Lam's co-conspirators, drawn from California, Connecticut, New York, Florida, and other countries, first connected with one another through online gaming platforms. The enterprise, which began no later than October 2023 and continued through at least May 2025, used social engineering and occasional home break-ins to obtain information that allowed members to drain victims' cryptocurrency wallets, the Justice Department said. In one case, two members of the alleged conspiracy impersonated Google $GOOGL and Gemini crypto exchange representatives to trick a Washington, D.C., resident into handing over security codes, enabling the group to drain more than 4,100 bitcoin from the victim's wallet, according to the Associated Press.