{"id":16060,"date":"2026-06-24T18:36:04","date_gmt":"2026-06-24T18:36:04","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=16060"},"modified":"2026-06-24T18:36:04","modified_gmt":"2026-06-24T18:36:04","slug":"scattered-spider-hackers-plead-responsible-on-day-1-of-trial-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=16060","title":{"rendered":"Scattered Spider Hackers Plead Responsible on Day 1 of Trial \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Two males pleaded responsible in the UK this week to legal expenses stemming from an August 2024 cyberattack that crippled <strong>Transport for London<\/strong>, the entity accountable for the general public transport community within the Larger London space. The duo have been key members of a prolific cybercrime group generally known as <strong>Scattered Spider<\/strong>, and their responsible pleas got here on the primary day of what was anticipated to be a six-week trial.<\/p>\n<div id=\"attachment_73881\" style=\"width: 760px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-73881\" decoding=\"async\" class=\" wp-image-73881\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/06\/flowers-jubair-nca.png\" alt=\"\" width=\"750\" height=\"421\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/06\/flowers-jubair-nca.png 926w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/06\/flowers-jubair-nca-768x431.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2026\/06\/flowers-jubair-nca-782x439.png 782w\" sizes=\"auto, (max-width: 750px) 100vw, 750px\"\/><\/p>\n<p id=\"caption-attachment-73881\" class=\"wp-caption-text\">Owen Flowers (left) 18, and Thalha Jubair, 20. Picture: UK Nationwide Crime Company (NCA).<\/p>\n<\/div>\n<p><strong>Thalha Jubair<\/strong>, 20, of East London and 18-year-old <strong>Owen Flowers<\/strong> of Walsall admitted conspiring to commit unauthorized acts towards Transport for London pc methods and inflicting danger of significant harm to human welfare. In response to <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.bbc.com\/news\/articles\/czx5yp9qy0do\" target=\"_blank\" rel=\"noopener\">a report<\/a> from the BBC, Flowers alone admitted to being a part of a conspiracy to hack into U.S. primarily based healthcare suppliers SSM Well being Care Company and Sutter Well being in September 2024.<\/p>\n<p>Jubair can also be needed by U.S. legislation enforcement businesses. In September 2025, prosecutors in New Jersey unsealed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.justice.gov\/opa\/pr\/united-kingdom-national-charged-connection-multiple-cyber-attacks-including-critical\" target=\"_blank\" rel=\"noopener\">an indictment<\/a> alleging Jubair and different Scattered Spider members dedicated pc fraud, wire fraud, and cash laundering in relation to 120 pc community intrusions involving 47 U.S. entities between Might 2022 and September 2025, and that the group\u2019s victims paid no less than $115 million in ransom funds.<\/p>\n<p>In July 2025, KrebsOnSecurity <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2025\/07\/uk-charges-four-in-scattered-spider-ransom-group\/\" target=\"_blank\" rel=\"noopener\">reported<\/a> that Flowers and Jubair have been arrested in the UK in reference to Scattered Spider <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.thetimes.com\/uk\/technology-uk\/article\/ransoms-hackers-cyber-crime-t5kjldwwm\" target=\"_blank\" rel=\"noopener\">ransom assaults<\/a>\u00a0towards the retailers\u00a0<strong>Marks &amp; Spencer<\/strong>\u00a0and\u00a0<strong>Harrods<\/strong>, and the British meals retailer\u00a0<strong>Co-op Group<\/strong>. A number of sources aware of these investigations mentioned Flowers was the Scattered Spider member who anonymously <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2024\/09\/the-dark-nexus-between-harm-groups-and-the-com\/\" target=\"_blank\" rel=\"noopener\">gave interviews to the media<\/a> within the days after the group\u2019s September 2023 ransomware assaults disrupted operations at Las Vegas casinos operated by <strong>MGM Resorts<\/strong>\u00a0and\u00a0<strong>Caesars Leisure<\/strong>.<\/p>\n<p>In response to prosecutors, Jubair co-ran a bustling Telegram channel known as <strong>Star Chat<\/strong>, the house of a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/?s=SIM-swapping\" target=\"_blank\" rel=\"noopener\">SIM-swapping<\/a> group that used voice- and SMS-based phishing assaults to steal credentials from staff on the main wi-fi suppliers within the U.S. and U.Ok. The group would then use that entry to promote a service that would redirect a goal\u2019s telephone quantity to a tool the attackers managed and intercept the sufferer\u2019s calls and textual content messages (together with one-time codes for multi-factor authentication).<\/p>\n<div id=\"attachment_72238\" style=\"width: 819px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-72238\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-72238\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/rocketace-tmobile.png\" alt=\"\" width=\"809\" height=\"915\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/rocketace-tmobile.png 809w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/rocketace-tmobile-768x869.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/rocketace-tmobile-782x884.png 782w\" sizes=\"auto, (max-width: 809px) 100vw, 809px\"\/><\/p>\n<p id=\"caption-attachment-72238\" class=\"wp-caption-text\">A receipt from Star Fraud Chat\u2019s SIM-swapping service focusing on a T-Cellular buyer after the group gained entry to inside T-Cellular worker instruments. \u201cRocket Ace\u201d was one in all Jubair\u2019s hacker handles, in keeping with U.S. prosecutors.<\/p>\n<\/div>\n<p>New Jersey prosecutors additionally allege Jubair additionally was concerned in a <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2022\/08\/how-1-time-passcodes-became-a-corporate-liability\/\" target=\"_blank\" rel=\"noopener\">mass SMS phishing marketing campaign in the course of the summer time of 2022<\/a> that stole single sign-on credentials from staff at a whole bunch of corporations.\u00a0That weeks-long SMS phishing marketing campaign led to intrusions and knowledge thefts at greater than 130 organizations, together with <strong>LastPass<\/strong>,\u00a0<strong>DoorDash<\/strong>,\u00a0<strong>Mailchimp<\/strong>,\u00a0<strong>Plex<\/strong>\u00a0and\u00a0<strong>Sign<\/strong>.<span id=\"more-73876\"\/><\/p>\n<p>KrebsOnSecurity reported final 12 months that one in all Jubair\u2019s alter egos at age 15 was \u201c<strong>Everlynn<\/strong>,\u201d a hacker who bought <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/?s=fake+edr\" target=\"_blank\" rel=\"noopener\">fraudulent \u201cemergency knowledge requests\u201d<\/a> that used compromised police and authorities electronic mail addresses to demand subscriber knowledge (e.g. username, IP\/electronic mail deal with) from main tech corporations, claiming the requests involved pressing issues of life and demise and couldn&#8217;t watch for a courtroom order.<\/p>\n<p>In April 2026, 24-year-old British nationwide and Scattered Spider member <strong>Tyler \u201cTylerb\u201d Buchanan<\/strong> <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2026\/04\/scattered-spider-member-tylerb-pleads-guilty\/\" target=\"_blank\" rel=\"noopener\">pleaded responsible<\/a> to wire fraud conspiracy and aggravated identification theft for taking part within the group\u2019s SMS phishing spree in the summertime of 2022. The federal government mentioned Buchanan, Jubair and others used the credentials harvested in that phishing marketing campaign to steal no less than $8 million in cryptocurrency from victims all through the US. Buchanan is at present scheduled to be sentenced on October 2.<\/p>\n<p>In August 2025, 20-year-old Scattered Spider member from Florida named <strong>Noah Michael City<\/strong> was <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2025\/08\/sim-swapper-scattered-spider-hacker-gets-10-years\/\" target=\"_blank\" rel=\"noopener\">sentenced to 10 years in federal jail<\/a> and ordered to pay $13 million in restitution, after pleading responsible to expenses of wire fraud and conspiracy.<\/p>\n<p>The U.S. Division of Justice says three alleged Scattered Spider defendants indicted together with Buchanan nonetheless face expenses, together with <strong>Ahmed Hossam Eldin Elbadawy<\/strong>, 24, a.ok.a. \u201cAD,\u201d of Faculty Station, Texas; <strong>Evans Onyeaka Osiebo<\/strong>, 21, of Dallas, Texas; and <strong>Joel Martin Evans<\/strong>, 26, a.ok.a. \u201cjoeleoli,\u201d of Jacksonville, North Carolina.<\/p>\n<p>Flowers and Jubair are slated to be sentenced in a London courtroom on July 15, 2026.<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Two males pleaded responsible in the UK this week to legal expenses stemming from an August 2024 cyberattack that crippled Transport for London, the entity accountable for the general public transport community within the Larger London space. The duo have been key members of a prolific cybercrime group generally known as Scattered Spider, and their [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":16062,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[697,486,554,262,6496,2075,211,2076,516],"class_list":["post-16060","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-day","tag-guilty","tag-hackers","tag-krebs","tag-plead","tag-scattered","tag-security","tag-spider","tag-trial"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16060","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=16060"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16060\/revisions"}],"predecessor-version":[{"id":16061,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/16060\/revisions\/16061"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/16062"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=16060"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=16060"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=16060"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-06-24 21:36:04 UTC -->