Authorities say Buchanan and his co-conspirators impersonated companies and IT providers to trick employees into entering credentials on fake login pages, enabling access to corporate systems and sensitive data across sectors including technology, telecoms, cloud services, and outsourcing firms. The group then leveraged stolen information to target individual victims’ crypto accounts, bypassing two-factor authentication through SIM-swapping attacks that transferred control of victims’ phone numbers to devices under their control…