Early Scattered Spider member pleads guilty to cybercrime spree
At a glance
- Severity
- Low
- Used in attacks
- No flaws named
- Hacker groups and malware
- Scattered Spider
- Reported by
- 1 outlet
Get our latest cybersecurity news first on Google.
Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday.
Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity theft. His guilty plea wasn’t shared publicly until prosecutors filed an order of forfeiture this week seeking proceeds from Elbadawy’s criminal activities.
Elbadawy and his co-conspirators — Noah Michael Urban, a Florida man sentenced to 10 years in prison last year, and Tyler Robert Buchanan, a Scottish man who pleaded guilty to multiple cybercrimes in April and awaits sentencing — were part of an aggressive subset of The Com coined Scattered Spider.
The financially-motivated crew obtained credentials via social engineering and stole sensitive company data to identify high net worth employees with virtual currency accounts containing millions of dollars, according to an indictment filed against Elbadawy and his co-conspirators in late 2024.
Federal authorities filed charges against five individuals with links to the Scattered Spider cybercrime outfit, including Elbadawy, Urban, Buchanan, Evans Onyeaka Osiebo and Joel Martin Evans in 2024.
Elbadawy’s victims included large businesses in the entertainment, telecom, technology, business process outsourcing, IT, cloud and virtual currency sectors, officials said. Prosecutors linked Elbadawy and his co-conspirators to at least 12 victim companies in the indictment, including three businesses located in Southern California where he awaits sentencing.
Authorities detailed 29 victims who were compromised by Elbadawy and his co-conspirators. The crew stole virtual currency from wallets controlled by many of those victims. The most high-value thefts included virtual currency worth nearly $6.35 million in September 2021, $571,000 in June 2022 and nearly $1.7 million in December 2022.
Prosecutors are seeking significant property and asset forfeiture from Elbadawy, including Bitcoin valued at more than $14.19 million, Ethereum valued at more than $3.4 million and nearly $63,000 in cash. Officials also requested the forfeiture of a lifted golf cart, three luxury vehicles, a painting of Muhammad Ali, luxury watches, gold jewelry, a vast collection of designer bags and 150 pairs of shoes.
The terms of Elbadawy’s plea agreement haven’t been released.
While early leaders of Scattered Spider have been arrested or sentenced for their crimes, others have filled those roles with even more exceptional impact.
The Com has grown to thousands of members, typically between 11 and 25 years old, splintered into three primary subsets the FBI describes as Hacker Com, In Real Life Com and Extortion Com.
Criminal acts committed by these multiple, interconnected networks include swatting, extortion and sextortion of minors, production and distribution of child sexual abuse material, violent crime and various other cybercrimes.
You can read the indictment against Elbadawy and some of his co-conspirators below.
Latest Podcasts
Government
CISA promotes a fresh way to deter cyberattackers: Lie to them
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
What’s next for CISA's CDM program that gives cybersecurity tools to federal agencies
Supreme Court denies Trump request to allow USPS mail ballot changes
Technology
Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The G7 tells industry to hurry up and prep for post-quantum encryption
FCC proposes public scorecard to rate telecoms on anti-robocall efforts
Threats
Authorities seize popular, long-running DDoS-for-hire service domains
Cisco warns customers of actively exploited zero-day in email gateways
Five alleged leaders of Black Axe’s operations in South Africa extradited to US
GitLab's critical flaw is already drawing internet-wide probes
Policy
Originally published by CyberScoop. © CyberScoop. Written by Matt Kapko.
Fastnexa security experts
Worried Scattered Spider could come after your company?
We test your defences the way groups like Scattered Spider actually break in, then help you close the gaps before they find them.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →
Coverage
One outlet has carried this so far.
2026-09-18 20:24 UTC
Related stories
- [Virtual Event] Cybersecurity Outlook 2027
Dark Reading · 2026-12-03
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · 2026-11-12
- [Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · 2026-10-08
- AI Agents Are Privileged Users; Who Is Auditing Their Access?
Dark Reading · 2026-09-28
- IAM for AI agents: A Practical Enterprise Framework
The Hacker News · 2026-09-28