Tech support phishing report VR-9FD8D72C
Investigator report
Filed by a vetted PublicAML investigator rather than by an anonymous reader. The account itself has not been independently re-checked.
The addresses below carry a risk label from this report.
- Type
- Phishing
- Reported as
- Tech support phishing
- Chain
- bitcoin
- Reported by
- DenysInvestigator
- Incident date
- Jun 19, 2026
- Published
- Sep 9, 2026
What happened
Theft address from a support-impersonation ("caller") operation exposed by ZachXBT on 10 August 2026. In June 2026 a victim lost $1.2M in Bitcoin and Ethereum. The group drained the victim's Trezor wallet after a spoofed BitcoinIRA email sent under the alias "Patricia Massie". The bitcoin leg of the theft went to this address: 6.9944 BTC arrived and left on 19 June 2026 across two transactions, and the address is now empty. Method: the actor phones victims posing as exchange or hardware-wallet support and talks them into surrendering access. ZachXBT published call recordings in which she taunts victims after draining them. Another actor operating as "bled"/"harm" appears to have supplied the phishing panel infrastructure. The investigation names Tiffany Milanovich, a US-based threat actor tied to at least $5M in thefts from hardware-wallet and centralised-exchange support impersonation. The Ethereum leg of the same June 2026 theft is 0x491333E8EA6f4fC2a2475DB01b649e1E4602ec3c, filed separately because this form takes one chain per report. Source: ZachXBT thread, https://x.com/zachxbt/status/2086785488149774411 (post 3/ names this address). Filed by PublicAML from public reporting, not by a victim of the incident.
Addresses named in this report
Named here and believe it is wrong? Open the address page above and use the flag on the assessment. Every dispute is read.
