Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
enforcement-actionphishing-campaign-intelligencevoice-social-engineeringcryptocurrency-platform-risk

US Charges Five Alleged Scattered Spider Members Over SMS Phishing and Crypto Theft

Updated 1mo agoFirst seen May 25, 20266 sources

U.S. prosecutors unsealed charges against five men allegedly linked to the Scattered Spider cybercrime ecosystem, accusing them of running a large-scale scheme that used SMS phishing, spoofed login pages, social engineering, stolen employee credentials, email hijacking, and SIM swapping to compromise companies and individuals. Court filings say the operation targeted technical employees across the United States between September 2021 and April 2023, enabling the theft of non-public corporate data, personal identifiers, and millions of dollars in cryptocurrency. Four suspects were charged in the United States with conspiracy to commit wire fraud, while a separate complaint was filed against a fifth defendant in the United Kingdom.

The case adds to mounting law-enforcement scrutiny of Scattered Spider, a loose English-speaking threat actor network also tracked under multiple aliases and associated with the broader "Com" ecosystem. Authorities and researchers have linked the group to high-profile intrusions and collaborations with ransomware operations including BlackCat/ALPHV, Qilin, and RansomHub, as well as incidents affecting MGM Resorts, Clorox, Snowflake-linked victims, and later investigations into the hacks at Marks & Spencer and Co-op. The charges mark a significant escalation in efforts to disrupt a group known for blending phishing, identity takeover, and extortion-focused intrusion tactics.

Share:
US Charges Five Alleged Scattered Spider Members Over SMS Phishing and Crypto Theft
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Apr 18, 20262mo ago

Tyler Buchanan pleads guilty in U.S. Scattered Spider-linked crypto theft case

Tyler Buchanan, a 24-year-old from Dundee, pleaded guilty in the United States to conspiring to hack at least a dozen companies and steal at least $8 million in cryptocurrency. The plea relates to the September 2021-April 2023 SMS phishing and credential-theft campaign previously described by U.S. prosecutors.

British man pleads guilty to conspiring to steal $8m in virtual currency
May 20, 20251y ago

Police investigate Scattered Spider over M&S and Co-op hacks

By May 2025, Scattered Spider had become a focus of a police investigation into hacks affecting Marks & Spencer and Co-op, marking a new publicly reported investigative development involving the group.

Nov 20, 20242y ago

U.S. unseals charges against five alleged Scattered Spider members

The U.S. Department of Justice announced charges against five alleged members or associates of the Scattered Spider cybercrime gang for wire-fraud-related conduct tied to the 2021-2023 phishing and cryptocurrency theft scheme. Four defendants were charged in the United States, and a separate complaint was filed against a fifth defendant in the United Kingdom.

Jul 19, 20242y ago

UK arrests suspect tied to MGM Resorts ransomware attack

A suspect was arrested in the United Kingdom in connection with the 2023 MGM Resorts ransomware attack, an action cited as part of increasing law-enforcement pressure on the Scattered Spider ecosystem.

Jun 17, 20242y ago

Spanish police arrest alleged Scattered Spider member in Mallorca

Spanish police, working with the FBI, arrested a 22-year-old British national in Palma de Mallorca suspected of being a key Scattered Spider member. Authorities said the suspect was detained while trying to fly to Italy, seized a laptop and phone, and linked him to attacks on dozens of U.S. companies and individuals.

Spanish police arrested an alleged member of the Scattered Spider group
Apr 30, 20233y ago

Scattered Spider-linked phishing and theft scheme ends

Prosecutors said the charged conspiracy ran through April 2023, by which time the defendants had allegedly stolen non-public corporate data, personal identifiers, and millions of dollars in cryptocurrency from victims across the United States.

Sep 1, 20215y ago

Scattered Spider-linked phishing and crypto theft campaign begins

According to U.S. court documents, individuals later charged as linked to Scattered Spider began a large-scale SMS phishing and social-engineering scheme targeting companies and individuals. The operation used spoofed login pages, stolen employee credentials, email hijacking, data theft, and SIM swapping to seize control of victims’ accounts and cryptocurrency wallets.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.