U.S. prosecutors unsealed charges against five men allegedly linked to the Scattered Spider cybercrime ecosystem, accusing them of running a large-scale scheme that used SMS phishing, spoofed login pages, social engineering, stolen employee credentials, email hijacking, and SIM swapping to compromise companies and individuals. Court filings say the operation targeted technical employees across the United States between September 2021 and April 2023, enabling the theft of non-public corporate data, personal identifiers, and millions of dollars in cryptocurrency. Four suspects were charged in the United States with conspiracy to commit wire fraud, while a separate complaint was filed against a fifth defendant in the United Kingdom.
The case adds to mounting law-enforcement scrutiny of Scattered Spider, a loose English-speaking threat actor network also tracked under multiple aliases and associated with the broader "Com" ecosystem. Authorities and researchers have linked the group to high-profile intrusions and collaborations with ransomware operations including BlackCat/ALPHV, Qilin, and RansomHub, as well as incidents affecting MGM Resorts, Clorox, Snowflake-linked victims, and later investigations into the hacks at Marks & Spencer and Co-op. The charges mark a significant escalation in efforts to disrupt a group known for blending phishing, identity takeover, and extortion-focused intrusion tactics.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
Tyler Buchanan, a 24-year-old from Dundee, pleaded guilty in the United States to conspiring to hack at least a dozen companies and steal at least $8 million in cryptocurrency. The plea relates to the September 2021-April 2023 SMS phishing and credential-theft campaign previously described by U.S. prosecutors.
By May 2025, Scattered Spider had become a focus of a police investigation into hacks affecting Marks & Spencer and Co-op, marking a new publicly reported investigative development involving the group.
The U.S. Department of Justice announced charges against five alleged members or associates of the Scattered Spider cybercrime gang for wire-fraud-related conduct tied to the 2021-2023 phishing and cryptocurrency theft scheme. Four defendants were charged in the United States, and a separate complaint was filed against a fifth defendant in the United Kingdom.
A suspect was arrested in the United Kingdom in connection with the 2023 MGM Resorts ransomware attack, an action cited as part of increasing law-enforcement pressure on the Scattered Spider ecosystem.
Spanish police, working with the FBI, arrested a 22-year-old British national in Palma de Mallorca suspected of being a key Scattered Spider member. Authorities said the suspect was detained while trying to fly to Italy, seized a laptop and phone, and linked him to attacks on dozens of U.S. companies and individuals.
Prosecutors said the charged conspiracy ran through April 2023, by which time the defendants had allegedly stolen non-public corporate data, personal identifiers, and millions of dollars in cryptocurrency from victims across the United States.
According to U.S. court documents, individuals later charged as linked to Scattered Spider began a large-scale SMS phishing and social-engineering scheme targeting companies and individuals. The operation used spoofed login pages, stolen employee credentials, email hijacking, data theft, and SIM swapping to seize control of victims’ accounts and cryptocurrency wallets.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
6 references tracked. Mallory keeps watching after this page renders.
bbc.com
Open sourcebbc.com
Open sourcetechtarget.com
Open sourcecyberscoop.com
Open sourcebleepingcomputer.com
Open sourcesecurityaffairs.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.