Skip to main content
Security Policy

Scattered Spider cybercrime leader pleads guilty to $8M crypto theft

Scattered Spider cybercrime leader pleads guilty to $8M crypto theft Image: Primary
A British man identified as the leader of the Scattered Spider cybercrime collective has pleaded guilty in U.S. federal court to wire fraud and aggravated identity theft charges. Tyler Robert Buchanan, 24, admitted to participating in a scheme that stole at least $8 million in cryptocurrency by hacking more than a dozen companies between 2021 and 2023. The group targeted organizations across multiple industries including entertainment, telecommunications, technology, and cloud communications. Prosecutors said Buchanan and his accomplices conducted SMS phishing attacks, sending fraudulent text messages that appeared to come from legitimate company sources or IT suppliers. The messages contained links to phishing websites designed to steal login credentials and personal information. The hackers used stolen credentials to perform SIM swap attacks, hijacking victims' phone numbers to gain access to cryptocurrency wallets and transfer funds to accounts they controlled. Buchanan was arrested in Spain in June 2024 and transferred to U.S. custody in April 2025. He faces a maximum sentence of 22 years in prison when sentenced on August 21, 2026. Three other alleged members of the Scattered Spider collective face similar charges and up to 20 years in prison if convicted. A fourth conspirator, Noah Michael Urban, was sentenced to 10 years in prison last year after pleading guilty to wire fraud and conspiracy charges. Scattered Spider, also known by aliases including 0ktapus and Octo Tempest, is a loose-knit group of English-speaking hackers who coordinate attacks through Telegram channels, Discord servers, and online forums. The collective includes members as young as 16 and employs tactics including social engineering, phishing, multi-factor authentication bombing, and SIM swapping. According to the FBI, Scattered Spider has partnered with Russian ransomware gangs including BlackCat/AlphV and has been linked to high-profile breaches at companies including MGM Resorts, Caesars Entertainment, Riot Games, and Twilio. The guilty plea represents a significant development in law enforcement efforts to combat cybercrime collectives that use sophisticated social engineering techniques to bypass security measures. The case highlights ongoing challenges in protecting organizations from determined threat actors who exploit human vulnerabilities rather than technical weaknesses in systems.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Capital
Capital

Anthropic nears $15 billion revolver ahead of IPO filing

Anthropic is set to finalize an expansion of its revolving credit facility to $15 billion, according to people familiar with the matter cited by Bloomberg. Morgan Stanley is leading the process, with Goldman Sachs, JPMorgan Chase ...

Infrastructure
Infrastructure

Firmus commits $300 million for Australia-US cable capacity

Australian AI cloud firm Firmus will invest $300 million to secure up to 150Tbps of dedicated capacity for 25 years on SubCo's planned APX East submarine cable system. The 16-fiber-pair cable, first announced in January, is inten...

AI
AI

G42 explores majority US ownership to protect chip access

Abu Dhabi-based AI company G42 has held exploratory talks about potentially selling a majority stake to American companies, according to people familiar with the matter. The reported discussions are aimed at securing the company's...

Infrastructure
Infrastructure

Meta brings Kuna AI-optimized data center online

Meta's Kuna, Idaho, data center is now serving traffic, according to the company's data-center development vice president. The facility is Meta's second AI-optimized site to come online and represents an overall investment of $1.2...

Infrastructure Policy
Infrastructure Policy

Russia bans crypto mining in Moscow region through 2032

Russia's government has banned cryptocurrency mining and mining-pool participation in Moscow, the surrounding region and parts of Kursk through the end of 2032 under Government Decree No. 936. The measure is intended to reduce pre...

Security
Security

CrowdStrike investigates Falcon privilege-escalation zero-day

CrowdStrike is investigating a reported zero-day exploit, dubbed FalconFlank, that can let an attacker obtain SYSTEM privileges on fully updated Windows 11 and Windows Server systems running its Falcon endpoint platform. The expl...