US charges five linked to Scattered Spider cybercrime gang

Share:

The U.S. Justice Department has charged five suspects believed to be part of the financially motivated Scattered Spider cybercrime gang with conspiracy to commit wire fraud.

Between September 2021 and April 2023, they were able to steal millions from cryptocurrency wallets using victims’ credentials stolen in SMS phishing attacks targeting dozens of targets, including both individuals and companies.

Scattered Spider specializes in social engineering attacks, impersonating help desk technicians, and using phishing/smishing attacks to steal credentials from targeted companies’ employees. In an attack on an interactive entertainment products and software company, the threat actors sent phishing messages that warned employees their VPN was being deactivated and to visit a site to reactivate it.

“WARNING!! Your [Victim Company 1] VPN is being deactivated, to keep your VPN active, please head over to [Victim Company 1]-vpn.net,” the phishing message said. Other phishing campaigns pretended to be password change notifications, prompting recipients to click a link if they did not change their password.

According to court documents, they also used credentials stolen from hacked companies’ employees to exfiltrate confidential data, including databases, “confidential work product, intellectual property, and personal identifying information” from their systems.

This information was later used to hijack their victims’ email accounts in SIM swap attacks that allowed them to gain control over their phone numbers and virtual currency wallets to transfer millions to wallets under their control.

These five suspects now face charges of wire fraud, wire fraud conspiracy, and aggravated identity theft:

  • Ahmed Hossam Eldin Elbadawy, 23, a.k.a. “AD,” of College Station, Texas;
  • Noah Michael Urban, 20, a.k.a. “Sosa” and “Elijah,” of Palm Coast, Florida;
  • Evans Onyeaka Osiebo, 20, of Dallas, Texas;
  • Joel Martin Evans, 25, a.k.a. “joeleoli,” of Jacksonville, North Carolina;
  • Tyler Robert Buchanan, 22, of the United Kingdom.

“We allege that this group of cybercriminals perpetrated a sophisticated scheme to steal intellectual property and proprietary information worth tens of millions of dollars and steal personal information belonging to hundreds of thousands of individuals,” said United States Attorney Martin Estrada in a Wednesday press release.

If convicted, each defendant faces up to 20 years in prison for conspiracy to commit wire fraud, five years for the conspiracy charge, and a mandatory two-year consecutive sentence for aggravated identity theft. Buchanan also faces up to 20 years for the wire fraud charge.

What is Scattered Spider?

Security vendors and organizations also track scattered Spider as 0ktapus, Scatter Swine, Octo Tempest, Starfraud, UNC3944, and Muddled Libra.

However, even though most think of it as a cohesive group, Scattered Spider is a loose-knit group of English-speaking threat actors, some as young as 16, with varied skill sets. They orchestrate various types of attacks and communicate using the same Telegram channels, Discord servers, and hacker forums.

Some Scattered Spider members are also believed to be part of the “Comm,” another hacking collective linked to cyberattacks and violent incidents. This fluid organizational structure makes it challenging for law enforcement to monitor their activities and to attribute specific attacks to a particular cybercrime gang or threat actor.

In a 2023 advisory, the FBI said they’re known for using various tactics to breach corporate networks, including social engineering, phishing, multi-factor authentication (MFA) bombing (targeted MFA fatigue), and SIM swapping.

Since the start of 2023, Scattered Spider has also partnered with several Russian ransomware gangs, including BlackCat/AlphV, Qilin, and RansomHub.

In July, UK police also arrested a 17-year-old suspect, believed to be a Scattered Spider hacking collective member who was involved in the 2023 MGM Resorts ransomware attack. Other high-profile attacks linked to this cybercrime gang include those on Caesars, DoorDash, MailChimp, Twilio, Riot Games, and Reddit.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
4:17 am, Jun 19, 2025
weather icon 17°C
L: 15° | H: 18°
clear sky
Humidity: 83 %
Pressure: 1024 mb
Wind: 1 mph W
Wind Gust: 1 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 4%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:42 am
Sunset: 9:20 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
15° | 18°°C 0 mm 0% 10 mph 79 % 1025 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
18° | 28°°C 0 mm 0% 11 mph 73 % 1025 mb 0 mm/h
Sat Jun 21 10:00 pm
weather icon
18° | 32°°C 1 mm 100% 11 mph 73 % 1020 mb 0 mm/h
Sun Jun 22 10:00 pm
weather icon
19° | 27°°C 0.8 mm 80% 13 mph 89 % 1014 mb 0 mm/h
Mon Jun 23 10:00 pm
weather icon
16° | 23°°C 0.36 mm 36% 14 mph 80 % 1015 mb 0 mm/h
Today 7:00 am
weather icon
17° | 18°°C 0 mm 0% 1 mph 79 % 1024 mb 0 mm/h
Today 10:00 am
weather icon
23° | 26°°C 0 mm 0% 1 mph 59 % 1025 mb 0 mm/h
Today 1:00 pm
weather icon
29° | 29°°C 0 mm 0% 2 mph 33 % 1024 mb 0 mm/h
Today 4:00 pm
weather icon
29° | 29°°C 0 mm 0% 8 mph 32 % 1023 mb 0 mm/h
Today 7:00 pm
weather icon
27° | 27°°C 0 mm 0% 10 mph 41 % 1024 mb 0 mm/h
Today 10:00 pm
weather icon
21° | 21°°C 0 mm 0% 7 mph 56 % 1025 mb 0 mm/h
Tomorrow 1:00 am
weather icon
19° | 19°°C 0 mm 0% 7 mph 68 % 1025 mb 0 mm/h
Tomorrow 4:00 am
weather icon
18° | 18°°C 0 mm 0% 5 mph 73 % 1024 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€91,350.56
-0.04%
Ethereum(ETH)
€2,193.81
0.11%
Tether(USDT)
€0.87
0.00%
XRP(XRP)
€1.88
0.07%
Solana(SOL)
€126.95
-1.31%
USDC(USDC)
€0.87
0.00%
Dogecoin(DOGE)
€0.148412
0.25%
Shiba Inu(SHIB)
€0.000010
-0.40%
Pepe(PEPE)
€0.000009
1.59%
Scroll to Top