Scattered Spider: what the Elbadawy docket actually shows, against what got reported this week
By Sethu Satheesh · 18 Sept 2026 · 23 min read
Threat Actor: Unknown/unattributed as an organization; individually charged defendants named in "Accused" (press label "Scattered Spider" not used by DOJ in this docket) · Target: At least 12 companies across entertainment, BPO, technology, virtual currency, cloud communications and telecom sectors; 29 named individual cryptocurrency holders
Source: www.courtlistener.com
Executive Summary
On 15 September 2026, prosecutors in the Central District of California asked a federal judge to let them keep 174.9 Bitcoin, 1,306 Ethereum, a BMW i8, a Corvette, a Mercedes G63, a Muhammad Ali painting, 150 pairs of shoes and roughly a dozen other items seized from a 24-year-old named Ahmed Hossam Eldin Elbadawy1. The filing named five defendants — Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan — and is the reason this case is newsworthy this week. It is also the point at which most of the press coverage stopped checking the underlying docket and started repeating each other.
The five were charged together in November 2024 over a scheme the government says ran from no later than 25 September 2021 to 12 April 2023: SMS phishing text messages sent to employees at a dozen-plus companies, stolen login credentials used to loot corporate networks, and — combined with SIM-swapping and other account-takeover techniques — the theft of at least $11 million in cryptocurrency from 29 individual victims23. All five have now either pleaded guilty or been convicted. What the docket actually shows about when and what each of them admitted differs, in at least one case significantly, from what has been reported about them this month.
Elbadawy is not, on this record, a defendant who was arrested last month. He was indicted in October 2024, arraigned not guilty on the operative indictment in October 20254, and has since resolved his case — the government's forfeiture filing this week describes property "subject to forfeiture" under his plea agreement, meaning a plea exists on the docket even though its own change-of-plea entry has not surfaced publicly the way his co-defendants' have1. One widely syndicated report this week states he pleaded guilty in "October 2025"1; the public docket shows that on 16 October 2025 he did the opposite — he pleaded not guilty to all counts4. Whatever happened afterward that produced a binding plea agreement is not visible on the public docket, which is itself consistent with a pattern in this case: three of the five defendants' change-of-plea hearings were held under seal, becoming public only when a sentencing filing or, in Elbadawy's case, a forfeiture application referenced them months later56.
The case is also a useful corrective to how loosely "Scattered Spider" gets used as a label. Neither the original indictment nor either DOJ press release about this specific docket uses the name at all — the term appears only in press coverage23. The victim companies in the charging documents are never named; they are "Victim Company 1" through "Victim Company 12," described only by sector7. Press coverage of the broader Scattered Spider phenomenon has separately and correctly reported that the actor cluster's other, later operations hit MGM Resorts, Caesars Entertainment, Transport for London, and several UK retailers — but those are different intrusions, charged in different cases, against a different set of defendants, with conduct dates after this indictment's 12 April 2023 cutoff8. Nothing in the record reviewed for this paper ties Elbadawy, Osiebo, Evans, or Buchanan to MGM or Caesars.
Verification of Claims
-
Claim: Elbadawy pleaded guilty in October 2025. → False → The public docket for United States v. Elbadawy et al., 2:24-cr-00595 (C.D. Cal.), shows a Minutes of Arraignment on the First Superseding Indictment held on 16 October 2025 before Magistrate Judge Karen E. Scott: "Defendant enters plea of Not Guilty to all counts as charged"4. GovInfoSecurity reported on 16 September 2026 that his "October 2025 guilty plea first came to light publicly" via the forfeiture filing1. The two are not reconcilable on the same date. A plea agreement clearly exists — the government's forfeiture application cites it — but the public docket does not show when or where it was entered; the entries around it (18 October–4 November 2025) are sealed15.
-
Claim: Osiebo and Evans "still face criminal charges" in this case (i.e., have not yet resolved them). → False → Reported as current by GovInfoSecurity on 16 September 20261, reported as current in DOJ's own 17 April 2026 press release on Buchanan's plea9 — but the docket shows Osiebo pleaded guilty to Counts One and Three under seal on 10 June 2025, more than a year before either of those reports, and was sentenced 14 August 2026 to 45 months1011. Evans pleaded guilty and was sentenced 27 August 2026 to 24 months on Count One12. Both defendants' cases were fully resolved before the reports describing them as pending were published. DOJ's own April 2026 release is internally consistent for its own date (Osiebo's plea was sealed at the time), but the language has been repeated since without being updated.
-
Claim: Roughly $11 million in cryptocurrency was stolen. → Verified → The First Superseding Indictment states the conspirators "stole at least 11 million dollars' worth of virtual currency from individual victims, including Individual Victims 1 through 29"7. Summing the individually itemized thefts in the overt-acts section (Individual Victims 1 through 10 alone total more than $8.3 million, led by $6,347,605 from Individual Victim 1) is consistent with, and does not exceed, this figure7. The $11 million figure is the government's own charged total, not a press estimate.
-
Claim: 175 Bitcoin and 1,306 Ethereum are being forfeited. → Assessed, Not Confirmed (as a live, current holding); Verified (as the amount originally seized) → A September 2025 court order for interlocutory sale of Elbadawy's cryptocurrency gives the precise seized amounts: "174.93507503 Bitcoin seized from Defendant on March 1, 2023" and "1,306.745425583278022653 Ethereum seized from Defendant on March 1, 2023"13 — rounded to "175" and "1,306" in the government's September 2026 forfeiture papers and in press coverage1. Because that 2025 order authorized an interlocutory sale — converting the seized crypto to cash before the case concluded, standard practice given cryptocurrency's price volatility — the actual current holding subject to this week's forfeiture order may be a cash-equivalent sum rather than the coins themselves. No source reviewed states whether the sale occurred or at what price.
-
Claim: This is a "Scattered Spider" case. → Assessed, Not Confirmed (as an official designation), Verified (as consistent press usage) → Neither the original November 2024 DOJ release nor the April 2026 release announcing Buchanan's plea uses the term "Scattered Spider"29; both describe the defendants only by their alleged conduct. The label is universal in press coverage of the case, including this paper's own framing for searchability, but it is a media and threat-intelligence-industry attribution, not a prosecutorial one.
Timeline
| Date | Actor | Event | Source |
|---|---|---|---|
| No later than 25 Sep 2021 | Conspirators | Charged conspiracy period begins | 7 |
| 25–26 Sep 2021 | Elbadawy or co-conspirator | Unauthorized access to Individual Victim 1's email and crypto wallets; ~$6,347,605 stolen | 7 |
| May–Jul 2022 | Defendants/co-conspirators | SMS phishing and intrusions against Victim Companies 1–6 (dated overt acts) | 7 |
| 1 Mar 2023 | FBI | Search of Elbadawy's College Station, TX residence: crypto-exchange accountholder database and stolen credentials for 197+ Victim Company employees seized, along with 174.9 BTC and 1,306.7 ETH | 713 |
| 12 Apr 2023 | — | Charged conspiracy period ends | 7 |
| 20 Nov 2024 | US Attorney's Office, C.D. Cal. | Grand jury indictment against Elbadawy, Urban, Osiebo and Evans unsealed; criminal complaint against Buchanan unsealed; US Attorney Martin Estrada and FBI ADIC Akil Davis quoted | 2 |
| 20 Nov 2024 | FBI | Evans arrested in North Carolina | 2 |
| 13 Mar 2025 | Court | Urban's case transferred to the Middle District of Florida under Rule 20 | 14 |
| 16 May 2025 | Grand jury | First Superseding Indictment returned, adding Buchanan as an indicted co-defendant and Counts 1s/2s/3s against Elbadawy, Osiebo and Evans | 7 |
| 10 Jun 2025 | Osiebo | Pleads guilty (sealed) to Counts One and Three; sentencing initially set for 12 Dec 2025 | 10 |
| 16 Oct 2025 | Elbadawy | Arraigned on First Superseding Indictment; pleads not guilty to all counts | 4 |
| 18 Oct–4 Nov 2025 | Court/Government | A cluster of sealed documents and orders filed as to Elbadawy, Osiebo and Evans | 5 |
| 17 Apr 2026 | Buchanan | Pleads guilty to Counts 1 and 3 of the First Superseding Indictment; sentencing set for 21 Aug 2026; DOJ release states Elbadawy, Osiebo and Evans "still face criminal charges" | 915 |
| 30 Jun 2026 | Court | Buchanan's sentencing rescheduled a second time, to 29 Sep 2026 | 16 |
| 14 Aug 2026 | Court | Osiebo sentenced: 45 months (21 on Count 1, 24 on Count 3, consecutive) | 11 |
| 27 Aug 2026 | Court | Evans sentenced: 24 months on Count 1; Count 3 not part of his judgment | 12 |
| 15 Sep 2026 | US Attorney's Office | Application for preliminary order of forfeiture filed naming all five defendants; itemizes crypto, cash, vehicles and luxury goods | 1 |
| 17 Sep 2026 | Parties | Sentencing memoranda filed as to Elbadawy, ahead of his own still-pending sentencing | 17 |
Attack Anatomy
Initial access: SMS phishing
The charged scheme began with SMS phishing ("smishing") text messages sent to employees at each of the twelve named Victim Companies, impersonating the employer or a contracted IT, business-process-outsourcing, or telecom supplier7. The indictment's overt-acts section ties this specifically to Elbadawy: as of 1 March 2023 he possessed stolen login credentials for at least 197 employees across eight of the twelve Victim Companies, consistent with a smishing campaign run at that scale7. Krebs on Security's contemporaneous reporting on the group's broader 2022 activity documents the accompanying infrastructure pattern: lookalike domains such as twilio-help[.]com and ouryahoo-okta[.]com, registered to host cloned employer or identity-provider login pages that the SMS lures linked to18.
Credential harvesting and relay
Victims who followed the SMS link landed on a phishing site cloned to resemble a legitimate employer or supplier login page, hosted on rented VPS infrastructure718. Harvested credentials were relayed in real time through a Telegram bot or channel, per Krebs' technical reporting on the group's phishing-kit infrastructure, letting the conspirators use stolen logins within minutes of capture rather than in a later, separate step18.
Account takeover: email access and SIM swapping
Stolen corporate credentials were used to loot the Victim Companies' networks directly23. Against the 29 named individual cryptocurrency-holding victims, the indictment describes a second, personal-account-focused track: unauthorized access to a victim's personal email as a step toward reaching their cryptocurrency wallets (charged specifically as to, among others, Individual Victims 1 and 9), combined with SIM swapping and other account-takeover techniques used to intercept SMS-based two-factor authentication codes tied to a victim's phone number79. The indictment describes this collectively as bypassing victims' "two factor authentication security features"7.
Cryptocurrency theft
With email and 2FA controls defeated, the conspirators — per the indictment, Elbadawy personally conducted or directed several of these transfers — initiated fraudulent cryptocurrency transfers from the compromised accounts to conspirator-controlled addresses, including the single largest theft charged in the indictment, $6,347,605 from Individual Victim 17. Seized proceeds recovered from Elbadawy's own residence on 1 March 2023 — 174.9 Bitcoin and 1,306.7 Ethereum — are consistent with funds routed through this mechanism, though the indictment does not itemize which specific victim transfers fund which specific seized coins713.
Loading diagram...
Accused
Ahmed Hossam Eldin Elbadawy, 24 ("AD"), of College Station, Texas, is charged under 2:24-cr-00595 in the US District Court for the Central District of California, before Chief Judge John W. Holcomb. He was originally indicted on two counts along with three co-defendants in October 2024, then charged in a First Superseding Indictment in May 2025 with Counts One (18 U.S.C. § 1349, conspiracy to commit wire fraud), Two (18 U.S.C. § 371, conspiracy to violate the Computer Fraud and Abuse Act and the access-device statute), and Three (18 U.S.C. § 1028A, aggravated identity theft)7. Per press reporting confirmed against the government's own forfeiture filing, he pleaded guilty to Counts One and Three; Count Two was dismissed1. He is presumed innocent of any charge not resolved by that plea, and — as with every defendant discussed here — the facts below are the government's allegations in charging and plea-related filings, not judicial findings, except where a judgment has actually been entered.
Co-defendants, same indictment:
- Noah Michael Urban, "Sosa"/"Elijah," 21, of Palm Coast, Florida — case transferred to the Middle District of Florida in March 2025; pleaded guilty there in April 2025 to three fraud-related counts; sentenced to 10 years in federal prison and ordered to pay $13 million in restitution914.
- Evans Onyeaka Osiebo, 21, of Dallas, Texas — pleaded guilty (sealed) to Counts One and Three on 10 June 2025; sentenced 14 August 2026 to 45 months, the longest term of the C.D. Cal. defendants1011.
- Joel Martin Evans, "joeleoli," 26, of Jacksonville, North Carolina — arrested at indictment; sentenced 27 August 2026 to 24 months on Count One only, with a court recommendation to house him near Jacksonville, NC for family visitation1219.
- Tyler Robert Buchanan, "Dread Pirate Roberts"/"Evefan," 24, of Dundee, Scotland — charged by criminal complaint, in federal custody since April 2025, pleaded guilty 17 April 2026 to Counts One and Three, facing a statutory maximum of 22 years; sentencing has been continued at least three times and was most recently set for 29 September 202691516.
Admitted role (per the First Superseding Indictment's overt-acts section, specific to Elbadawy): conducting SMS phishing against Victim Company employees; researching Individual Victim 28 before targeting him; possessing, as of 1 March 2023, stolen login credentials for at least 197 employees across eight of the twelve named Victim Companies, plus a stolen database of registration identifiers, email addresses and partial phone numbers belonging to a virtual currency exchange's accountholders; and personally conducting or directing fraudulent cryptocurrency transfers from at least nine of the 29 named individual victims, including the single largest theft charged in the indictment ($6,347,605 from Individual Victim 1)7.
Attribution and naming basis: Named because charged and, per the government's own forfeiture filing, convicted by guilty plea. This paper does not use "Scattered Spider" as an official designation for Elbadawy — DOJ has not used that term in either public release about this docket — but records the label because it is how the broader actor cluster is discussed in security reporting289.
MITRE ATT&CK (IDs checked live on attack.mitre.org, 18 September 2026; Enterprise matrix unless noted):
| ID | Technique | Basis |
|---|---|---|
| T1660 | Phishing (Mobile matrix) | SMS ("smishing") text messages to employee mobile phones as the initial lure7 |
| T1566.002 | Phishing: Spearphishing Link | Links in the SMS messages to credential-harvesting sites7 |
| T1583.001 | Acquire Infrastructure: Domains | VPSs and lookalike domains registered to host phishing pages, per the indictment's infrastructure allegations and Krebs' reporting of domains like twilio-help[.]com718 |
| T1586.002 | Compromise Accounts: Email Accounts | Unauthorized access to victims' personal email as a step toward crypto-wallet access (e.g., Individual Victims 1 and 9)7 |
| T1621 | Multi-Factor Authentication Request Generation | Indictment's description of bypassing "two factor authentication security features" via account access7 |
| T1111 | Multi-Factor Authentication Interception | SIM swapping to intercept SMS-based 2FA codes sent to victims' phone numbers79 |
| T1102.002 | Web Service: Bidirectional Communication | Telegram channel used to receive harvested credentials in real time, per Krebs' technical reporting on the group's phishing-kit infrastructure18 |
| T1657 | Financial Theft | Fraudulent cryptocurrency transfers to conspirator-controlled addresses7 |
Technical Indicators
# No file hashes or live network infrastructure have been published by DOJ or
# in the court record reviewed. What follows is the charged methodology and
# named cryptocurrency addresses from the plea agreement's admitted facts,
# via the interlocutory-sale order, plus a historical domain pattern reported
# by Krebs on Security for the broader group's 2022 phishing campaigns —
# included as MO context, not as this indictment's own IOCs.
mechanism:
- "SMS phishing to employee mobile phones, impersonating the victim company or a contracted IT/BPO/telecom supplier"
- "Phishing sites cloned to look like legitimate employer or supplier login pages, hosted on rented VPS infrastructure"
- "Credentials captured by phishing kit, forwarded in real time to a Telegram bot/channel"
- "SIM swapping of individual crypto-holders' phone numbers to intercept SMS-based two-factor codes"
cryptocurrency_seized_from_elbadawy:
- asset: "Bitcoin"
amount: "174.93507503"
seized: "1 March 2023"
address_suffix: "...HrjVKp"
- asset: "Ethereum"
amount: "1306.745425583278022653"
seized: "1 March 2023"
address_suffix: "...c4b49f"
historical_domain_pattern_reported_2022 (context only, not this case's confirmed IOCs):
- "twilio-help[.]com"
- "ouryahoo-okta[.]com"
network_iocs: none disclosed for this specific indictment
file_hashes: none disclosedLegal and Regulatory Response
Charges. United States v. Elbadawy et al., 2:24-cr-00595, C.D. Cal., before Chief Judge John W. Holcomb. Original indictment 8 October 2024 (sealed until 20 November 2024); First Superseding Indictment 16 May 2025720. Counts as charged: One (§ 1349, wire fraud conspiracy, 20-year statutory maximum), Two (§ 371, conspiracy to violate 18 U.S.C. §§ 1030(a)(2)(C), 1030(a)(4) and 1029(a)(3), 5-year maximum), Three (§ 1028A, aggravated identity theft, mandatory consecutive 2 years)27.
Investigating and assisting agencies. FBI (lead); on the original charges, assistance from the US Attorney's Office for the Eastern District of North Carolina, Police Scotland, and FBI field offices in Charlotte, Denver, Houston and Portland2. On Buchanan's plea, additionally the Department of Justice's Office of International Affairs, the Spanish Cuerpo Nacional de Policía, and FBI Dallas9.
Prosecutors. Assistant US Attorneys Lauren Restrepo (Cyber and Intellectual Property Crimes Section, later National Security Division) and Sue J. Bai (Terrorism and Export Crimes Section) on the original charges; Benjamin D. Lichtman as AUSA of record on Buchanan's change-of-plea hearing215.
Sealed proceedings. At least three of the five defendants' guilty pleas — Osiebo's (June 2025) and, per the pattern of sealed filings around his own case, apparently Elbadawy's — were entered or negotiated under seal, becoming publicly visible only via later, unsealed filings (a sentencing judgment for Osiebo; a forfeiture application for Elbadawy)1510. The court has not explained why on the public docket.
Forfeiture. Two forfeiture allegations in the First Superseding Indictment, under 18 U.S.C. §§ 981(a)(1)(C)/28 U.S.C. § 2461(c) (proceeds of Counts One or Three) and 18 U.S.C. §§ 982/1030/1029 (property facilitating Counts Two)7. A September 2025 order authorized interlocutory sale of Elbadawy's seized Bitcoin and Ethereum pending final forfeiture13. The 15 September 2026 application for a preliminary order of forfeiture, naming all five defendants collectively, itemizes cryptocurrency, $62,720 cash, three vehicles, watches, handbags, shoes and a painting as to Elbadawy specifically, per press review of the filing1.
Related, separate prosecution. Two UK nationals, Thalha Jubair and Owen Flowers, pleaded guilty in a separate case in June 2026 to charges tied to the 2024 disruption of Transport for London and hacks of US healthcare providers SSM Health Care Corporation and Sutter Health; both were sentenced in July 2026. That prosecution is not part of 2:24-cr-00595 and involves different defendants and different charged conduct821.
Impact Assessment
- Companies targeted or intruded upon: Charged, at least 12 specifically detailed as "Victim Companies" in the indictment (sectors: interactive entertainment ×2, business process outsourcing ×4, technology, virtual currency, cloud communications, cable/internet/telephone, telecommunications ×2), against a broader reported claim of "at least 45 companies" targeted overall73.
- Individual cryptocurrency victims: Charged, 29, with itemized theft amounts ranging from $4,010 to $6,347,6057.
- Total cryptocurrency stolen: Charged, "at least $11 million"7.
- Credentials found in Elbadawy's possession alone: Confirmed by indictment, login credentials for at least 197 employees across eight Victim Companies as of 1 March 20237.
- Sentences to date: Confirmed — Urban 10 years + $13M restitution (M.D. Fla.); Osiebo 45 months; Evans 24 months; Elbadawy and Buchanan sentencing pending as of this writing91112.
- Elbadawy's own sentencing date: Unknown from the public docket. Sentencing memoranda were filed 17 September 2026; no publicly visible entry states the hearing date itself17.
- Whether the seized cryptocurrency has been sold or its current cash value: Unknown; the interlocutory sale was authorized in September 2025, but no filing reviewed confirms it occurred or at what price13.
- Named companies (MGM, Caesars, etc.) as victims of this specific case: Not established. Those are documented Scattered Spider-cluster victims from separate, later incidents outside this indictment's charged period8.
Lessons and Defensive Recommendations
For SOC and identity teams
- The charged mechanism has not changed in years and remains effective: SMS phishing to a personal device, a cloned login page, then live credential relay through a bot channel so stolen credentials can be used within minutes718. Treat "urgent account deactivation" SMS to employees as a standing detection rule, not a one-off awareness reminder.
- SIM swapping defeats SMS-based two-factor authentication by design. Any account holding meaningful value — corporate SSO or personal cryptocurrency — should move to a hardware key or app-based authenticator that isn't tied to a phone number.
For platforms handling law-enforcement or legal process
- This case is a reminder that identity theft charges under § 1028A attach to using another person's identifying information "during and in relation to" the underlying fraud — a second, mandatory consecutive sentence independent of the wire fraud count itself. It meaningfully raises the floor on sentencing exposure for this kind of credential-theft scheme, as this case's own sentences show (Osiebo's Count Three alone added 24 months on top of his Count One term)11.
For journalists and researchers covering multi-defendant cases
- Verify defendant status against the docket, not against the most recent press release that happens to be about someone else. The "still faces criminal charges" line in DOJ's own April 2026 release was accurate about Elbadawy and Evans on the day it was written and about Osiebo not at all — Osiebo had already pleaded guilty ten months earlier, under seal910. A boilerplate co-defendant-status paragraph in a press release is not a live status check.
- Treat a defendant's own arraignment plea and their eventual disposition as two different facts to verify separately. "Pleaded not guilty at arraignment" and "later pleaded guilty under a plea agreement" are both true of several defendants in this case; conflating the two, or reporting only the first, produces exactly the kind of error corrected in this paper's claims section.
For readers assessing "Scattered Spider" coverage generally
- The name describes a loose, shifting cluster of individuals and operations, not a fixed legal entity. A given piece of Scattered Spider coverage may describe conduct from a completely different case, different years, and different people than the one actually being discussed. Check the docket number.
Sources
Corrections log — 18 September 2026: citation structure only. Footnote 5 ("Same as 1") merged into footnote 1; footnote 19 given its own document link. No factual content changed.
Footnotes
-
Texan Scattered Spider Member Pleads Guilty to Hack Attacks — GovInfoSecurity, Mathew J. Schwartz, 16 September 2026 (reporting on the 15 September 2026 forfeiture application) ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
5 Defendants Charged Federally with Running Scheme that Targeted Victim Companies via Phishing Text Messages — US Attorney's Office, Central District of California, 20 November 2024 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10
-
Feds Charge Five Men in 'Scattered Spider' Roundup — Krebs on Security, Brian Krebs, 21 November 2024 ↩ ↩2 ↩3 ↩4
-
United States v. Elbadawy et al., 2:24-cr-00595-JWH (C.D. Cal.), docket entry 123: Minutes of Arraignment on First Superseding Indictment, 16 October 2025, "[Defendant] enters plea of Not Guilty to all counts as charged" — CourtListener/RECAP docket ↩ ↩2 ↩3 ↩4
-
Docket entries 111–124 (7 October–13 November 2025), including sealed documents 112, 114–117, 119–122 — CourtListener/RECAP docket ↩ ↩2 ↩3 ↩4
-
Docket entries 199–222 (2–17 September 2026), notices of manual filing of sealed and under-seal documents as to Elbadawy, and the 15 September 2026 forfeiture application — CourtListener/RECAP docket ↩
-
First Superseding Indictment, Doc. 61, United States v. Elbadawy et al., 2:24-cr-00595 (C.D. Cal.), filed 16 May 2025 — CourtListener/RECAP docket ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11 ↩12 ↩13 ↩14 ↩15 ↩16 ↩17 ↩18 ↩19 ↩20 ↩21 ↩22 ↩23 ↩24 ↩25 ↩26 ↩27 ↩28 ↩29 ↩30 ↩31 ↩32 ↩33
-
Scattered Spider Hackers Plead Guilty on Day 1 of Trial — Krebs on Security, Brian Krebs, 23 June 2026 ↩ ↩2 ↩3 ↩4
-
British National Pleads Guilty to Hacking into Companies and Stealing At Least $8 Million in Virtual Currency — US Attorney's Office, Central District of California, 17 April 2026 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8 ↩9 ↩10 ↩11
-
Docket entry 84, United States v. Elbadawy et al., 2:24-cr-00595 (C.D. Cal.): Sealed Minutes of Change of Plea Hearing as to Evans Onyeaka Osiebo, 10 June 2025, "pleads GUILTY to counts one and three of the indictment" — CourtListener/RECAP docket ↩ ↩2 ↩3 ↩4 ↩5
-
Docket entry 179, Judgment and Commitment as to Evans Onyeaka Osiebo, 14 August 2026: "45 months. 21 months on Count 1 and 24 months on Count 3, consecutively" — CourtListener/RECAP docket ↩ ↩2 ↩3 ↩4 ↩5
-
Docket entry 197, Judgment and Commitment as to Joel Martin Evans, 27 August 2026, Doc. 197 (recap_document 492177806): 24 months on Count 1 of the First Superseding Indictment — CourtListener/RECAP docket ↩ ↩2 ↩3 ↩4
-
Docket entry 106, Order for Interlocutory Sale of Defendant Ahmed Hossam Eldin Elbadawy's Cryptocurrency, 18–19 September 2025 — CourtListener/RECAP docket ↩ ↩2 ↩3 ↩4 ↩5
-
Docket entry 50, Consent to Transfer Jurisdiction (Rule 20) to the Middle District of Florida as to Noah Michael Urban, 13 March 2025 — CourtListener/RECAP docket ↩ ↩2
-
Docket entry 143, Minutes of Change of Plea Hearing as to Tyler Robert Buchanan, 17 April 2026: pleads guilty to Counts 1 and 3, sentencing set for 21 August 2026 — CourtListener/RECAP docket ↩ ↩2 ↩3
-
Docket entry 147, Scheduling Notice advancing Buchanan's sentencing from 2 October 2026 to 29 September 2026, 30 June 2026 — CourtListener/RECAP docket ↩ ↩2
-
Docket entries 221 and 222, Sentencing Memoranda, 17 September 2026 — CourtListener/RECAP docket ↩ ↩2
-
Feds Charge Five Men in 'Scattered Spider' Roundup — Krebs on Security, Brian Krebs, 21 November 2024 (technical detail on 2022 Twilio phishing infrastructure and domains, general MO context) ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Judgment and Commitment as to Joel Martin Evans, Doc. 197, p.2 — court recommendation for BOP housing "located in the Jacksonville, North Carolina area, to facilitate visitation with family" — 27 August 2026 ↩
-
Docket entry 1, Sealed Indictment, United States v. Elbadawy et al., filed 8 October 2024 — CourtListener/RECAP docket ↩
-
Scattered Spider Hackers Plead Guilty on Day 1 of Trial — Krebs on Security, 23 June 2026 (Jubair and Flowers sentencing, separate UK-related prosecution) ↩
Related Research
Cybernews found an exposed server revealing a two-year operation that brute-forced weak credentials on end-of-life PPTP/L2TP VPN devices to build an 87,000-IP residential proxy network, resold to platforms including VPN Pure, using a jailbroken Claude Code to automate the hunt.
Zimperium disclosed RatHat, an Android banking trojan that sends a live map of the victim's screen to a generative AI assistant to navigate the device, abuses Wireless Debugging for shell access, and reinstalls itself after removal — attributed to likely China-based operators.
A Conti affiliate who coded a loader and intruded on twelve victims got 48 months in Nashville on 10 September 2026. The judgment credits custody since his July 2023 arrest in Cork, leaving about ten months. Plea agreement and docket analysed.