Evan Tangeman, a 22-year-old from Newport Beach, California, was sentenced to 70 months in prison after pleading guilty to a RICO conspiracy tied to a cybercriminal network that stole roughly $230 million to $260 million in cryptocurrency from victims. Prosecutors said Tangeman laundered at least $3.5 million between October 2023 and May 2025 for the group, which allegedly stole more than 4,100 Bitcoin from a Washington, D.C., victim in August 2024 and used the proceeds to fund luxury homes, private jets, high-end vehicles, private security, and other lavish purchases.
Authorities said the organization, identified by law enforcement as the Social Engineering Enterprise, targeted wealthy cryptocurrency holders using stolen and dark-web-sourced data, spoofed phone numbers, impersonation of Google and Gemini support staff, and remote-access tools including AnyDesk to obtain Bitcoin Core private keys. Investigators alleged the group then obscured the proceeds through mixers, exchanges, peel chains, pass-through wallets, and VPNs, while Tangeman also helped rent properties under false identities and destroy devices after arrests of key members. Another alleged launderer, Kunal Mehta, has also pleaded guilty and is awaiting sentencing.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
10 events from the most recent confirmed update back to the earliest known activity.
On 2026-05-07, Marlon Ferro, also known as “GothFerrari,” was sentenced to 78 months in prison for participating in the cryptocurrency theft network. Prosecutors said he acted as a money launderer and carried out home burglaries to steal hardware wallets when remote fraud or hacking attempts failed; he was also ordered to pay $2.5 million in restitution.
On April 27, 2026, Tangeman was sentenced to 70 months in prison for laundering funds tied to the cryptocurrency theft enterprise. The sentence followed his guilty plea and admissions about helping conceal and spend stolen proceeds.
Evan Tangeman pleaded guilty in December 2025 to RICO conspiracy charges connected to laundering proceeds from the cryptocurrency theft enterprise. He admitted laundering at least $3.5 million in stolen cryptocurrency.
Another alleged money launderer, Kunal Mehta, pleaded guilty in November 2025 in the same broader case. He was reported to be awaiting sentencing.
Prosecutors said Tangeman's admitted laundering conduct continued through May 2025. His role included helping conceal operations and arranging luxury home purchases and rentals under false identities.
Authorities charged 14 suspects across September 2024 and May 2025 in a RICO conspiracy tied to the cryptocurrency theft and laundering scheme. Prosecutors alleged the network stole roughly $230 million to $260 million in cryptocurrency from victims.
According to prosecutors, several leaders of the organization were arrested in 2024. After those arrests, Tangeman allegedly ordered the destruction of devices and other evidence.
In August 2024, the group allegedly stole more than 4,100 Bitcoin from a Washington, D.C., victim. Authorities said the theft involved spoofed phone numbers, impersonation of Google and Gemini support, and AnyDesk access to obtain Bitcoin Core private keys.
Between October 2023 and May 2025, Evan Tangeman allegedly helped launder at least $3.5 million for the criminal enterprise. Prosecutors said the group used mixers, exchanges, peel chains, pass-through wallets, and VPNs to conceal proceeds.
Prosecutors said the criminal organization later dubbed the Social Engineering Enterprise was formed in 2023 by Malone Lam in Singapore. The group allegedly used stolen and dark-web-purchased databases to identify wealthy cryptocurrency holders for theft and fraud.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehelpnetsecurity.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.