Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →George Garofano was sentenced on August 29, 2018, to eight months in federal prison after pleading guilty to illegally accessing approximately 240 iCloud accounts during the credential-phishing campaign commonly called “Celebgate.” He was also ordered to serve three years of supervised release. His case was reported as the fourth—and apparently final—federal sentencing connected to the campaign.
What happened at sentencing
Garofano, who was 26 when sentenced, was expected to surrender to federal authorities in October 2018. The offense carried a statutory maximum of five years in prison. Prosecutors sought a sentence in the 10-to-16-month range, while his lawyer asked for less time.
The defense argued that Garofano was not the mastermind, that he was about 21 when the conduct occurred, and that he had matured and expressed remorse. Those were mitigation arguments from his lawyer, not a court finding that he played only a minor role. The judge imposed eight months, followed by three years of supervised release.
The sentence imposed is not necessarily the same as the time ultimately served, and eight months was not the maximum available penalty. The contemporary account is available from CyberScoop’s August 29, 2018 report.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minute#1 Best Overall
What Garofano pleaded guilty to
The prosecution centered on unauthorized access and theft, not on proof that Garofano personally published every image that later circulated online. He pleaded guilty in connection with illegally entering approximately 240 iCloud accounts using stolen usernames and passwords and taking personal information, including private photographs and videos. The account also says that, in some instances, credentials or stolen material were traded with others.
“Hacked 240 accounts” is a shorthand description. More precisely, the reported conduct involved obtaining credentials through phishing and then using them to access individual accounts without authorization. The available reporting does not establish a successful breach of Apple’s core infrastructure.
Rank #2
- A New True Crime Story Every Day – Discover a different true crime event for every day of the year. From infamous serial killers and unsolved disappearances to shocking murders, investigations, arrests, and courtroom verdicts, each page delivers a fascinating piece of true crime history tied to that specific date.
- Over 280 Real Cases Included – Explore more than 280 carefully researched true crime cases from the United States. Every page is designed to teach you something new, making this the perfect daily ritual for true crime fans, podcast listeners, and mystery lovers.
- The Perfect Gift for True Crime Lovers – Looking for a gift for the true crime obsessed person in your life? This unique desk calendar is a thoughtful gift for fans of true crime podcasts, documentaries, books, and criminal investigations.
- Undated for Year-Round Enjoyment – Start on any day of the year. The undated design includes all 366 days, including February 29th, so you can enjoy a full year of true crime content no matter when you begin.
- Stylish Desk Decor with a Purpose – Designed to look great on desks, bookshelves, countertops, and office spaces. The compact format and premium gold spiral binding make it both functional and aesthetically pleasing while delivering a new true crime discovery every day.
How the phishing campaign worked
The campaign operated approximately from April 2013 through October 2014. It relied primarily on social engineering rather than a demonstrated technical intrusion into Apple’s servers.
- Impersonation: Attackers sent messages made to look as if they came from Apple.
- Credential collection: Victims were induced to provide Apple usernames and passwords.
- Account access: The attackers used those credentials to enter victims’ iCloud accounts.
- Theft: They copied personal information, including intimate photographs and videos.
- Exchange and circulation: Credentials and, in some cases, stolen material were shared with others. Images later spread through online communities and sites including Reddit and 4chan.
That sequence matters legally and technically. Unauthorized access and theft were central to Garofano’s guilty plea; later public distribution could involve additional people and platforms. The fact that the victims included public figures does not make the conduct less unlawful, and it does not justify locating or sharing the stolen material.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
The four federal defendants
Garofano was the fourth publicly reported defendant sentenced in the federal cases arising from the credential-theft campaign.
| Defendant | Reported sentence | Case context |
|---|---|---|
| Ryan Collins | 18 months | Pleaded guilty; sentenced in 2017. |
| Edward Majerczyk | 9 months | Pleaded guilty; sentenced in 2017. |
| Emilio Herrera | 16 months | Pleaded guilty in 2018; illegally accessed more than 550 iCloud accounts. |
| George Garofano | 8 months | Pleaded guilty; sentenced August 29, 2018, with three years of supervised release. |
Contemporary coverage described Garofano’s sentencing as what appeared to be the final case in that four-defendant federal prosecution sequence. That wording does not establish that every person involved in the wider leak was identified or prosecuted.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why “Celebgate” is an incomplete description
“Celebgate” is a media label for the 2014 leak and the events surrounding it, not the name of a single technical breach. The reported prosecutions describe a campaign targeting individual accounts over many months. The public scandal was amplified by the rapid online spread of private images, but the underlying security failure was credential theft and account intrusion.
The case also illustrates why a stolen password can be enough to compromise an account. Reused passwords, convincing impersonation messages and the absence of an additional login factor can allow an attacker to bypass the account holder without deploying malware or exploiting Apple’s systems.
Security lessons for account holders
- Use a unique password for every email and cloud account.
- Turn on two-factor authentication or passkeys wherever the service offers them.
- Do not follow login links in unexpected messages; open the provider’s app or type its address yourself.
- Review account-access alerts and revoke unfamiliar sessions or devices.
- Report phishing attempts and preserve the message headers or URL for investigators instead of forwarding the lure.
The durable public-interest lesson is privacy protection and accountability: accessing an account with stolen credentials is criminal conduct, and redistributing private images compounds the harm regardless of a victim’s fame.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




