Ahmed Hossam Eldin Elbadawy, a 24-year-old Texas resident and alleged early core member of Scattered Spider, pleaded guilty to federal wire-fraud-conspiracy charges tied to the group's extortion campaign. Court filings made public roughly a year after the plea seek forfeiture of more than $17 million in alleged criminal proceeds, including cryptocurrency and luxury assets.
Operating as a financially motivated subset of The Com, Scattered Spider used social engineering to obtain credentials, steal sensitive corporate data, and extort victims between 2021 and 2023. Prosecutors said Elbadawy and alleged associates Noah Michael Urban and Tyler Robert Buchanan targeted high-net-worth individuals—including virtual-currency holders—and organizations in entertainment, telecommunications, technology, and cryptocurrency-related sectors.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
Court records released publicly disclosed Elbadawy's guilty plea and prosecutors' effort to forfeit more than $17 million in cryptocurrency and luxury assets alleged to be criminal proceeds.
Ahmed Hossam Eldin Elbadawy, identified as an early core member of The Com and a participant in Scattered Spider activity, pleaded guilty to federal conspiracy-to-commit-wire-fraud charges. The plea occurred approximately one year before it was made public through later court records.
Scattered Spider, described as a financially motivated subset of The Com, began conducting social-engineering-based credential theft, corporate data theft, and extortion attacks. The group targeted high-net-worth individuals and companies in entertainment, telecommunications, technology, and virtual-currency sectors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.