惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
量子位
腾讯CDC
A
About on SuperTechFans
小众软件
小众软件
Microsoft Azure Blog
Microsoft Azure Blog
T
Tailwind CSS Blog
V
V2EX
B
Blog RSS Feed
H
Hackread – Cybersecurity News, Data Breaches, AI and More
GbyAI
GbyAI
Recent Announcements
Recent Announcements
Microsoft Security Blog
Microsoft Security Blog
博客园 - 叶小钗
罗磊的独立博客
宝玉的分享
宝玉的分享
WordPress大学
WordPress大学
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家
V
Visual Studio Blog
D
DataBreaches.Net
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
有赞技术团队
有赞技术团队

The Register - Security: Cyber-crime

Election interlopers register 5K+ domains, hope to catch some voting phish Palo Alto VPN bug graduates from advisory to active exploitation ShinyHunters adds Charter to trophy shelf after 4.9M customer records leak Carnival confirms ShinyHunters cruised off with 6M customer records after April breach CrowdStrike, Google shatter Glassworm botnet MyPillow must decide whether to be firm or soft as ransomware crims demand pay A Russian speaker and jailbroken Gemini went on a hacking spree and emptied at least one MAGA victim's crypto wallets Shai-Hulud copycat worm infects yet another npm package Grafana Labs admits all its codebase are belong to someone who popped its GitHub account Nobody believes the 'criminals and scumbags' who hacked Canvas really deleted stolen student data Malware crew TeamPCP open-sources its Shai-Hulud worm on GitHub Foxconn confirms cyberattack after ransomware crew claims it stole confidential Apple, Nvidia files Cache-poisoning caper turns TanStack npm packages toxic 'CopyFail' attackers start cashing in on Linux flaw Cushman & Wakefield confirms vishing cyberattack ShinyHunters claims dump puts 119K Vimeo emails in the wild ShinyHunters claims 119K Vimeo emails in the wild Critical cPanel exploited: 'Millions' of sites could be hit Pro-Iran group turns Ubuntu DDoS into shakedown French prosecutors link 15-year-old to gov mega-breach UK business breach rate stuck at 43%... blame the phishing What type of 'C2 on a sleep cycle' do they leave behind? Novel Chinese spy group found in critical networks in Poland, Asia Chinese spy group caught lurking in Poland, Asia networks Don’t pay VECT a ransom - your big files are likely gone Pitney Bowes the latest victim of ShinyHunters’ breach-spree Ongoing supply-chain attack targets security, dev tools Medical and utility tech companies admit digital breakins Burglar alarm biz gets burgled, ShinyHunters pursues ransom Crime crew impersonates help desk, abuses Teams chats ShinyHunters claim they have cruise giant Carnival’s booty
US gets second Scattered Spider-linked guilty plea
Connor Jones Connor Jones · 2026-04-21 · via The Register - Security: Cyber-crime

Cyber-crime

Scot becomes second Scattered Spider-linked crook to plead guilty in US

Tyler Buchanan admits role in scheme that stole at least $8 million in virtual currency

A Scottish man linked to the Scattered Spider cybercrime crew has pleaded guilty in the US to a phishing and SIM-swap scheme that stole at least $8 million in cryptocurrency.

Tyler Robert Buchanan, 24, pleaded guilty in California to one count of conspiracy to commit wire fraud and one count of aggravated identity theft, and now faces a statutory maximum prison sentence of 22 years.

Originally from Dundee, the Scot was arrested in Palma airport in June 2024, and has been held in US custody since April 2025.

His identity was originally withheld from Spanish police reports, which only mentioned the arrest of a 22-year-old Brit with alleged ties to serious cybercrime, although many suspected Buchanan was the individual in question. 

Buchanan, who also went by aliases such as "Dread Pirate Roberts," "Evefan," and "tylerb," was formally identified after his extradition from Spain to the US in April last year.

Buchanan admitted to being part of the group that, between September 2021 and April 2023, defrauded at least a dozen US companies, their employees, and various individuals, too.

The Department of Justice (DoJ) did not identify this group as Scattered Spider specifically, although it is widely reported that Buchanan was a member during the specified period.

The Scot further admitted involvement in thefts totaling at least $8 million in virtual currency.

Together with the other alleged co-conspirators named in court documents [PDF], the gang is accused of stealing at least $11 million through a spate of cybercrimes during the year-and-a-half period.

Noah Michael Urban was the first Scattered Spider leader pleaded guilty in the US. He is currently serving a 10-year prison sentence handed to him in August 2025. 

Three others – Ahmed Hossam Eldin Elbadawy, 24, Evans Onyeaka Osiebo, 21, and Joel Martin Evans, 26 – still face criminal charges. All three are described as senior figures in the Scattered Spider operation.

SIM swappers, crypto thieves

The offenses described by the DoJ cover both Scattered Spider and Buchanan as an individual.

Scattered Spider's MO is well-known. They are known for carrying out sophisticated SIM swapping attacks to socially engineer their way into launching financially driven cyberattacks. 

The list of Scattered Spider's victims is enormous. They include MGM Resorts and Caesars Entertainment – both part of the great Las Vegas Casino ransomware attacks of 2023 – Transport for London, and the UK retail attacks of summer 2025. 

These attacks, the group's most notorious, were all carried out after Buchanan's involvement ended, per the timeline specified by the DoJ.

However, according to the official allegations, Buchanan, Elbadawy, Osiebo, and Urban had various responsibilities when it came to carrying out attacks.

In addition to carrying out the phishing schemes and computer intrusions, all four allegedly worked behind the scenes creating, managing, and paying for infrastructure, like domain names and copycat websites to support the phishing attacks. 

One example of the phishing messages sent to victims included warnings that their VPNs were about to expire, and to follow a link to ensure their service remained active. 

Others simply involved directing users to fake sites where their credentials were harvested and later used to compromise accounts.

The $8 million that Buchanan pleaded guilty to stealing came from individuals whose cryptocurrency wallets he raided while using data stolen from companies and Scattered Spider's familiar methods.

"Buchanan further admitted that he and several co-conspirators used the information stolen from company intrusions to identify and gain access to virtual currency accounts and wallets belonging to individual victims to steal millions of dollars' worth of virtual currency," the DoJ's announcement read.

"To gain access to individual victims' virtual currency wallets and accounts, and bypass two-factor authentication security features, Buchanan and others gained unauthorized access to victims' online accounts and conducted SIM swaps of victims' mobile telephone numbers to devices that the conspirators controlled."

In April 2023, police found evidence at Buchanan's Scotland residence of names and addresses of individuals, as well as a text file containing wallet seed phrases and the login details for one victim's account.

Buchanan is set to be sentenced on August 21, 2026. ®