“Celebgate” hacker Ryan Collins sentenced to 18 months in prison after pleading guilty to federal hacking charges and admitting to a two-year phishing scam
Ryan Collins ran a two-year phishing scam to gain the passwords of more than 100 people, including Jennifer Lawrence, Rihanna and Avril Lavigne
Context & Ripple Effects
The sentencing closes an arc that began in March, when Collins was charged and admitted to phishing but prosecutors found no evidence he shared the stolen images — a fact that likely shaped the outcome. The 18-month term lands well below the five-year maximum faced by the second Celebgate hacker who phished 300+ Gmail and iCloud accounts, giving the first real sentencing data point within this case cluster.
It also slots into a wider run of federal credential-theft sentences: Marcel Lehel Lazar received 52 months weeks earlier, and the pattern has since extended abroad, from Joseph James O'Connor's five-year Twitter-hacking sentence to the UK student jailed over phishing kits tied to £100M of fraud.
First-order effects
- Collins begins an 18-month federal prison term after pleading guilty to hacking charges for a two-year phishing campaign that harvested passwords from more than 100 people, including Jennifer Lawrence, Rihanna and Avril Lavigne.
- Because prosecutors found no evidence Collins distributed the stolen content, his victims face the breach itself as the resolved harm rather than any public exposure flowing from it.
Second-order effects
- The gap between Collins's 18 months and the five-year exposure of the second Celebgate defendant gives that defendant's lawyers a concrete sentencing benchmark, while prosecutors gain a template for charging pure credential theft without distribution.
- Cloud account providers whose credentials were phished — iCloud and Gmail both appear across these cases — face continued pressure to harden password recovery flows, since every sentence here traces back to phishing rather than technical exploits.
Third-order effects
- If the sentencing ladder holds — 18 months for Collins, 52 months for Lazar, five years for O'Connor — US courts are establishing multi-year prison terms as the standard price of large-scale credential phishing, deterring individuals but not yet the tooling layer.
- The 2025 UK prosecution of a phishing-kit creator points to where enforcement is heading next: upstream from the hackers who use the tools to the people who build and sell them.
The trend: Courts on both sides of the Atlantic are escalating punishment for credential phishing, moving from jailing individual account thieves toward prosecuting the kit-makers who industrialize the technique.