Hijacked-account ramping
Hijacked-account ramping is using other people's brokerage accounts, accessed without their consent, to place buy orders that raise the price of a stock the perpetrator already holds, then selling into that price.
What is hijacked-account ramping, and where is the line?
Ramping means pushing a price up with buying. In this technique the buying is done with money that belongs to someone else, through an account the schemer has taken over without the holder’s knowledge.
The pattern in the SEC’s filings is consistent. The perpetrator holds, or takes a position in, a thinly traded stock. Other people’s brokerage accounts are then used to buy that stock. The purchases raise the price and the volume. The perpetrator sells into the higher price from an account of their own, often one opened in another name or another country.
The account holders are the first victims: their money was spent, without their decision, at a price that had been pushed up. Anyone else who traded against the raised price is the second group, and whether the record shows loss to that group is covered below.
What it is not. The line is drawn by what the intrusion is used for.
- It is not hack-to-trade. That technique steals information and trades on it; this one steals control of accounts and uses the orders those accounts place to move the price.
- It is not ordinary account takeover fraud. There the account’s own cash or securities are the target, and the profit is the withdrawal. In ramping the account’s buying power is the instrument and the profit is realised elsewhere, in the perpetrator’s own account. Nothing need be withdrawn from the account; the loss is the price paid for shares bought at a raised price.
- It is not ramping by the promoter’s own accounts. A promoter who buys through accounts they control or nominate, to lift the price ahead of a sale, is doing something related but different, and the pump and dump and painting the tape pages cover it. Here the orders come from accounts whose holders never agreed to them, which is what adds an unauthorised-access element and a second set of victims.
The order flow in these cases is real in the sense that trades actually execute. What is false is its origin: it looks like the independent decisions of many retail investors, and it is not. That places the technique in the order-book family, where the manipulation works through the pattern of orders rather than through a statement.
How does it work?
- Obtain access. The filings describe hacking into brokerage accounts. The SEC’s complaints do not, in the documents read for this page, set out a single method; how a schemer obtains log-in details is a question for the criminal cases and the brokers.
- Take a position. The perpetrator holds shares in the target before the buying starts, or, in the 2016 and 2017 matters, trades in the same stock through their own account at about the same time.
- Place the orders. Buy orders go in through the hijacked accounts, in stocks those account holders had not traded before. Low-volume stocks are targets because a modest amount of buying moves them.
- Sell into the price. The perpetrator sells from their own account at the raised price. In the SEC’s 2025 complaint against Kushnarev, alleged sales executed both against the forced purchases and against purchases by other participants who had no part in the scheme.
- Move the proceeds. The 2016 complaint alleges transfers from the trading account to a bank account in the defendant’s name; the 2017 SEC release describes converting proceeds into Bitcoin to pay another person.
Two variants appear in the record. In one, the hijacked accounts are also used to sell, to close the perpetrator’s short position (the 2025 complaint). In the other, the hijacked accounts are made to buy options the perpetrator sells at inflated prices, which the same complaint describes for 2019 to mid-2021.
What law applies?
None of the four SEC matters was brought under a statute written for account hijacking. The provisions cited are the general market-fraud ones.
Section 10(b) and Rule 10b-5 are the antifraud provisions the SEC cited in every one of the four matters. The SEC’s 2016 complaint against Mustapha cites Rule 10b-5(a) and (c), the parts that reach schemes and practices rather than statements.
Section 17(a) of the Securities Act is the parallel antifraud provision, cited across all four matters.
Section 9(a)(2) of the Exchange Act makes it unlawful to effect a series of transactions in a security that creates actual or apparent active trading or raises or depresses its price, for the purpose of inducing others to buy or sell. It was cited in the Willner judgment and in the 2025 complaint against Kushnarev; the 2022 release cites Section 9(a) against Mohamed without specifying the paragraph.
The Computer Fraud and Abuse Act, 18 U.S.C. § 1030, is the general federal computer-intrusion statute. The record read for this page does not state which counts underlie Willner’s guilty plea, which the SEC release describes as a plea to conspiracy to commit securities fraud and computer intrusions; the statute is listed here because it is the federal law on unauthorised computer access, not because those filings cite it.
| Provision | Citation | Primary text |
|---|---|---|
| Securities Exchange Act Section 9(a)(2) — manipulation of security prices | 15 U.S.C. § 78i(a)(2) | Read the text |
| Securities Exchange Act Section 10(b) and SEC Rule 10b-5 | 15 U.S.C. § 78j(b); 17 C.F.R. § 240.10b-5 | Read the text |
| Securities Act Section 17(a) — fraud in the offer or sale of securities | 15 U.S.C. § 77q(a) | Read the text |
| Computer Fraud and Abuse Act | 18 U.S.C. § 1030 | Read the text |
What does the record show?
Which real enforcement actions have alleged hijacked account ramping?
This library holds 4 enforcement actions tagged hijacked account ramping. The table shows the largest by civil penalty together with the most recently filed. Every row links to a page carrying the regulator's own release and, where one was published, the complaint.
| Action | Agency | Filed | Penalty | Status |
|---|---|---|---|---|
| SEC v. Dmitrii Yevgenyevich Kushnarev (hijacked account ramping, 2025) | SEC | 2025-09-24 | — | filed |
| SEC v. Rahim Mohamed, Davies ("Dave") Wong, et al. (hijacked account ramping, 2022) | SEC | 2022-08-15 | — | filed |
| SEC v. Joseph P. Willner (hijacked account ramping, 2017) | SEC | 2017-10-30 | — | judgment |
Four SEC matters in this library carry the tag. Dates below are those in the SEC’s own documents.
Idris Mustapha, 2016. The SEC’s complaint, filed 22 June 2016 in the Southern District of New York, alleges that Mustapha, a UK resident, hacked accounts of customers of U.S. and other brokers in April and May 2016 and traded the same stocks in his own account. It alleges profits of at least $68,000 and losses in victim accounts of at least $289,000. On 5 July 2016 the court granted a preliminary injunction and continued an asset freeze. That is the last event recorded in this library; the outcome of the case is not recorded here.
Joseph Willner, 2017 to 2020. The SEC’s October 2017 press release alleged access to the accounts of more than 100 victims and illicit profits of at least $700,000, with parallel criminal charges. The October 2020 release records a final consent judgment entered on 9 October 2020, an injunction against future violations, and disgorgement and interest of $418,581 deemed satisfied by the forfeiture and restitution orders in the criminal case. In that case, the release says, he pleaded guilty on 16 July 2019 and was sentenced on 28 February 2020.
Rahim Mohamed, Davies Wong and 16 others, 2022. The SEC’s complaint, filed 15 August 2022 in the Northern District of Georgia, names 18 defendants and two relief defendants. It alleges that hackers used at least 31 retail brokerage accounts in late 2017 and early 2018 to buy two microcap stocks, allowing holders of large blocks to sell at inflated prices and take more than $1 million. The library records this matter as filed; it does not record any judgment.
Dmitrii Kushnarev, 2025. The SEC’s complaint, filed 22 September 2025 in the same district, alleges an account-takeover scheme running from no later than March 2014 to at least May 2021, involving hundreds of U.S. and some Canadian accounts at no fewer than 10 brokerages and more than 380 securities, with approximately $31 million in gross proceeds and $1.5 million in net profit. The library records it as filed. The SEC’s release thanks the U.S. Attorney’s Office for the Northern District of Georgia and the FBI for assistance; it does not describe a criminal case.
What the record does not show. All four are cases the SEC chose to announce, and the library is not a sample of all account takeovers. Nothing here measures how common the conduct is. None of the four documents quantifies loss to counterparties other than the hijacked account holders. The Kushnarev complaint states that sales executed against purchases by uninvolved participants, but the extent of any resulting loss to them is not given in the documents read. Outside Willner’s consent judgment and his criminal outcome, every statement above is an allegation.
How is hijacked-account ramping detected?
Detection happens at two levels, and the record shows both.
At the broker. Orders that a customer has no history of placing, in stocks they have never held, from a new device or address, are the first sign. The 2016 complaint’s own example ties a victim’s unauthorised trades and the defendant’s own trades to the same computing device.
In market surveillance. Several unrelated accounts at one broker buying the same illiquid stock at once is a pattern that would be visible to a surveillance team across a firm and, with regulators’ data, across firms. The SEC’s release for the 2016 matter credits the Enforcement Division’s Center for Risk and Quantitative Analytics and the Division of Economic and Risk Analysis, and the 2022 and 2025 releases thank a long list of foreign regulators, which shows the trail crosses borders.
- Orders placed in a customer's account from a new device or location, in a stock the customer has never traded.
- Several unrelated customer accounts at one firm buying the same thinly traded stock within minutes of each other.
- Buying that lifts a low-volume stock's price and volume with no news, followed by selling from a different account.
- A trading account whose sales in a stock repeatedly coincide with bursts of unrelated accounts buying it.
- The same device or network address appearing in both the hijacked accounts' log-ins and an outside trading account.
- Cash moved out of a trading account soon after the trades, toward a bank account or an intermediary.
What penalties does hijacked account ramping actually attract?
The numbers below are computed from this site's own case records at build time, not quoted from a secondary source. They change whenever a new action is added to the library.
- Actions recorded
- 4
- Median penalty
- —
- Largest penalty
- —
- Criminal parallel
- 25%
- Median sentence
- 6 months
What are the red flags?
For an account holder, the red flags are ones the broker’s own log shows: a trade you did not place, in a stock you did not choose. For an investor buying a small stock, a sudden rise on no news is a warning that comes with no way of knowing the cause.
- A holding, or a sale, in your account that you did not order, in a small or obscure stock.
- An alert of a log-in from a device or country you do not recognise, near the time of an unfamiliar trade.
- A thinly traded stock that jumps in price and volume with no announcement, and reverses soon afterwards.
- Repeated sharp moves in the same low-volume names that fade within hours or days.
Why this technique is tagged separately
Because it has two aspects that pump-and-dump pages do not. There is an unauthorised-access element, so the first victims are people who took no part in the market at all. And the price effect is built from orders that look like independent retail demand, which is why the cases are brought as manipulation and not only as intrusion.
How do the records for hijacked account ramping end?
This describes the 4records in this library tagged hijacked account ramping, not how such cases end in the world. "Settled" is not a finding of guilt. Many records are filings whose outcome this library does not track: 3 of 4 are marked filed or unknown.
| Measure | Records | Value |
|---|---|---|
| Share with a criminal parallel | 4 | Too few records to show |
| Median civil penalty, where recorded | 0 | Too few records to show |
| Median months from filing to resolution | 1 | Too few records to show |
Frequently asked questions about hijacked-account ramping
- What is hijacked-account ramping?
- It is a scheme in which someone gains unauthorised access to other people's brokerage accounts, places buy orders through them in a stock the schemer already holds, and sells that stock into the higher price the orders created. The buyer whose money is used is not the person who chose the trade.
- Is it the same as hack-to-trade?
- No. Hack-to-trade steals information, such as unreleased press releases, and trades on it; hijacked-account ramping steals control of accounts and uses the orders those accounts place to move a price.
- Is it the same as ordinary account takeover fraud?
- No. Ordinary account takeover fraud is aimed at the money in the account, which is withdrawn or transferred. In ramping the account's buying power is the tool, and the profit is made in a different account that sells at the raised price.
- Who are the victims?
- The account holders whose money was used to buy at prices pushed up, and anyone who bought from or sold to the schemer at a price the orders had distorted. The SEC's 2016 complaint against Idris Mustapha alleges losses in the hijacked accounts; its 2025 complaint against Dmitrii Kushnarev alleges his sales also executed against purchases by uninvolved market participants.
- Which law does the SEC use against it?
- In the four matters in this library the SEC cited the antifraud provisions, Section 10(b) of the Exchange Act with Rule 10b-5 and Section 17(a) of the Securities Act. In three of them it also cited the manipulation provisions of Section 9(a) of the Exchange Act (Section 9(a)(2) in two of them).
- Can it lead to prison?
- Yes, in the criminal case parallel to one SEC action. The SEC's October 2020 release records that Joseph Willner pleaded guilty to conspiracy to commit securities fraud and computer intrusions and was sentenced to six months of incarceration. That is one recorded outcome, not a general rule.
- Does a filed complaint mean the defendants did it?
- No. A complaint states what the SEC alleges. Of the four matters here, only Willner's has a recorded judgment, entered by consent; the others are recorded as filed or as an injunction ruling, and nothing in the record shows a finding of liability against those defendants.
- How can an investor protect an account?
- By the ordinary controls: unique passwords, two-factor authentication where offered, and trade and log-in alerts. An unrecognised trade in a stock you have never held should be reported to the broker immediately.
What techniques are related to hijacked-account ramping?
Terms defined on this page
Sources
- SEC Litigation Release 23580: SEC sues UK-based trader for account intrusion scheme (June 23, 2016) — U.S. Securities and Exchange Commission
- SEC v. Mustapha, complaint (S.D.N.Y., June 22, 2016) — U.S. Securities and Exchange Commission
- SEC press release 2017-202: Day trader charged in brokerage account takeover scheme — U.S. Securities and Exchange Commission
- SEC Litigation Release 24947: final judgment against Joseph P. Willner (October 19, 2020) — U.S. Securities and Exchange Commission
- SEC Litigation Release 25469: 18 defendants charged over hacked brokerage accounts (August 16, 2022) — U.S. Securities and Exchange Commission
- SEC Litigation Release 26410: account takeover scheme involving U.S. brokerage accounts (September 24, 2025) — U.S. Securities and Exchange Commission
- SEC v. Kushnarev, complaint (N.D. Ga., September 22, 2025) — U.S. Securities and Exchange Commission
- Securities Exchange Act Section 9(a)(2), 15 U.S.C. § 78i — Legal Information Institute, Cornell Law School