Market Manipulation. Search

Hijacked-account ramping

Hijacked-account ramping is using other people's brokerage accounts, accessed without their consent, to place buy orders that raise the price of a stock the perpetrator already holds, then selling into that price.

Also called account takeover ramp, account intrusion scheme, ATO manipulation. Observed in equities, options. One of the order-book manipulation techniques. 4 enforcement actions in the library.
Updated 2026-09-20

What is hijacked-account ramping, and where is the line?

Ramping means pushing a price up with buying. In this technique the buying is done with money that belongs to someone else, through an account the schemer has taken over without the holder’s knowledge.

The pattern in the SEC’s filings is consistent. The perpetrator holds, or takes a position in, a thinly traded stock. Other people’s brokerage accounts are then used to buy that stock. The purchases raise the price and the volume. The perpetrator sells into the higher price from an account of their own, often one opened in another name or another country.

The account holders are the first victims: their money was spent, without their decision, at a price that had been pushed up. Anyone else who traded against the raised price is the second group, and whether the record shows loss to that group is covered below.

What it is not. The line is drawn by what the intrusion is used for.

The order flow in these cases is real in the sense that trades actually execute. What is false is its origin: it looks like the independent decisions of many retail investors, and it is not. That places the technique in the order-book family, where the manipulation works through the pattern of orders rather than through a statement.

How does it work?

  1. Obtain access. The filings describe hacking into brokerage accounts. The SEC’s complaints do not, in the documents read for this page, set out a single method; how a schemer obtains log-in details is a question for the criminal cases and the brokers.
  2. Take a position. The perpetrator holds shares in the target before the buying starts, or, in the 2016 and 2017 matters, trades in the same stock through their own account at about the same time.
  3. Place the orders. Buy orders go in through the hijacked accounts, in stocks those account holders had not traded before. Low-volume stocks are targets because a modest amount of buying moves them.
  4. Sell into the price. The perpetrator sells from their own account at the raised price. In the SEC’s 2025 complaint against Kushnarev, alleged sales executed both against the forced purchases and against purchases by other participants who had no part in the scheme.
  5. Move the proceeds. The 2016 complaint alleges transfers from the trading account to a bank account in the defendant’s name; the 2017 SEC release describes converting proceeds into Bitcoin to pay another person.

Two variants appear in the record. In one, the hijacked accounts are also used to sell, to close the perpetrator’s short position (the 2025 complaint). In the other, the hijacked accounts are made to buy options the perpetrator sells at inflated prices, which the same complaint describes for 2019 to mid-2021.

How a hijacked account is used to raise a priceA flow from left to right on the top row and back on the bottom row. The perpetrator first obtains unauthorised access to other people's brokerage accounts. Through those accounts, buy orders are placed in a thinly traded stock in which the perpetrator already holds a position. The buying raises the price and the volume with no news behind it. The perpetrator sells the shares held beforehand at that raised price. The sales are filled by buyers, some of whom may be the hijacked accounts themselves and some of whom are ordinary market participants who trade at the raised price without knowing why it rose. accessorders placeddemandsell into itfilled by Compromiselog-in details or accessobtained Other people's accountsholders do not know Unauthorised buysin a thinly traded stock Price and volume riseno news behind it Perpetrator sellsshares held beforehand Other buyerstrade at the raisedprice
Compromise, orders, price, sale — and the point where ordinary buyers are drawn in.

What law applies?

None of the four SEC matters was brought under a statute written for account hijacking. The provisions cited are the general market-fraud ones.

Section 10(b) and Rule 10b-5 are the antifraud provisions the SEC cited in every one of the four matters. The SEC’s 2016 complaint against Mustapha cites Rule 10b-5(a) and (c), the parts that reach schemes and practices rather than statements.

Section 17(a) of the Securities Act is the parallel antifraud provision, cited across all four matters.

Section 9(a)(2) of the Exchange Act makes it unlawful to effect a series of transactions in a security that creates actual or apparent active trading or raises or depresses its price, for the purpose of inducing others to buy or sell. It was cited in the Willner judgment and in the 2025 complaint against Kushnarev; the 2022 release cites Section 9(a) against Mohamed without specifying the paragraph.

The Computer Fraud and Abuse Act, 18 U.S.C. § 1030, is the general federal computer-intrusion statute. The record read for this page does not state which counts underlie Willner’s guilty plea, which the SEC release describes as a plea to conspiracy to commit securities fraud and computer intrusions; the statute is listed here because it is the federal law on unauthorised computer access, not because those filings cite it.

Provisions most often charged
ProvisionCitationPrimary text
Securities Exchange Act Section 9(a)(2) — manipulation of security prices15 U.S.C. § 78i(a)(2) Read the text
Securities Exchange Act Section 10(b) and SEC Rule 10b-515 U.S.C. § 78j(b); 17 C.F.R. § 240.10b-5 Read the text
Securities Act Section 17(a) — fraud in the offer or sale of securities15 U.S.C. § 77q(a) Read the text
Computer Fraud and Abuse Act18 U.S.C. § 1030 Read the text

What does the record show?

Which real enforcement actions have alleged hijacked account ramping?

This library holds 4 enforcement actions tagged hijacked account ramping. The table shows the largest by civil penalty together with the most recently filed. Every row links to a page carrying the regulator's own release and, where one was published, the complaint.

Selected hijacked account ramping actions
Action Agency Filed Penalty Status
SEC v. Dmitrii Yevgenyevich Kushnarev (hijacked account ramping, 2025) SEC 2025-09-24 filed
SEC v. Rahim Mohamed, Davies ("Dave") Wong, et al. (hijacked account ramping, 2022) SEC 2022-08-15 filed
SEC v. Joseph P. Willner (hijacked account ramping, 2017) SEC 2017-10-30 judgment

All 4hijacked account rampingactions →

Four SEC matters in this library carry the tag. Dates below are those in the SEC’s own documents.

Idris Mustapha, 2016. The SEC’s complaint, filed 22 June 2016 in the Southern District of New York, alleges that Mustapha, a UK resident, hacked accounts of customers of U.S. and other brokers in April and May 2016 and traded the same stocks in his own account. It alleges profits of at least $68,000 and losses in victim accounts of at least $289,000. On 5 July 2016 the court granted a preliminary injunction and continued an asset freeze. That is the last event recorded in this library; the outcome of the case is not recorded here.

Joseph Willner, 2017 to 2020. The SEC’s October 2017 press release alleged access to the accounts of more than 100 victims and illicit profits of at least $700,000, with parallel criminal charges. The October 2020 release records a final consent judgment entered on 9 October 2020, an injunction against future violations, and disgorgement and interest of $418,581 deemed satisfied by the forfeiture and restitution orders in the criminal case. In that case, the release says, he pleaded guilty on 16 July 2019 and was sentenced on 28 February 2020.

Rahim Mohamed, Davies Wong and 16 others, 2022. The SEC’s complaint, filed 15 August 2022 in the Northern District of Georgia, names 18 defendants and two relief defendants. It alleges that hackers used at least 31 retail brokerage accounts in late 2017 and early 2018 to buy two microcap stocks, allowing holders of large blocks to sell at inflated prices and take more than $1 million. The library records this matter as filed; it does not record any judgment.

Dmitrii Kushnarev, 2025. The SEC’s complaint, filed 22 September 2025 in the same district, alleges an account-takeover scheme running from no later than March 2014 to at least May 2021, involving hundreds of U.S. and some Canadian accounts at no fewer than 10 brokerages and more than 380 securities, with approximately $31 million in gross proceeds and $1.5 million in net profit. The library records it as filed. The SEC’s release thanks the U.S. Attorney’s Office for the Northern District of Georgia and the FBI for assistance; it does not describe a criminal case.

What the record does not show. All four are cases the SEC chose to announce, and the library is not a sample of all account takeovers. Nothing here measures how common the conduct is. None of the four documents quantifies loss to counterparties other than the hijacked account holders. The Kushnarev complaint states that sales executed against purchases by uninvolved participants, but the extent of any resulting loss to them is not given in the documents read. Outside Willner’s consent judgment and his criminal outcome, every statement above is an allegation.

How is hijacked-account ramping detected?

Detection happens at two levels, and the record shows both.

At the broker. Orders that a customer has no history of placing, in stocks they have never held, from a new device or address, are the first sign. The 2016 complaint’s own example ties a victim’s unauthorised trades and the defendant’s own trades to the same computing device.

In market surveillance. Several unrelated accounts at one broker buying the same illiquid stock at once is a pattern that would be visible to a surveillance team across a firm and, with regulators’ data, across firms. The SEC’s release for the 2016 matter credits the Enforcement Division’s Center for Risk and Quantitative Analytics and the Division of Economic and Risk Analysis, and the 2022 and 2025 releases thank a long list of foreign regulators, which shows the trail crosses borders.

What penalties does hijacked account ramping actually attract?

The numbers below are computed from this site's own case records at build time, not quoted from a secondary source. They change whenever a new action is added to the library.

Actions recorded
4
Median penalty
Largest penalty
Criminal parallel
25%
Median sentence
6 months

Computed from 4enforcement actions in our own case library tagged hijacked-account-ramping , filed between 2016 and 2025. Median penalty covers the 0actions where a civil monetary penalty was disclosed; median sentence covers the 1 defendant who received a custodial term. Penalties exclude disgorgement and prejudgment interest, which are reported separately on each case page.

What are the red flags?

For an account holder, the red flags are ones the broker’s own log shows: a trade you did not place, in a stock you did not choose. For an investor buying a small stock, a sudden rise on no news is a warning that comes with no way of knowing the cause.

Why this technique is tagged separately

Because it has two aspects that pump-and-dump pages do not. There is an unauthorised-access element, so the first victims are people who took no part in the market at all. And the price effect is built from orders that look like independent retail demand, which is why the cases are brought as manipulation and not only as intrusion.

How do the records for hijacked account ramping end?

This describes the 4records in this library tagged hijacked account ramping, not how such cases end in the world. "Settled" is not a finding of guilt. Many records are filings whose outcome this library does not track: 3 of 4 are marked filed or unknown.

Too few records to show: status mix needs at least 5 records in this library, and there are4.

Other recorded outcomes, records in this library only
MeasureRecordsValue
Share with a criminal parallel4Too few records to show
Median civil penalty, where recorded0Too few records to show
Median months from filing to resolution1Too few records to show

Penalty and timing rows count only records where the figure or both dates are recorded; the count is shown beside each. Figures are computed at build time.

Frequently asked questions about hijacked-account ramping

What is hijacked-account ramping?
It is a scheme in which someone gains unauthorised access to other people's brokerage accounts, places buy orders through them in a stock the schemer already holds, and sells that stock into the higher price the orders created. The buyer whose money is used is not the person who chose the trade.
Is it the same as hack-to-trade?
No. Hack-to-trade steals information, such as unreleased press releases, and trades on it; hijacked-account ramping steals control of accounts and uses the orders those accounts place to move a price.
Is it the same as ordinary account takeover fraud?
No. Ordinary account takeover fraud is aimed at the money in the account, which is withdrawn or transferred. In ramping the account's buying power is the tool, and the profit is made in a different account that sells at the raised price.
Who are the victims?
The account holders whose money was used to buy at prices pushed up, and anyone who bought from or sold to the schemer at a price the orders had distorted. The SEC's 2016 complaint against Idris Mustapha alleges losses in the hijacked accounts; its 2025 complaint against Dmitrii Kushnarev alleges his sales also executed against purchases by uninvolved market participants.
Which law does the SEC use against it?
In the four matters in this library the SEC cited the antifraud provisions, Section 10(b) of the Exchange Act with Rule 10b-5 and Section 17(a) of the Securities Act. In three of them it also cited the manipulation provisions of Section 9(a) of the Exchange Act (Section 9(a)(2) in two of them).
Can it lead to prison?
Yes, in the criminal case parallel to one SEC action. The SEC's October 2020 release records that Joseph Willner pleaded guilty to conspiracy to commit securities fraud and computer intrusions and was sentenced to six months of incarceration. That is one recorded outcome, not a general rule.
Does a filed complaint mean the defendants did it?
No. A complaint states what the SEC alleges. Of the four matters here, only Willner's has a recorded judgment, entered by consent; the others are recorded as filed or as an injunction ruling, and nothing in the record shows a finding of liability against those defendants.
How can an investor protect an account?
By the ordinary controls: unique passwords, two-factor authentication where offered, and trade and log-in alerts. An unrecognised trade in a stock you have never held should be reported to the broker immediately.

Terms defined on this page

Account Takeover Attack · Ramping · Artificial Price · Section 9a2 · Criminal Parallel · Consent Judgment · Penny Stock

Sources

  1. SEC Litigation Release 23580: SEC sues UK-based trader for account intrusion scheme (June 23, 2016) — U.S. Securities and Exchange Commission
  2. SEC v. Mustapha, complaint (S.D.N.Y., June 22, 2016) — U.S. Securities and Exchange Commission
  3. SEC press release 2017-202: Day trader charged in brokerage account takeover scheme — U.S. Securities and Exchange Commission
  4. SEC Litigation Release 24947: final judgment against Joseph P. Willner (October 19, 2020) — U.S. Securities and Exchange Commission
  5. SEC Litigation Release 25469: 18 defendants charged over hacked brokerage accounts (August 16, 2022) — U.S. Securities and Exchange Commission
  6. SEC Litigation Release 26410: account takeover scheme involving U.S. brokerage accounts (September 24, 2025) — U.S. Securities and Exchange Commission
  7. SEC v. Kushnarev, complaint (N.D. Ga., September 22, 2025) — U.S. Securities and Exchange Commission
  8. Securities Exchange Act Section 9(a)(2), 15 U.S.C. § 78i — Legal Information Institute, Cornell Law School

Reviewed September 20, 2026. Every statute link points at the primary text. If something here is wrong, tell us — corrections are logged in public.