities arrested Ford in Atlanta after the new charges were brought. He pleaded not guilty and was ordered held without bail pending trial.
The U.S. Justice Department unsealed charges accusing Ford of wire fraud, computer-related offenses, access device fraud, aggravated identity theft and sex trafficking tied to the athlete-focused phishing scheme. The indictment alleges he stole Apple account credentials and abused them for financial fraud and other crimes.
The indictment says the unauthorized transactions tied to the athlete-targeting Apple account scheme continued through September 2024. This marks the latest specific end date described for the alleged fraud activity.
Using access to victims' Apple accounts, Ford allegedly stole financial and personal information and used linked payment cards for more than 2,000 unauthorized debit and credit card transactions. Prosecutors say this activity occurred over the course of the scheme.
According to prosecutors, Ford began a long-running social-engineering campaign targeting NBA and NFL athletes in which he impersonated a well-known adult film star and spoofed Apple customer support. The scheme sought victims' iCloud usernames, passwords and multifactor authentication codes.
Prosecutors allege Ford escalated beyond financial fraud by coercing an OnlyFans model into commercial sex acts with athletes, secretly recording encounters, and hacking a victim's home security cameras to steal private videos. These acts were presented as part of the broader criminal conduct in the indictment.
Authorities allege Ford carried out part of the phishing and account-takeover operation while incarcerated on the prior fraud case. Prosecutors said he later expanded the conduct after release to home confinement.
Before the newly alleged scheme, Kwamaine Jerell Ford had already been convicted and was serving a federal sentence for a similar fraud case involving athletes and celebrities. Prosecutors later said he resumed related criminal activity shortly after being released to home confinement.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
therecord.media
Open sourcecyberscoop.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.