Second “celebgate” hacker pleads guilty to phishing 300+ Gmail and iCloud accounts, faces 5 years; neither hacker was charged with distributing stolen content
A hacker has pleaded guilty for his role in the “Celebgate” breach of 2014. Edward Majerczyk faces up to five years …
Context & Ripple Effects
This plea closes out the charging phase of a case prosecutors have been assembling since early spring, when a Pennsylvania man was charged with hacking celebrity iCloud and Gmail accounts through the same phishing scheme. Majerczyk is the second defendant to admit his role, and his admission confirms the method behind the 2014 breach: credential phishing, not a platform exploit.
The scope matters here. The FBI had already put the damage at almost 600 breached iCloud accounts tied to the Celebgate hackers, and Majerczyk's guilty plea covers more than 300 Gmail and iCloud accounts on its own. Notably, neither he nor the other hacker was charged with distributing stolen content — the government's case rests entirely on unauthorized access.
First-order effects
- Majerczyk now faces up to five years in prison for phishing 300-plus Gmail and iCloud accounts, with sentencing to follow.
- Because neither hacker was charged with distributing stolen images, the prosecution establishes that accessing the accounts alone carries the criminal exposure — victims' recourse centers on the hacking counts, not on any redistribution charge.
Second-order effects
- Apple and Google face continued pressure to harden consumer accounts against social-engineering attacks, since the breach method was phishing emails rather than a flaw in iCloud or Gmail infrastructure itself.
- Prosecutors gain a working template: charge unauthorized access and identity theft while declining distribution counts when evidence of sharing is absent, which shapes how future cloud-account breach cases get pleaded.
Third-order effects
- If the pattern holds, credential phishing against consumer cloud storage becomes a recurring federal enforcement target rather than a one-off — a path the FBI was still pursuing years later when it charged a man who phished thousands of iCloud accounts by impersonating customer support.
- Sentencing outcomes across these cases will set de facto benchmarks for how heavily courts weigh large-scale account intrusion absent proof of content distribution, influencing both deterrence and how defendants negotiate pleas.
The trend: Consumer cloud accounts are increasingly compromised through impersonation and phishing rather than technical exploits, pushing prosecutions and platform security toward the human layer of authentication.