Close Menu
Edu Expertise Hub
    Facebook X (Twitter) Instagram
    Friday, December 5
    • About us
    • Contact
    • Submit Coupon
    Facebook X (Twitter) Instagram YouTube
    Edu Expertise Hub
    • Home
    • Udemy Coupons
    • Best Online Courses and Software Tools
      • Business & Investment
      • Computers & Internet
      • eBusiness and eMarketing
    • Reviews
    • Jobs
    • Latest News
    • Blog
    • Videos
    Edu Expertise Hub
    Home » Latest News » Brit charged in US over Scattered Spider cyber attacks
    Latest News

    Brit charged in US over Scattered Spider cyber attacks

    TeamBy TeamNovember 21, 2024No Comments5 Mins Read0 Views
    Facebook Twitter Pinterest LinkedIn Telegram Tumblr Email
    Brit charged in US over Scattered Spider cyber attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email


    The United States’ Department of Justice (DoJ) yesterday unsealed criminal charges against five individuals, including a 22 year-old British national named as Tyler Robert Buchanan, over their alleged involvement in the Scattered Spider cyber attacks.

    During their criminal rampage, the gang used social engineering techniques to game their victims into giving up vital credentials, often relating to IT helpdesks. Most famously, they attacked two mainstays of the Las Vegas entertainment industry, Caesars Entertainment and MGM Resorts.

    Buchanan, who was arrested in June 2024 in Spain, faces charges of conspiracy to commit wire fraud, conspiracy, wire fraud, and aggravated identity theft. He was already on the authorities’ radar following a raid on his home in Scotland in 2023, in which police recovered evidence implicating him as a key player in the gang.

    The four US nationals named are: Ahmed Hossam Edin Elbadaway, aka AD, aged 23; Noah Michael Urban, aka Sosa and Elijah, aged 20; Evans Onyeaka Osiebo, aged 20; and Joel Martin Evans, aka joeleoli, aged 25.

    Evans was arrested on Tuesday 19 November in North Carolina, while Urban, who was arrested in a separate case earlier this year, is also in custody.

    Collectively, the men are charged with one count of conspiracy to commit wire fraud, one count of conspiracy, and one count of aggravated identity theft.

    “We allege that this group of cyber criminals perpetrated a sophisticated scheme to steal intellectual property and proprietary information worth tens of millions of dollars and steal personal information belonging to hundreds of thousands of individuals,” said US attorney Martin Estrada.

    “As this case shows, phishing and hacking has become increasingly sophisticated and can result in enormous losses. If something about the text or email you received or website you’re viewing seems off, it probably is.”

    Akil Davis, assistant director in charge of the FBI’s Los Angeles Field Office, added: “The defendants allegedly preyed on unsuspecting victims in this phishing scheme and used their personal information as a gateway to steal millions in their cryptocurrency accounts.

    “These types of fraudulent solicitations are ubiquitous and rob American victims of their hard-earned money with the click of a mouse. I’m proud of our stellar cyber agents whose work led to the identification of the alleged schemers who are facing significant prison time if convicted.”

    Each defendant faces a statutory maximum prison sentences of 27 years if convicted, while Buchanan faces an additional 20-year sentence for the wire fraud count.

    Inside Scattered Spider

    The documents unsealed this week reveal an extensive campaign of malicious activity beginning in late 2021 and running through 2023, although the gang continued to operate with a revised playbook until recently.

    The defendants are accused of conducting widespread phishing attacks using mass SMS messages to employees of targeted victims, purporting to come from the victim company or a contracted IT services supplier – often Okta, which the gang also relentlessly victimised, and for a time, it was also branded as 0ktapus.

    Frequently, these SMS messages stated that the employee’s account was about to be locked or deactivated, and “conveniently” provided a link to help them address this. Naturally, this link led in reality to a spoofed website in which the unwitting victims readily entered their login credentials, with many of them also authenticating their identities using multifactor authentication (MFA).

    These credentials obtained, Scattered Spider was able to access the accounts of victim companies’ employees and from there obtain deeper access into their victims’ IT systems, stealing confidential data and personally identifiable information (PII).

    At times, the gang also used ransomware on its victims, acting as an affiliate of the ALPHV/BlackCat operation.

    The authorities believe that Scattered Spider often used the data it obtained to gain unauthorised access to numerous cryptocurrency accounts and wallets, and may have stolen millions of dollars’ worth of virtual currency.

    Scattered Spider was able to be particularly effective against victims in the UK and US because its core members were native English speakers. This enabled them to appear more convincing in their messaging and interactions – compared with Russian speakers, who can frequently be unmasked thanks to various linguistic quirks, prominently the misuse or omission of the definite article when speaking English.

    The gang was also somewhat renowned for making threats of real-world retaliation against non-compliant victims, with people reporting that they were told they would lose their jobs, or face physically violent retribution against themselves and their families.

    “Rather than using basic email phishing, the attackers took things a step further to make their attack look more convincing,” said William Wright, CEO of Scotland-based Closed Door Security.

    “They tracked an employee on LinkedIn and then contacted an IT helpdesk worker requesting a password reset. Once the new password was secured, they then conducted an MFA fatigue attack which was enough to grant them with system access. The single attack was highly targeted, but its returns were immense. 

    “The attack highlighted that when it comes to social engineering, criminals have many tricks up their sleeves. To counter these threats, organisations must run security tests across their networks to identify weaknesses either among employees or digital architecture,” he said.

    Consequences

    “These individuals, and other actors who they have collaborated with, have caused so much pain and financial harm to organisations … through their disruptive intrusions,” said Charles Carmakal, chief technology officer at Google Cloud-owned Mandiant.

    “This is a nice win for law enforcement that over time has significantly hampered the group’s fast-paced tempo this year. We hope this sends a message to the other actors they collaborate with that they aren’t immune to consequences.”

    This post is exclusively published on eduexpertisehub.com

    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Team

      Related Posts

      4 ways AI can make your PD more effective

      December 5, 2025

      Constrained budgets left security teams short-handed in 2025

      December 4, 2025

      From fragmented to family-first: Our district’s communication reboot

      December 3, 2025

      UK prosecution of alleged Chinese spies was ‘shambolic’ says Parliamentary committee

      December 3, 2025

      Lack of Guidelines and Expertise Prove Challenging for AI Use in Schools

      December 2, 2025

      How one school reimagined learning spaces–and what others can learn

      December 2, 2025
      Courses and Software Tools

      Welcome to AI: A Human Guide to Artificial Intelligence

      March 20, 2024126 Views

      Extreme Privacy: What It Takes to Disappear

      August 24, 202481 Views

      Modern C++ Programming Cookbook: Master Modern C++ with comprehensive solutions for C++23 and all previous standards

      September 18, 202434 Views

      Meebook E-Reader M7 | 6.8′ Eink Carta Screen | 300PPI Smart Light | Android 11 | Ouad Core Processor | Out Speaker | Support Google Play Store | 3GB+32GB Storage | Micro-SD Slot | Gray

      August 19, 202429 Views

      HR from the Outside In: Six Competencies for the Future of Human Resources

      May 20, 202525 Views
      Reviews

      4 ways AI can make your PD more effective

      December 5, 2025

      The Power Of AI For Business Leaders: Efficient Strategies to Optimize Operations, Increase Customer Experience, Mitigate Risks, And Drive Unparalleled Growth and Profitability

      December 5, 2025

      Project Mastery: Bridging Processes, People, and Resources: A Competency-Based Guidebook Focused on Technical Project Management, Leadership, and Business … Based Books for Structured Learning)

      December 5, 2025

      RUST MADE EASY: A BEGINNER’S BLUEPRINT TO FAST, SAFE, AND MODERN SYSTEMS PROGRAMMING: MASTER THE BASICS OF RUST PROGRAMMING WITH REAL EXAMPLES AND ZERO EXPERIENCE REQUIRED

      December 5, 2025

      Marketing Metrics (Pearson Business Analytics Series)

      December 4, 2025
      Stay In Touch
      • Facebook
      • YouTube
      • TikTok
      • WhatsApp
      • Twitter
      • Instagram
      Latest News

      4 ways AI can make your PD more effective

      December 5, 2025

      Constrained budgets left security teams short-handed in 2025

      December 4, 2025

      From fragmented to family-first: Our district’s communication reboot

      December 3, 2025

      UK prosecution of alleged Chinese spies was ‘shambolic’ says Parliamentary committee

      December 3, 2025

      Lack of Guidelines and Expertise Prove Challenging for AI Use in Schools

      December 2, 2025
      Latest Videos

      FC 25 vs eFootball 2025 – Graphical Details, Player Animation – Comparison! #fc25 #efootball

      December 4, 2025

      Career Game #360: Devin Booker Scoring Highlights vs BOS (02/07/2021)

      December 3, 2025

      is the CISM REQUIRED for a CYBERSECURITY career?

      December 2, 2025

      Digital Marketing ad agency to build your career and learn digital marketing .

      December 1, 2025

      Why Choose CIMA? | Unlock Your Path to a Successful Finance Career

      November 29, 2025
      Latest Jobs

      Senior Associate, AI Data Scientist

      November 21, 2025

      Nursing Adjunct Faculty – Part-Time Nursing Instructors Needed

      November 21, 2025

      Sr. Firewall Engineer

      November 21, 2025

      Portfolio Analyst

      November 21, 2025

      Vehicle Service Specialist

      November 21, 2025
      Legal
      • Home
      • Privacy Policy
      • Cookie Policy
      • Terms and Conditions
      • Disclaimer
      • Affiliate Disclosure
      • Amazon Affiliate Disclaimer
      Latest Udemy Coupons

      ISO 9001:2015 – Quality Management System Internal Auditor | Udemy Coupons 2025

      May 5, 202537 Views

      Advanced Program in Human Resources Management | Udemy Coupons 2025

      April 5, 202536 Views

      Mastering Maxon Cinema 4D 2024: Complete Tutorial Series | Udemy Coupons 2025

      August 22, 202436 Views

      Diploma in Aviation, Airlines, Air Transportation & Airports | Udemy Coupons 2025

      March 21, 202531 Views

      Time Management and Timeboxing in Business, Projects, Agile | Udemy Coupons 2025

      April 2, 202527 Views
      Blog

      Thank-You Letter Template for Recommendation Letter: How to Express Gratitude

      December 4, 2025

      How to Track Products Without the Admin Overload –

      December 3, 2025

      How to Show Appreciation Effectively

      December 2, 2025

      Beyond Burnout: How to Thrive as a High Performer

      November 26, 2025

      Marketing Without Handcuffs: Grow in Regulated Industries

      November 21, 2025
      Facebook X (Twitter) Instagram Pinterest YouTube Dribbble
      © 2025 All rights reserved!

      Type above and press Enter to search. Press Esc to cancel.

      We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
      .
      SettingsAccept
      Privacy & Cookies Policy

      Privacy Overview

      This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
      Necessary
      Always Enabled
      Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
      Non-necessary
      Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
      SAVE & ACCEPT