惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
云风的 BLOG
云风的 BLOG
人人都是产品经理
人人都是产品经理
T
The Blog of Author Tim Ferriss
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
J
Java Code Geeks
博客园 - 聂微东
B
Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
WordPress大学
WordPress大学
腾讯CDC
L
LangChain Blog
Apple Machine Learning Research
Apple Machine Learning Research
Microsoft Azure Blog
Microsoft Azure Blog
D
DataBreaches.Net
The GitHub Blog
The GitHub Blog
美团技术团队
博客园 - Franky
Google DeepMind News
Google DeepMind News
V
V2EX
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
月光博客
月光博客
The Cloudflare Blog

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court
Teenager alleged to be Scattered Spider hacker arrested i...
Graham CLULEY · 2026-05-04 · via Consumer Insights

Here's a tip for you all. Unless you want to draw attention to yourself as a cybercriminal, don't flaunt your diamond-encrusted "HACK THE PLANET" necklace on Snapchat, or pose as a Sopranos crime boss while the FBI is reportedly closing in.

Because if you do that, you'll only have yourself to blame for your poor operational security.

This is the picture that US prosecutors have painted of a teenager arrested earlier this month at Helsinki Airport while trying to board a flight to Tokyo.

The 19-year-old suspect - who allegedly went by the handle "Bouquet" - is accused of being an active member of the Scattered Spider cybercrime group, and now faces charges of wire fraud, conspiracy, and computer intrusion under a six-count federal complaint filed under seal in Chicago last December and recently obtained by the Chicago Tribune. The US is seeking his extradition.

Prosecutors allege that the teenage suspect took part in at least four Scattered Spider attacks , the earliest in March 2023 - just months after his 16th birthday. That first attack saw a textbook social engineering tactic deployed to reset a worker's 2FA protection, after which the attackers allegedly walked away with sensitive employee data.

A subsequent attack is alleged to have taken place in May 2025, when the gang targeted a "multibillion-dollar luxury item retailer" by phoning its IT help desk and impersonating staff to request password resets. Within hours, prosecutors say, they had compromised two privileged administrator accounts and exfiltrated 100 GB of corporate data.

The follow-up email reportedly had the subject line "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY [sic]" and demanded a US $8 million ransom. The retailer is said to have refused to pay up, although remediation costs allegedly exceeded US $2 million. Although the filings don't name the victim, the timing matches up with attacks against British retailers Marks & Spencer and Harrods.

It is claimed that "Bouquet" helped investigators build the case against him, by being anything but bashful about his wealth. Court documents detail trips between Dubai, Thailand, Mexico, and New York, alongside Snapchat photos of cash, watches, and the afore-mentioned "HACK THE PLANET" diamond chain.

The complaint also alleges that the Scattered Spider gang mocked law enforcement, with one 2024 screenshot reportedly showed failed login attempts captioned "F*** off, FBI."

Scattered Spider is a loosely-formed English-speaking collective of teenagers and young adults who became infamous after the 2023 attacks on MGM Resorts and Caesars Entertainment.

Their attack methodology shies away from fancy zero-day vulnerabilities, having discovered that it's simpler to make a phone call to an IT help desk, and talk someone on the other end into resetting a password or MFA token.

It's not been a great few weeks for alleged members of the Scattered Spider collective, with 24-year-old Brit Tyler Robert Buchanan pleading guilty in California recently to SMS phishing attacks that allegedly netted at least US $8 million in cryptocurrency.

Scattered Spider's success as hackers essentially relies upon one weak link - the IT help desk.

Make sure that your IT staff have a robust, mandatory process for verifying anyone who calls asking for a password reset or MFA change. In addition, ensure IT staff know that they won't get into trouble for slowing down a request, even if the caller claims to be the CEO.

You should also consider moving away from SMS-based MFA where you can, in favour of phishing-resistant alternatives like hardware security keys.

Test your own people regularly, because the attackers certainly will.