UK police have arrested a 17-year-old hacker believed to have been involved in the 2023 ransomware attack on MGM Resorts and is a member of the Scattered Spider hacking group
See also: Scattered Spider hackers linked to Qilin ransomware attacks

" We have arrested a 17-year-old boy from Walsall in connection with a global cybercrime group targeting large organisations with ransomware and gaining access to computer networks ," West Midlands Police in the UK said in a statement
Officers from our West Midlands Regional Organised Crime Unit (ROCUWM) joined with officers from the National Crime Agency , in coordination with the United States Federal Bureau of Investigation (FBI) , to make the arrest on Thursday 18 July.
The teenager was arrested on suspicion of violating the Computer Extortion and Abuse Act and was later released on bail while police completed their investigation. Authorities have also seized digital devices from the suspect which will be searched for further evidence.
"We are proud to have assisted law enforcement in identifying and arresting one of the alleged criminals responsible for the cyberattack against MGM Resorts and many others," MGM said.
UK police say the arrest is part of a wider investigation being conducted by the National Crime Agency and the FBI into a hacking group known to breach networks, steal data and develop ransomware.
See also: Member of the Scattered Spider hackers arrested
Although not explicitly mentioned in the police statement, the hacking group behind the MGM attack is known as Scattered Spider.

The name “Scattered Spider” suggests a loose community of English-speaking malicious actors, with varying skills, who usually frequent the same Telegram, Discord servers and hacker forums. Some members are also believed to be part of “Comm” – another hacking group linked to violent acts and incidents in cyberspace.
Contrary to the general belief that Scattered Spider is a cohesive gang, it is actually a network of individuals with a large pool of malicious actors participating in different attacks.
This fluid structure makes it difficult for law enforcement to track them or attribute attacks to a specific cybercrime group.
Scattered Spider is also known as 0ktapus, Starfraud, UNC3944, Scatter Swine, Octo Tempest , and Muddled Libra.
In a 2023 FBI advisory, law enforcement described the hacking group's skills and tactics, which include social engineering, electronic phishing, multi-factor authentication (MFA) bombing, and SIM swapping, to breach corporate networks.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Over the past year, hackers in this "community" have taken the unusual approach of collaborating with Russian ransomware gangs, including BlackCat/AlphV, Qilin , and RansomHub.
See also: Scattered Spider hackers collaborate with RansomHub
Ransomware attacks, such as those by the Scattered Spider hacker group, have emerged as a significant threat to the digital landscape, targeting individuals, businesses, and government agencies. These malicious attacks typically involve the encryption of critical data by cybercriminals, who then demand a ransom payment for the decryption key. The impact of ransomware can be devastating, leading to operational disruptions, financial losses, and the potential for sensitive information to be compromised. Prevention strategies, including regular data backups, robust cybersecurity measures, and employee education, are essential to mitigate the risks associated with such attacks.
Source: bleepingcomputer
