{"id":6307,"date":"2025-08-21T03:04:15","date_gmt":"2025-08-21T03:04:15","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/08\/21\/sim-swapper-scattered-spider-hacker-gets-10-years\/"},"modified":"2025-08-21T03:04:15","modified_gmt":"2025-08-21T03:04:15","slug":"sim-swapper-scattered-spider-hacker-gets-10-years","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/08\/21\/sim-swapper-scattered-spider-hacker-gets-10-years\/","title":{"rendered":"SIM-Swapper, Scattered Spider Hacker Gets 10 Years"},"content":{"rendered":"<p>    SIM-Swapper, Scattered Spider Hacker Gets 10 Years<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>A 20-year-old Florida man at the center of a prolific cybercrime group known as \u201c<strong>Scattered Spider<\/strong>\u201d was sentenced to 10 years in federal prison today, and ordered to pay roughly $13 million in restitution to victims.<\/p>\n<p><strong>Noah Michael Urban<\/strong> of Palm Coast, Fla. pleaded guilty in April 2025 to charges of wire fraud and conspiracy. Florida prosecutors alleged Urban <a href=\"https:\/\/krebsonsecurity.com\/2024\/01\/fla-man-charged-in-sim-swapping-spree-is-key-suspect-in-hacker-groups-oktapus-scattered-spider\/\" target=\"_blank\" rel=\"noopener\">conspired with others to steal at least $800,000<\/a> from five victims via <a href=\"https:\/\/krebsonsecurity.com\/category\/sim-swapping\/\" target=\"_blank\" rel=\"noopener\">SIM-swapping attacks<\/a> that diverted their mobile phone calls and text messages to devices controlled by Urban and his co-conspirators.<\/p>\n<div id=\"attachment_66236\" style=\"width: 456px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" loading=\"lazy\" aria-describedby=\"caption-attachment-66236\" decoding=\"async\" class=\" wp-image-66236\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2024\/01\/noahmichaelurban.png?resize=446%2C559&#038;ssl=1\" alt=\"\" width=\"446\" height=\"559\"><\/p>\n<p id=\"caption-attachment-66236\" class=\"wp-caption-text\">A booking photo of Noah Michael Urban released by the Volusia County Sheriff.<\/p>\n<\/div>\n<p>Although prosecutors had asked for Urban to serve eight years, Jacksonville news outlet <strong>News4Jax.com<\/strong> <a href=\"https:\/\/www.news4jax.com\/news\/local\/2025\/08\/20\/palm-coast-man-linked-to-scattered-spider-cybercrime-gang-sentenced-to-10-years-for-cryptocurrency-theft\/\" target=\"_blank\" rel=\"noopener\">reports<\/a> the federal judge in the case today opted to sentence Urban to 120 months in federal prison, ordering him to pay $13 million in restitution and undergo three years of supervised release after his sentence is completed.<\/p>\n<p>In November 2024 Urban was <a href=\"https:\/\/krebsonsecurity.com\/2024\/11\/feds-charge-five-men-in-scattered-spider-roundup\/\" target=\"_blank\" rel=\"noopener\">charged by federal prosecutors in Los Angeles<\/a> as one of five members of Scattered Spider (a.k.a. \u201cOktapus,\u201d \u201cScatter Swine\u201d and \u201cUNC3944\u201d), which specialized in SMS and voice phishing attacks that tricked employees at victim companies into entering their credentials and one-time passcodes at phishing websites. Urban pleaded guilty to one count of conspiracy to commit wire fraud in the California case, and the $13 million in restitution is intended to cover victims from both cases.<\/p>\n<p>The targeted SMS scams <a href=\"https:\/\/krebsonsecurity.com\/2022\/08\/how-1-time-passcodes-became-a-corporate-liability\/\" target=\"_blank\" rel=\"noopener\">spanned several months during the summer of 2022<\/a>, asking employees to click a link and log in at a website that mimicked their employer\u2019s Okta authentication page. Some SMS phishing messages told employees their VPN credentials were expiring and needed to be changed; other missives advised employees about changes to their upcoming work schedule.<\/p>\n<p>That phishing spree netted Urban and others access to more than 130 companies, including <strong>Twilio<\/strong>, <strong>LastPass<\/strong>, <strong>DoorDash<\/strong>, <strong>MailChimp<\/strong>, and <strong>Plex<\/strong>. The government says the group used that access to steal proprietary company data and customer information, and that members also phished people to steal millions of dollars worth of cryptocurrency.<\/p>\n<p>For many years, Urban\u2019s online hacker aliases \u201c<strong>King Bob<\/strong>\u201d and \u201c<strong>Sosa<\/strong>\u201d were fixtures of <a href=\"https:\/\/krebsonsecurity.com\/2024\/09\/the-dark-nexus-between-harm-groups-and-the-com\/\" target=\"_blank\" rel=\"noopener\">the Com<\/a>, a mostly Telegram and Discord-based community of English-speaking cybercriminals wherein hackers boast loudly about high-profile exploits and hacks that almost invariably begin with social engineering. King Bob constantly bragged on the Com about stealing unreleased rap music recordings from popular artists, presumably through SIM-swapping attacks. Many of those purloined tracks or \u201cgrails\u201d he later sold or gave away on forums.<\/p>\n<div id=\"attachment_71970\" style=\"width: 611px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-71970\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-71970\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/kingbobtweets.png?resize=601%2C485&#038;ssl=1\" alt=\"\" width=\"601\" height=\"485\"><\/p>\n<p id=\"caption-attachment-71970\" class=\"wp-caption-text\">Noah \u201cKing Bob\u201d Urban, posting to Twitter\/X around the time of his sentencing today.<\/p>\n<\/div>\n<p>Sosa also was active in a particularly destructive group of accomplished criminal SIM-swappers known as \u201c<strong>Star Fraud<\/strong>.\u201d Cyberscoop\u2019s AJ Vicens reported in 2023 that individuals within Star Fraud were likely involved in the high-profile Caesars Entertainment and MGM Resorts extortion attacks that same year.<\/p>\n<p>The Star Fraud SIM-swapping group gained the ability to temporarily move targeted mobile numbers to devices they controlled by constantly phishing employees of the major mobile providers. In February 2023, KrebsOnSecurity published data taken from the Telegram channels for Star Fraud and two other SIM-swapping groups showing these crooks focused on SIM-swapping T-Mobile customers, and that they collectively <a href=\"https:\/\/krebsonsecurity.com\/2023\/02\/hackers-claim-they-breached-t-mobile-more-than-100-times-in-2022\/\" target=\"_blank\" rel=\"noopener\">claimed internal access to T-Mobile on 100 separate occasions over a 7-month period in 2022<\/a>.<span id=\"more-71967\"><\/span><\/p>\n<p>Reached via one of his King Bob accounts on Twitter\/X, Urban called the sentence unjust, and said the judge in his case discounted his age as a factor.<\/p>\n<p>\u201cThe judge purposefully ignored my age as a factor because of the fact another Scattered Spider member hacked him personally during the course of my case,\u201d Urban said in reply to questions, noting that he was sending the messages from a Florida county jail. \u201cHe should have been removed as a judge much earlier on. But staying in county jail is torture.\u201d<\/p>\n<p>A <a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/urban-status-hack.pdf\" target=\"_blank\" rel=\"noopener\">court transcript<\/a> (PDF) from a status hearing in February 2025 shows Urban was telling the truth about the hacking incident that happened while he was in federal custody. It involved an intrusion into a magistrate judge\u2019s email account, where a copy of Urban\u2019s sealed indictment was stolen. The judge told attorneys for both sides that a co-defendant in the California case was trying to find out about Mr. Urban\u2019s activity in the Florida case.<\/p>\n<p>\u201cWhat it ultimately turned into a was a big faux pas,\u201d <strong>Judge Harvey E. Schlesinger<\/strong> said. \u201cThe Court\u2019s password\u2026business is handled by an outside contractor. And somebody called the outside contractor representing Judge Toomey saying, \u2018I need a password change.\u2019 And they gave out the password change. That\u2019s how whoever was making the phone call got into the court.\u201d<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    BrianKrebs<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/krebsonsecurity.com\/2025\/08\/sim-swapper-scattered-spider-hacker-gets-10-years\/\">Go to krebsonsecurity<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>SIM-Swapper, Scattered Spider Hacker Gets 10 Years A 20-year-old Florida man at the center of a prolific cybercrime group known as \u201cScattered Spider\u201d was sentenced to 10 years in federal prison today, and ordered to pay roughly $13 million in restitution to victims. Noah Michael Urban of Palm Coast, Fla. pleaded guilty in April 2025 [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1203,1727,1728,55,218,219,190,1729,221,224,1730,1731,225,212,226,504,227,757,228,1732],"tags":[72],"class_list":["post-6307","post","type-post","status-publish","format-standard","hentry","category-doordash","category-judge-harvey-e-schlesinger","category-king-bob","category-krebsonsecurity","category-lastpass","category-mailchimp","category-neer-do-well-news","category-news4jax-com","category-noah-michael-urban","category-oktapus","category-plex","category-scatter-swine","category-scattered-spider","category-sim-swapping","category-sosa","category-star-fraud","category-t-mobile","category-the-com","category-twilio","category-unc3944","tag-krebsonsecurity"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6307"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=6307"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/6307\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=6307"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=6307"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=6307"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}