{"id":4451,"date":"2025-07-12T03:09:14","date_gmt":"2025-07-12T03:09:14","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=4451"},"modified":"2025-07-12T03:09:14","modified_gmt":"2025-07-12T03:09:14","slug":"uk-arrests-4-in-scattered-spider-ransom-group-krebs-on-safety","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=4451","title":{"rendered":"UK Arrests 4 in \u2018Scattered Spider\u2019 Ransom Group \u2013 Krebs on Safety"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p>Authorities in the UK this week arrested 4 individuals aged 17 to twenty in reference to current information theft and extortion assaults in opposition to the retailers <strong>Marks &amp; Spencer<\/strong> and <strong>Harrods<\/strong>, and the British meals retailer <strong>Co-op Group. <\/strong>The breaches have been linked to a prolific however loosely-affiliated cybercrime group dubbed \u201c<strong>Scattered Spider<\/strong>,\u201d whose different current victims embrace a number of airways.<\/p>\n<p>The U.Ok.\u2019s <strong>Nationwide Crime Company<\/strong> (NCA) declined confirm the names of these arrested, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.nationalcrimeagency.gov.uk\/news\/retail-cyber-attacks-nca-arrest-four-for-attacks-on-m-s-co-op-and-harrods\" target=\"_blank\" rel=\"noopener\">saying<\/a> solely that they included two males aged 19, one other aged 17, and 20-year-old feminine.<\/p>\n<p>Scattered Spider is the title given to an English-speaking cybercrime group identified for utilizing social engineering techniques to interrupt into corporations and steal information for ransom, usually impersonating workers or contractors to deceive IT assist desks into granting entry. The <strong>FBI<\/strong> warned final month that Scattered Spider had just lately shifted to focusing on corporations within the retail and airline sectors.<\/p>\n<p>KrebsOnSecurity has realized the identities of two of the suspects. A number of sources near the investigation stated these arrested embrace <strong>Owen David Flowers<\/strong>, a U.Ok. man alleged to have been concerned within the cyber intrusion and ransomware assault that shut down a number of <strong>MGM On line casino<\/strong> properties in September 2023. Those self same sources stated the lady arrested is or just lately was in a relationship with Flowers.<\/p>\n<p>Sources advised KrebsOnSecurity that Flowers, who allegedly glided by the hacker handles \u201cbo764,\u201d \u201cHoly,\u201d and \u201cNazi,\u201d was the group member who anonymously gave interviews to the media within the days after the MGM hack. His actual title was omitted from <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2024\/09\/the-dark-nexus-between-harm-groups-and-the-com\/\" target=\"_blank\" rel=\"noopener\">a September 2024 story in regards to the group<\/a> as a result of he was not but charged in that incident.<\/p>\n<p>The larger fish arrested this week is 19-year-old <strong>Thalha Jubair<\/strong>,\u00a0a U.Ok. man whose alleged exploits underneath varied monikers have been well-documented in tales on this website. Jubair is believed to have used the nickname \u201c<strong>Earth2Star<\/strong>,\u201d which corresponds to a founding member of the cybercrime-focused Telegram channel \u201c<strong>Star Fraud Chat<\/strong>.\u201d<\/p>\n<p>In 2023, KrebsOnSecurity <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2023\/02\/hackers-claim-they-breached-t-mobile-more-than-100-times-in-2022\/\" target=\"_blank\" rel=\"noopener\">revealed an investigation<\/a> into the work of three totally different SIM-swapping teams that phished credentials from T-Cell workers and used that entry to supply a service whereby any T-Cell phone quantity could possibly be swapped to a brand new gadget. Star Chat was by far probably the most energetic and consequential of the three SIM-swapping teams, who collectively broke into T-Cell\u2019s community greater than 100 occasions within the second half of 2022.<\/p>\n<div id=\"attachment_71644\" style=\"width: 757px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" aria-describedby=\"caption-attachment-71644\" decoding=\"async\" class=\" wp-image-71644\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ace-earth2star-starchat.png\" alt=\"\" width=\"747\" height=\"306\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ace-earth2star-starchat.png 1153w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ace-earth2star-starchat-768x314.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ace-earth2star-starchat-782x320.png 782w\" sizes=\"auto, (max-width: 747px) 100vw, 747px\"\/><\/p>\n<p id=\"caption-attachment-71644\" class=\"wp-caption-text\">Jubair allegedly used the handles \u201cEarth2Star\u201d and \u201cStar Ace,\u201d and was a core member of a prolific SIM-swapping group working in 2022. Star Ace posted this picture to the Star Fraud chat channel on Telegram, and it lists varied costs for SIM-swaps.<\/p>\n<\/div>\n<p>Sources inform KrebsOnSecurity that Jubair additionally was a core member of the <strong>LAPSUS$<\/strong> cybercrime group that <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2022\/03\/a-closer-look-at-the-lapsus-data-extortion-group\/\" target=\"_blank\" rel=\"noopener\">broke into dozens of know-how corporations in 2022<\/a>, stealing supply code and different inner information from tech giants together with <strong>Microsoft<\/strong>, <strong>Nvidia<\/strong>, <strong>Okta<\/strong>, <strong>Rockstar Video games<\/strong>, <strong>Samsung<\/strong>, <strong>T-Cell<\/strong>, and <strong>Uber<\/strong>.<\/p>\n<p>In April 2022, KrebsOnSecurity <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2022\/04\/leaked-chats-show-lapsus-stole-t-mobile-source-code\/\" target=\"_blank\" rel=\"noopener\">revealed inner chat information from LAPSUS$<\/a>, and people chats indicated Jubair was utilizing the nicknames <strong>Amtrak<\/strong> and <strong>Asyntax<\/strong>. At one level within the chats, Amtrak advised the LAPSUS$ group chief to not share T-Cell\u2019s brand in photographs despatched to the group as a result of he\u2019d been beforehand busted for SIM-swapping and his mother and father would suspect he was again at it once more.<\/p>\n<p>As proven in these chats, the chief of LAPSUS$ finally determined to betray Amtrak by posting his actual title, telephone quantity, and different hacker handles right into a public chat room on Telegram.<\/p>\n<div id=\"attachment_59487\" style=\"width: 759px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-59487\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-59487\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/04\/amtraxdox.png\" alt=\"\" width=\"749\" height=\"207\"\/><\/p>\n<p id=\"caption-attachment-59487\" class=\"wp-caption-text\">In March 2022, the chief of the LAPSUS$ information extortion group uncovered Thalha Jubair\u2019s title and hacker handles in a public chat room on Telegram.<\/p>\n<\/div>\n<p><span id=\"more-70968\"\/>That story in regards to the leaked LAPSUS$ chats linked Amtrak\/Asyntax\/Jubair to the identification \u201c<strong>Everlynn<\/strong>,\u201d the founding father of a cybercriminal service that <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2022\/03\/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests\/\" target=\"_blank\" rel=\"noopener\">bought fraudulent \u201cemergency information requests\u201d<\/a> focusing on the foremost social media and electronic mail suppliers. In such schemes, the hackers compromise electronic mail accounts tied to police departments and authorities businesses, after which ship unauthorized calls for for subscriber information whereas claiming the data being requested can\u2019t anticipate a courtroom order as a result of it pertains to an pressing matter of life and demise.<\/p>\n<div id=\"attachment_59127\" style=\"width: 758px\" class=\"wp-caption aligncenter\"><img aria-describedby=\"caption-attachment-59127\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-59127\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/infinityrecursion.png\" alt=\"\" width=\"748\" height=\"622\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/infinityrecursion.png 864w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/infinityrecursion-768x638.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/infinityrecursion-782x650.png 782w\" sizes=\"auto, (max-width: 748px) 100vw, 748px\"\/><\/p>\n<p id=\"caption-attachment-59127\" class=\"wp-caption-text\">The roster of the now-defunct \u201cInfinity Recursion\u201d hacking workforce, from which some member of LAPSUS$ hail.<\/p>\n<\/div>\n<p>Sources say Jubair additionally used the nickname \u201c<strong>Operator<\/strong>,\u201d and that till just lately he was the administrator of the <strong>Doxbin<\/strong>, a long-running and extremely poisonous on-line group that&#8217;s used to \u201cdox\u201d or publish deeply private info on individuals. In Could 2024, a number of well-liked cybercrime channels on Telegram ridiculed Operator after it was revealed that he\u2019d staged his personal kidnapping in a botched plan to throw off regulation enforcement investigators.<\/p>\n<p>In November 2024, U.S. authorities <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/krebsonsecurity.com\/2024\/11\/feds-charge-five-men-in-scattered-spider-roundup\/\" target=\"_blank\" rel=\"noopener\">charged 5 males aged 20 to 25<\/a> in reference to the Scattered Spider group, which has lengthy relied on recruiting minors to hold out its most dangerous actions. Certainly, most of the group\u2019s core members have been recruited from on-line gaming platforms like Roblox and Minecraft of their early teenagers, and have been perfecting their social engineering techniques for years.<\/p>\n<p>\u201cThere&#8217;s a clear sample that a few of the most wicked menace actors first joined cybercrime gangs at an exceptionally younger age,\u201d stated <strong>Allison Nixon<\/strong>, chief analysis officer on the New York based mostly safety agency <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.unit221b.com\" target=\"_blank\" rel=\"noopener\">Unit 221B<\/a>. \u201cCybercriminals arrested at 15 or youthful want critical intervention and monitoring to forestall a years lengthy large escalation.\u201d<\/p>\n<\/p><\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>Authorities in the UK this week arrested 4 individuals aged 17 to twenty in reference to current information theft and extortion assaults in opposition to the retailers Marks &amp; Spencer and Harrods, and the British meals retailer Co-op Group. The breaches have been linked to a prolific however loosely-affiliated cybercrime group dubbed \u201cScattered Spider,\u201d whose [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":4453,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[258,853,262,3976,2075,211,2076],"class_list":["post-4451","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-arrests","tag-group","tag-krebs","tag-ransom","tag-scattered","tag-security","tag-spider"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4451","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4451"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4451\/revisions"}],"predecessor-version":[{"id":4452,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/4451\/revisions\/4452"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/4453"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4451"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4451"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4451"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-15 05:27:40 UTC -->