The US Department of Justice has announced charges against five people believed to have been part of the Scattered Spider.

Between September 2021 and April 2023, these hackers managed to steal millions from cryptocurrency wallets, using credentials stolen in SMS phishing attacks. The group has targeted both individuals and companies.
Scattered Spider specializes in social engineering attacks, impersonation of customer service employees, and phishing/smishing attacks to steal credentials from employees of targeted companies.
In one attack, hackers sent phishing emails warning employees of the targeted company that their VPN had been disabled. The emails invited employees to visit a website to re-enable it.
See also: Scattered Spider hackers linked to Qilin ransomware attacks
Other phishing campaigns pretended to be password change notifications and urged recipients to click a link.
According to court documents, the Scattered Spider hackers also used credentials stolen from employees of previously compromised companies to access confidential data.
This data was later used to compromise victims' email accounts in SIM swap, which allowed them to gain control of phone numbers and virtual currency wallets.
Members of the Scattered Spider gang
The five suspects are charged with computer fraud, conspiracy to commit fraud and identity theft:
- Ahmed Hossam Eldin Elbadawy, 23, from Texas, also known as "AD"
- Noah Michael Urban, 20, from Florida, also known as “Sosa” and “Elijah”
- Evans Onyeaka Osiebo, 20, from Texas
- Joel Martin Evans, 25, from North Carolina, also known as “joeleoli”
- Tyler Robert Buchanan, 22 years old from the United Kingdom
"We allege that this group committed a sophisticated scheme to steal intellectual property and information worth tens of millions of dollars. They also stole personal information belonging to hundreds of thousands of individuals," said United States Attorney Martin Estrada.
A few words about the Scattered Spider hackers
Cybersecurity experts are tracking the Scattered Spider group under various names, including 0ktapus, Scatter Swine, Octo Tempest, Starfraud, UNC3944, and Muddled Libra.
This is a group of English-speaking hackers. Some of them are as young as 16. They orchestrate various types of attacks and communicate using Telegram channels, Discord servers, and hacking forums.
See also: Scattered Spider hackers collaborate with RansomHub
Some members of Scattered Spider are also believed to be part of “Comm,” another hacking group linked to cyberattacks and violent incidents. This fluid organizational structure makes it difficult for law enforcement to track its activities and attribute specific attacks to it.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Since early 2023, Scattered Spider hackers have collaborated with several Russian ransomware gangs, including BlackCat/AlphV, Qilin, and RansomHub.
In July, UK police arrested a 17-year-old suspect believed to be part of the group and involved in the ransomware attack on MGM Resorts (in 2023). Other attacks linked to this gang include those on Caesars, DoorDash, MailChimp, Twilio, Riot Games, and Reddit.
The charges against the five members of the Scattered Spider gang represent a significant step towards dismantling a dangerous cybercrime network. However, it is clear that more needs to be done to stay ahead of these ever-evolving threats.
See also: Critical Kubernetes vulnerability allows hackers to execute arbitrary code
The Scattered Spider gang is under investigation for a range of malicious activities, including data breaches, identity theft and ransomware attacks. These attacks increasingly target individuals and corporate entities. The defendants in this case allegedly employed simple and effective methods to infiltrate computer systems and steal sensitive information and money from victims.
The authorities emphasize the importance of such legal actions in preventing future cybercrimes and demonstrate their commitment to protecting citizens and businesses from online threats.
Source: www.bleepingcomputer.com
