惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

MyScale Blog
MyScale Blog
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
L
LINUX DO - 热门话题
N
Netflix TechBlog - Medium
S
Schneier on Security
T
The Exploit Database - CXSecurity.com
Vercel News
Vercel News
P
Palo Alto Networks Blog
C
CERT Recently Published Vulnerability Notes
Simon Willison's Weblog
Simon Willison's Weblog
I
Intezer
L
Lohrmann on Cybersecurity
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
D
Darknet – Hacking Tools, Hacker News & Cyber Security
P
Proofpoint News Feed
The Register - Security
The Register - Security
T
Threat Research - Cisco Blogs
P
Privacy & Cybersecurity Law Blog
A
Arctic Wolf
F
Fortinet All Blogs
V
Vulnerabilities – Threatpost
The Hacker News
The Hacker News
V
Visual Studio Blog
Know Your Adversary
Know Your Adversary
博客园 - Franky
C
Check Point Blog
P
Privacy International News Feed
NISL@THU
NISL@THU
T
Tenable Blog
云风的 BLOG
云风的 BLOG
T
Tailwind CSS Blog
C
Cyber Attacks, Cyber Crime and Cyber Security
B
Blog RSS Feed
A
About on SuperTechFans
L
LangChain Blog
Cyberwarzone
Cyberwarzone
Security Latest
Security Latest
C
CXSECURITY Database RSS Feed - CXSecurity.com
G
Google Developers Blog
WordPress大学
WordPress大学
T
Threatpost
Y
Y Combinator Blog
Last Week in AI
Last Week in AI
The GitHub Blog
The GitHub Blog
爱范儿
爱范儿
T
Tor Project blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Spread Privacy
Spread Privacy

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty CISA, NCSC issue Firestarter backdoor warning 500k Biobank volunteers' data listed for sale on Alibaba Another npm supply chain worm hits dev environments France's 'Secure' ID agency probes breach as crooks claim 19M records France's 'Secure' ID agency probes claimed 19M record breach macOS ClickFix attacks deliver AppleScript stealers to snarf credentials, wallets macOS ClickFix attacks deliver AppleScript stealers Yet another ex-ransomware negotiator admits turning rogue after payoff from crimelords Third ransomware pro pleads guilty to cybercrime U-turn AI-assisted intruders pwned Vercel via OAuth abuse and a pilfered employee account AI-pwned: Vercel breach traced to stolen employee creds Crook claims to leak 'video surveillance footage' of companies Crook claims to leak 'video surveillance footage' of firms Adaptavist Group breach spawns imposter emails as ransomware crew claims mega-haul Adaptavist Group breach: Ransomware crew claims mega-haul Scot becomes second Scattered Spider-linked crook to plead guilty in US North Korea targets macOS users in latest heist McGraw Hill linked to 13.5M-record data leak McGraw Hill linked to 13.5M-record data leak Autovista blames ransomware for service disruption Autovista blames ransomware for service disruption No honor among thieves as 0APT threatens rival ransomware gang Krybit 0APT ransomware gang extorts Krybit amid doxxing threat Fake Linux leader using Slack to con devs into giving up their secrets Fake Linux Foundation leader using Slack to phish devs Booking.com warns of possible reservation data exposure Booking.com warns of possible reservation data exposure Gym giant Basic-Fit breached with at least 1M affected US, UK, Canadian cops disrupt $45M global crypto scam www.theregister.com Old Adobe Reader zero-day uses PDFs to size up targets Zephyr Energy loses £700K to contractor payment fraud Russia's Fancy Bear still attacking routers to boost fake sites, NCSC warns Russia's APT28 behind latest wave of router, DNS attacks AI recruiting biz Mercor says it was 'one of thousands' hit in LiteLLM supply-chain attack Mercor says it was 'one of thousands' hit in LiteLLM attack Telnyx package latest hit in PyPI supply-chain compromise Telnyx package latest hit in PyPI supply-chain compromise European Commission admits breach of public web systems European Commission admits breach of public web systems AFC Ajax drops ball as hackers transfer tickets, lift bans AFC Ajax drops ball as hackers transfer tickets, lift bans HackerOne slams supplier for delayed breach notice after staff data exposed HackerOne slams supplier over delayed breach notice Russian initial access broker jailed for 81 months in US Russian initial access broker jailed for 81 months in US Smooth criminals talking their way into cloud environments, Google says Chip tester shrugged off ransomware – then came the leak Chip tester shrugged off ransomware – then came the leak Russians posing as Signal support to launch phishing raids JLR cyber bailout risks dangerous precedent, watchdog warns Unknown attackers exploit yet another critical SharePoint bug Microsoft Intune: Lock it down, warn feds after Stryker Ransomware crims abused Cisco 0-day weeks before disclosure North Korea's 100,000-strong fake IT worker army rake in $500M a year for Kim Jong Un Robotics surgical biz Intuitive discloses phishing attack Cybercrime up 245% since the start of the Iran war AI-driven fraud far more profitable, Interpol warns Credential-stealing crew spoofs Ivanti, Fortinet, Cisco VPNs Interpol sinkholes 45,000 IPs linked to global cybercrime SocksEscort fraud-enabling proxy service taken down CISA warns max-severity n8n bug is being exploited in the wild Iran-linked cyber crew claims hit on US med-tech firm Meta, cops deploy AI and handcuffs in scam crackdown Dutch police collar teen over string of bank card frauds EU law advisor wants cybercrime protections fast-tracked Cybercrime isn't just a cover for Iran's government goons Crooks compromise WordPress sites, spread infostealers Ericsson breach blamed on third party vendor vishing attack Polish cyber police busts gang of alleged teen DDoS peddlers
US gets second Scattered Spider-linked guilty plea
Connor Jones Connor Jones · 2026-04-21 · via The Register - Security: Cyber-crime

Cyber-crime

Scot becomes second Scattered Spider-linked crook to plead guilty in US

Tyler Buchanan admits role in scheme that stole at least $8 million in virtual currency

A Scottish man linked to the Scattered Spider cybercrime crew has pleaded guilty in the US to a phishing and SIM-swap scheme that stole at least $8 million in cryptocurrency.

Tyler Robert Buchanan, 24, pleaded guilty in California to one count of conspiracy to commit wire fraud and one count of aggravated identity theft, and now faces a statutory maximum prison sentence of 22 years.

Originally from Dundee, the Scot was arrested in Palma airport in June 2024, and has been held in US custody since April 2025.

His identity was originally withheld from Spanish police reports, which only mentioned the arrest of a 22-year-old Brit with alleged ties to serious cybercrime, although many suspected Buchanan was the individual in question. 

Buchanan, who also went by aliases such as "Dread Pirate Roberts," "Evefan," and "tylerb," was formally identified after his extradition from Spain to the US in April last year.

Buchanan admitted to being part of the group that, between September 2021 and April 2023, defrauded at least a dozen US companies, their employees, and various individuals, too.

The Department of Justice (DoJ) did not identify this group as Scattered Spider specifically, although it is widely reported that Buchanan was a member during the specified period.

The Scot further admitted involvement in thefts totaling at least $8 million in virtual currency.

Together with the other alleged co-conspirators named in court documents [PDF], the gang is accused of stealing at least $11 million through a spate of cybercrimes during the year-and-a-half period.

Noah Michael Urban was the first Scattered Spider leader pleaded guilty in the US. He is currently serving a 10-year prison sentence handed to him in August 2025. 

Three others – Ahmed Hossam Eldin Elbadawy, 24, Evans Onyeaka Osiebo, 21, and Joel Martin Evans, 26 – still face criminal charges. All three are described as senior figures in the Scattered Spider operation.

SIM swappers, crypto thieves

The offenses described by the DoJ cover both Scattered Spider and Buchanan as an individual.

Scattered Spider's MO is well-known. They are known for carrying out sophisticated SIM swapping attacks to socially engineer their way into launching financially driven cyberattacks. 

The list of Scattered Spider's victims is enormous. They include MGM Resorts and Caesars Entertainment – both part of the great Las Vegas Casino ransomware attacks of 2023 – Transport for London, and the UK retail attacks of summer 2025. 

These attacks, the group's most notorious, were all carried out after Buchanan's involvement ended, per the timeline specified by the DoJ.

However, according to the official allegations, Buchanan, Elbadawy, Osiebo, and Urban had various responsibilities when it came to carrying out attacks.

In addition to carrying out the phishing schemes and computer intrusions, all four allegedly worked behind the scenes creating, managing, and paying for infrastructure, like domain names and copycat websites to support the phishing attacks. 

One example of the phishing messages sent to victims included warnings that their VPNs were about to expire, and to follow a link to ensure their service remained active. 

Others simply involved directing users to fake sites where their credentials were harvested and later used to compromise accounts.

The $8 million that Buchanan pleaded guilty to stealing came from individuals whose cryptocurrency wallets he raided while using data stolen from companies and Scattered Spider's familiar methods.

"Buchanan further admitted that he and several co-conspirators used the information stolen from company intrusions to identify and gain access to virtual currency accounts and wallets belonging to individual victims to steal millions of dollars' worth of virtual currency," the DoJ's announcement read.

"To gain access to individual victims' virtual currency wallets and accounts, and bypass two-factor authentication security features, Buchanan and others gained unauthorized access to victims' online accounts and conducted SIM swaps of victims' mobile telephone numbers to devices that the conspirators controlled."

In April 2023, police found evidence at Buchanan's Scotland residence of names and addresses of individuals, as well as a text file containing wallet seed phrases and the login details for one victim's account.

Buchanan is set to be sentenced on August 21, 2026. ®