{"id":7181,"date":"2025-09-25T03:00:37","date_gmt":"2025-09-25T03:00:37","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/25\/feds-tie-scattered-spider-duo-to-115m-in-ransoms\/"},"modified":"2025-09-25T03:00:37","modified_gmt":"2025-09-25T03:00:37","slug":"feds-tie-scattered-spider-duo-to-115m-in-ransoms","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/25\/feds-tie-scattered-spider-duo-to-115m-in-ransoms\/","title":{"rendered":"Feds Tie \u2018Scattered Spider\u2019 Duo to $115M in Ransoms"},"content":{"rendered":"<p>    Feds Tie \u2018Scattered Spider\u2019 Duo to $115M in Ransoms<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>U.S. prosecutors last week levied criminal hacking charges against 19-year-old U.K. national <strong>Thalha Jubair<\/strong> for allegedly being a core member of <strong>Scattered Spider<\/strong>, a prolific cybercrime group blamed for extorting at least $115 million in ransom payments from victims. The charges came as Jubair and an alleged co-conspirator appeared in a London court to face accusations of hacking into and extorting several large U.K. retailers, the London transit system, and healthcare providers in the United States.<\/p>\n<p>At a court hearing last week, U.K. prosecutors laid out a litany of charges against Jubair and 18-year-old <strong>Owen Flowers<\/strong>, accusing the teens of involvement in an August 2024 cyberattack that crippled <strong>Transport for London<\/strong>, the entity responsible for the public transport network in the Greater London area.<\/p>\n<div id=\"attachment_72226\" style=\"width: 759px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" loading=\"lazy\" aria-describedby=\"caption-attachment-72226\" decoding=\"async\" class=\" wp-image-72226\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/paw-flowers-jubair.png?resize=749%2C470&#038;ssl=1\" alt=\"\" width=\"749\" height=\"470\"><\/p>\n<p id=\"caption-attachment-72226\" class=\"wp-caption-text\">A court artist sketch of Owen Flowers (left) and Thalha Jubair appearing at Westminster Magistrates\u2019 Court last week. Credit: Elizabeth Cook, PA Wire.<\/p>\n<\/div>\n<p>On July 10, 2025, KrebsOnSecurity <a href=\"https:\/\/krebsonsecurity.com\/2025\/07\/uk-charges-four-in-scattered-spider-ransom-group\/\" target=\"_blank\" rel=\"noopener\">reported<\/a> that Flowers and Jubair had been arrested in the United Kingdom in connection with recent Scattered Spider <a href=\"https:\/\/www.thetimes.com\/uk\/technology-uk\/article\/ransoms-hackers-cyber-crime-t5kjldwwm\" target=\"_blank\" rel=\"noopener\">ransom attacks<\/a> against the retailers <strong>Marks &amp; Spencer<\/strong> and <strong>Harrods<\/strong>, and the British food retailer <strong>Co-op Group<\/strong>.<\/p>\n<p>That story cited sources close to the investigation saying Flowers was the Scattered Spider member who anonymously gave interviews to the media in the days after the group\u2019s September 2023 ransomware attacks disrupted operations at Las Vegas casinos operated by <strong>MGM Resorts<\/strong> and <strong>Caesars Entertainment<\/strong>.<\/p>\n<p>The story also noted that Jubair\u2019s alleged handles on cybercrime-focused Telegram channels had far lengthier rap sheets involving some of the more consequential and headline-grabbing data breaches over the past four years. What follows is an account of cybercrime activities that prosecutors have attributed to Jubair\u2019s alleged hacker handles, as told by those accounts in posts to public Telegram channels that are closely monitored by multiple cyber intelligence firms.<\/p>\n<h2>EARLY DAYS (2021-2022)<\/h2>\n<p>Jubair is alleged to have been a core member of the <strong>LAPSUS$<\/strong>\u00a0cybercrime group that\u00a0<a href=\"https:\/\/krebsonsecurity.com\/2022\/03\/a-closer-look-at-the-lapsus-data-extortion-group\/\" target=\"_blank\" rel=\"noopener\">broke into dozens of technology companies beginning in late 2021<\/a>, stealing source code and other internal data from tech giants including\u00a0<strong>Microsoft<\/strong>,\u00a0<strong>Nvidia<\/strong>,\u00a0<strong>Okta<\/strong>,\u00a0<strong>Rockstar Games<\/strong>,\u00a0<strong>Samsung<\/strong>,\u00a0<strong>T-Mobile<\/strong>, and\u00a0<strong>Uber<\/strong>.<\/p>\n<p>That is, according to the former leader of the now-defunct LAPSUS$. In April 2022, KrebsOnSecurity <a href=\"https:\/\/krebsonsecurity.com\/2022\/04\/leaked-chats-show-lapsus-stole-t-mobile-source-code\/\" target=\"_blank\" rel=\"noopener\">published internal chat records<\/a> taken from a server that LAPSUS$ used, and those chats indicate Jubair was working with the group using the nicknames <strong>Amtrak<\/strong>\u00a0and\u00a0<strong>Asyntax<\/strong>. In the middle of the gang\u2019s cybercrime spree, Asyntax told the LAPSUS$ leader not to share T-Mobile\u2019s logo in images sent to the group because he\u2019d been previously busted for SIM-swapping and his parents would suspect he was back at it again.<\/p>\n<p>The leader of LAPSUS$ responded by gleefully posting Asyntax\u2019s real name, phone number, and other hacker handles into a public chat room on Telegram:<\/p>\n<div id=\"attachment_59487\" class=\"wp-caption aligncenter\">\n<div id=\"attachment_59487\" style=\"width: 759px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-59487\" decoding=\"async\" loading=\"lazy\" class=\"wp-image-59487\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2022\/04\/amtraxdox.png?resize=749%2C207&#038;ssl=1\" alt=\"\" width=\"749\" height=\"207\"><\/p>\n<p id=\"caption-attachment-59487\" class=\"wp-caption-text\">In March 2022, the leader of the LAPSUS$ data extortion group exposed Thalha Jubair\u2019s name and hacker handles in a public chat room on Telegram.<\/p>\n<\/div>\n<\/div>\n<p><span id=\"more-70968\"><\/span>That story about the leaked LAPSUS$ chats also connected Amtrak\/Asyntax to several previous hacker identities, including \u201c<strong>Everlynn<\/strong>,\u201d who in April 2021 began offering a cybercriminal service that <a href=\"https:\/\/krebsonsecurity.com\/2022\/03\/hackers-gaining-power-of-subpoena-via-fake-emergency-data-requests\/\" target=\"_blank\" rel=\"noopener\">sold fraudulent \u201cemergency data requests\u201d<\/a>\u00a0targeting the major social media and email providers.<\/p>\n<p>In these so-called \u201cfake EDR\u201d schemes, the hackers compromise email accounts tied to police departments and government agencies, and then send unauthorized demands for subscriber data (e.g. username, IP\/email address), while claiming the information being requested can\u2019t wait for a court order because it relates to an urgent matter of life and death.<\/p>\n<div id=\"attachment_59127\" style=\"width: 760px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-59127\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-59127\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/infinityrecursion.png?resize=750%2C623&#038;ssl=1\" alt=\"\" width=\"750\" height=\"623\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/infinityrecursion.png 864w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/infinityrecursion-768x638.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/03\/infinityrecursion-782x650.png 782w\" sizes=\"(max-width: 750px) 100vw, 750px\"><\/p>\n<p id=\"caption-attachment-59127\" class=\"wp-caption-text\">The roster of the now-defunct \u201cInfinity Recursion\u201d hacking team, which sold fake EDRs between 2021 and 2022. The founder \u201cEverlynn\u201d has been tied to Jubair. The member listed as \u201cPeter\u201d became the leader of LAPSUS$ who would later post Jubair\u2019s name, phone number and hacker handles into LAPSUS$\u2019s chat channel.<\/p>\n<\/div>\n<p><span id=\"more-72208\"><\/span><\/p>\n<h2>EARTHTOSTAR<\/h2>\n<p>Prosecutors in New Jersey last week <a href=\"https:\/\/www.justice.gov\/opa\/pr\/united-kingdom-national-charged-connection-multiple-cyber-attacks-including-critical\" target=\"_blank\" rel=\"noopener\">alleged<\/a> Jubair was part of a threat group variously known as Scattered Spider, <strong>0ktapus<\/strong>, and <strong>UNC3944<\/strong>, and that he used the nicknames <strong>EarthtoStar<\/strong>, <strong>Brad<\/strong>, <strong>Austin<\/strong>, and <strong>Austistic<\/strong>.<\/p>\n<p>Beginning in 2022, EarthtoStar co-ran a bustling Telegram channel called <strong>Star Chat<\/strong>, which was home to a prolific SIM-swapping group that relentlessly used voice- and SMS-based phishing attacks to steal credentials from employees at the major wireless providers in the U.S. and U.K.<\/p>\n<div id=\"attachment_71644\" style=\"width: 760px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-71644\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-71644\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ace-earth2star-starchat.png?resize=750%2C307&#038;ssl=1\" alt=\"\" width=\"750\" height=\"307\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ace-earth2star-starchat.png 1153w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ace-earth2star-starchat-768x314.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/07\/ace-earth2star-starchat-782x320.png 782w\" sizes=\"(max-width: 750px) 100vw, 750px\"><\/p>\n<p id=\"caption-attachment-71644\" class=\"wp-caption-text\">Jubair allegedly used the handle \u201cEarth2Star,\u201d a core member of a prolific SIM-swapping group operating in 2022. This ad produced by the group lists various prices for SIM swaps.<\/p>\n<\/div>\n<p>The group would then use that access to sell a SIM-swapping service that could redirect a target\u2019s phone number to a device the attackers controlled, allowing them to intercept the victim\u2019s phone calls and text messages (including one-time codes). Members of Star Chat targeted multiple wireless carriers with SIM-swapping attacks, but they focused mainly on phishing T-Mobile employees.<\/p>\n<p>In February 2023, KrebsOnSecurity scrutinized more than seven months of these SIM-swapping solicitations on Star Chat, which almost daily peppered the public channel with \u201cTmo up!\u201d and \u201cTmo down!\u201d notices indicating periods wherein the group claimed to have active access to T-Mobile\u2019s network.<\/p>\n<div id=\"attachment_72238\" style=\"width: 760px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-72238\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72238\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/rocketace-tmobile.png?resize=750%2C848&#038;ssl=1\" alt=\"\" width=\"750\" height=\"848\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/rocketace-tmobile.png 809w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/rocketace-tmobile-768x869.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/rocketace-tmobile-782x884.png 782w\" sizes=\"(max-width: 750px) 100vw, 750px\"><\/p>\n<p id=\"caption-attachment-72238\" class=\"wp-caption-text\">A redacted receipt from Star Chat\u2019s SIM-swapping service targeting a T-Mobile customer after the group gained access to internal T-Mobile employee tools.<\/p>\n<\/div>\n<p>The data showed that Star Chat \u2014 along with two other SIM-swapping groups operating at the same time \u2014 <a href=\"https:\/\/krebsonsecurity.com\/2023\/02\/hackers-claim-they-breached-t-mobile-more-than-100-times-in-2022\/\" target=\"_blank\" rel=\"noopener\">collectively broke into T-Mobile over a hundred times in the last seven months of 2022<\/a>. However, Star Chat was by far the most prolific of the three, responsible for at least 70 of those incidents.<\/p>\n<div id=\"attachment_62908\" style=\"width: 759px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-62908\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-62908\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2023\/02\/tmodates.png?resize=749%2C496&#038;ssl=1\" alt=\"\" width=\"749\" height=\"496\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2023\/02\/tmodates.png 1040w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2023\/02\/tmodates-768x509.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2023\/02\/tmodates-782x518.png 782w\" sizes=\"(max-width: 749px) 100vw, 749px\"><\/p>\n<p id=\"caption-attachment-62908\" class=\"wp-caption-text\">The 104 days in the latter half of 2022 in which different known SIM-swapping groups claimed access to T-Mobile employee tools. Star Chat was responsible for a majority of these incidents. Image: krebsonsecurity.com.<\/p>\n<\/div>\n<p>A review of EarthtoStar\u2019s messages on Star Chat as indexed by the threat intelligence firm <strong>Flashpoint<\/strong> shows this person also sold \u201cAT&amp;T email resets\u201d and AT&amp;T call forwarding services for up to $1,200 per line. EarthtoStar explained the purpose of this service in post on Telegram:<\/p>\n<blockquote>\n<p>\u201cOk people are confused, so you know when u login to chase and it says \u20182fa required\u2019 or whatever the fuck, well it gives you two options, SMS or Call. If you press call, and I forward the line to you then who do you think will get said call?\u201d<\/p>\n<\/blockquote>\n<p>New Jersey prosecutors allege Jubair also was involved in a <a href=\"https:\/\/krebsonsecurity.com\/2022\/08\/how-1-time-passcodes-became-a-corporate-liability\/\" target=\"_blank\" rel=\"noopener\">mass SMS phishing campaign during the summer of 2022<\/a> that stole single sign-on credentials from employees at hundreds of companies. The text messages asked users to click a link and log in at a phishing page that mimicked their employer\u2019s <strong>Okta<\/strong> authentication page, saying recipients needed to review pending changes to their upcoming work schedules.<\/p>\n<p>The phishing websites used a Telegram instant message bot to forward any submitted credentials in real-time, allowing the attackers to use the phished username, password and one-time code to log in as that employee at the real employer website.<\/p>\n<p>That weeks-long SMS phishing campaign led to intrusions and data thefts at more than 130 organizations, including <strong>LastPass<\/strong>, <strong>DoorDash<\/strong>, <strong>Mailchimp<\/strong>, <strong>Plex<\/strong> and <strong>Signal<\/strong>.<\/p>\n<div id=\"attachment_61104\" style=\"width: 760px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-61104\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-61104\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2022\/08\/amitaico.png?resize=750%2C441&#038;ssl=1\" alt=\"\" width=\"750\" height=\"441\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/08\/amitaico.png 1427w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/08\/amitaico-768x452.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2022\/08\/amitaico-782x460.png 782w\" sizes=\"(max-width: 750px) 100vw, 750px\"><\/p>\n<p id=\"caption-attachment-61104\" class=\"wp-caption-text\">A visual depiction of the attacks by the SMS phishing group known as 0ktapus, ScatterSwine, and Scattered Spider. Image: Amitai Cohen twitter.com\/amitaico.<\/p>\n<\/div>\n<h2>DA, COMRADE<\/h2>\n<p>EarthtoStar\u2019s group Star Chat specialized in phishing their way into business process outsourcing (BPO) companies that provide customer support for a range of multinational companies, including a number of the world\u2019s largest telecommunications providers. In May 2022, EarthtoStar posted to the Telegram channel \u201cFrauwudchat\u201d:<\/p>\n<blockquote>\n<p>\u201cHi, I am looking for partners in order to exfiltrate data from large telecommunications companies\/call centers\/alike, I have major experience in this field, [including] a massive call center which houses 200,000+ employees where I have dumped all user credentials and gained access to the [domain controller] + obtained global administrator I also have experience with REST API\u2019s and programming. I have extensive experience with VPN, Citrix, cisco anyconnect, social engineering + privilege escalation. If you have any Citrix\/Cisco VPN or any other useful things please message me and lets work.\u201d<\/p>\n<\/blockquote>\n<p>At around the same time in the Summer of 2022, at least two different accounts tied to Star Chat \u2014 \u201c<strong>RocketAce<\/strong>\u201d and \u201c<strong>Lopiu<\/strong>\u201d \u2014 introduced the group\u2019s services to denizens of the Russian-language cybercrime forum <strong>Exploit<\/strong>, including:<\/p>\n<p>-SIM-swapping services targeting Verizon and T-Mobile customers;<br \/>\n-Dynamic phishing pages targeting customers of single sign-on providers like Okta;<br \/>\n-Malware development services;<br \/>\n-The sale of extended validation (EV) code signing certificates.<\/p>\n<div id=\"attachment_72222\" style=\"width: 759px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-72222\" decoding=\"async\" loading=\"lazy\" class=\" wp-image-72222\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/kela-lopiu.png?resize=749%2C414&#038;ssl=1\" alt=\"\" width=\"749\" height=\"414\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/kela-lopiu.png 1010w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/kela-lopiu-768x424.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/kela-lopiu-782x432.png 782w\" sizes=\"(max-width: 749px) 100vw, 749px\"><\/p>\n<p id=\"caption-attachment-72222\" class=\"wp-caption-text\">The user \u201cLopiu\u201d on the Russian cybercrime forum Exploit advertised many of the same unique services offered by EarthtoStar and other Star Chat members. Image source: ke-la.com.<\/p>\n<\/div>\n<p>These two accounts on Exploit created multiple sales threads in which they claimed administrative access to U.S. telecommunications providers and asked other Exploit members for help in monetizing that access. In June 2022, RocketAce, which appears to have been just one of EarthtoStar\u2019s many aliases, posted to Exploit:<\/p>\n<blockquote>\n<p>Hello. I have access to a telecommunications company\u2019s citrix and vpn. I would like someone to help me break out of the system and potentially attack the domain controller so all logins can be extracted we can discuss payment and things leave your telegram in the comments or private message me ! Looking for someone with knowledge in citrix\/privilege escalation<\/p>\n<\/blockquote>\n<p>On Nov. 15, 2022, EarthtoStar posted to their <strong>Star Sanctuary<\/strong> Telegram channel that they were hiring malware developers with a minimum of three years of experience and the ability to develop rootkits, backdoors and malware loaders.<\/p>\n<p>\u201cOptional: Endorsed by advanced APT Groups (e.g. Conti, Ryuk),\u201d the ad concluded, referencing two of Russia\u2019s most rapacious and destructive ransomware affiliate operations. \u201cPart of a nation-state \/ ex-3l (3 letter-agency).\u201d<\/p>\n<h2>2023-PRESENT DAY<\/h2>\n<p>The Telegram and Discord chat channels wherein Flowers and Jubair allegedly planned and executed their extortion attacks are part of a loose-knit network known as the <strong>Com<\/strong>, an English-speaking cybercrime community consisting mostly of individuals living in the United States, the United Kingdom, Canada and Australia.<\/p>\n<p>Many of these Com chat servers have hundreds to thousands of members each, and some of the more interesting solicitations on these communities are job offers for in-person assignments and tasks that can be found if one searches for posts titled, \u201cIf you live near,\u201d or \u201cIRL job\u201d \u2014 short for \u201cin real life\u201d job.<\/p>\n<p>These \u201c<a href=\"https:\/\/krebsonsecurity.com\/2022\/09\/violence-as-a-service-brickings-firebombings-shootings-for-hire\/\" target=\"_blank\" rel=\"noopener\">violence-as-a-service<\/a>\u201d solicitations typically involve \u201cbrickings,\u201d where someone is hired to toss a brick through the window at a specified address. Other IRL jobs for hire include tire-stabbings, molotov cocktail hurlings, drive-by shootings, and even home invasions. The people targeted by these services are typically other criminals within the community, but it\u2019s not unusual to see Com members asking others for help in harassing or intimidating security researchers and even the very law enforcement officers who are investigating their alleged crimes.<\/p>\n<p>It remains unclear what precipitated this incident or what followed directly after, but on January 13, 2023, a Star Sanctuary account used by EarthtoStar solicited the home invasion of a sitting U.S. federal prosecutor from New York. That post included a photo of the prosecutor taken from the Justice Department\u2019s website, along with the message:<\/p>\n<blockquote>\n<p>\u201cNeed irl niggas, in home hostage shit no fucking pussies no skinny glock holding 100 pound niggas either\u201d<\/p>\n<\/blockquote>\n<p>Throughout late 2022 and early 2023, EarthtoStar\u2019s alias \u201cBrad\u201d (a.k.a. \u201cBrad_banned\u201d) frequently advertised Star Chat\u2019s malware development services, including custom malicious software designed to hide the attacker\u2019s presence on a victim machine:<\/p>\n<blockquote>\n<p>We can develop KERNEL malware which will achieve persistence for a long time,<br \/>\nbypass firewalls and have reverse shell access.<\/p>\n<p>This shit is literally like STAGE 4 CANCER FOR COMPUTERS!!!<\/p>\n<p>Kernel meaning the highest level of authority on a machine.<br \/>\nThis can range to simple shells to Bootkits.<\/p>\n<p>Bypass all major EDR\u2019s (SentinelOne, CrowdStrike, etc)<br \/>\nPatch EDR\u2019s scanning functionality so it\u2019s rendered useless!<\/p>\n<p>Once implanted, extremely difficult to remove (basically impossible to even find)<br \/>\nDevelopment Experience of several years and in multiple APT Groups.<\/p>\n<p>Be one step ahead of the game. Prices start from $5,000+. Message @brad_banned to get a quote<\/p>\n<\/blockquote>\n<p>In September 2023 , both MGM Resorts and Caesars Entertainment suffered ransomware attacks at the hands of a Russian ransomware affiliate program known as <strong>ALPHV<\/strong> and <strong>BlackCat<\/strong>. Caesars <a href=\"https:\/\/www.courtwatch.news\/p\/how-the-fbi-tracked-down-the-15-million-caesars-casino-ransom\" target=\"_blank\" rel=\"noopener\">reportedly paid a $15 million ransom<\/a> in that incident.<\/p>\n<p>Within hours of MGM publicly acknowledging the 2023 breach, members of Scattered Spider were claiming credit and telling reporters they\u2019d broken in by social engineering a third-party IT vendor. At a hearing in London last week, U.K. prosecutors told the court Jubair was found in possession of more than $50 million in ill-gotten cryptocurrency, including funds that were linked to the Las Vegas casino hacks.<\/p>\n<p>The Star Chat channel was finally banned by Telegram on March 9, 2025. But U.S. prosecutors say Jubair and fellow Scattered Spider members continued their hacking, phishing and extortion activities up until September 2025.<\/p>\n<p>In April 2025, the Com was buzzing about the publication of \u201c<strong>The Com Cast<\/strong>,\u201d a lengthy screed detailing Jubair\u2019s alleged cybercriminal activities and nicknames over the years. This account included photos and voice recordings allegedly of Jubair, and asserted that in his early days on the Com Jubair used the nicknames Clark and Miku (these are both aliases used by Everlynn in connection with their fake EDR services).<\/p>\n<div id=\"attachment_72224\" style=\"width: 667px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-72224\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-72224\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/09\/comcast-jubair.png?resize=657%2C507&#038;ssl=1\" alt=\"\" width=\"657\" height=\"507\"><\/p>\n<p id=\"caption-attachment-72224\" class=\"wp-caption-text\">Thalha Jubair (right), without his large-rimmed glasses, in an undated photo posted in The Com Cast.<\/p>\n<\/div>\n<p>More recently, the anonymous Com Cast author(s) claimed, Jubair had used the nickname \u201cOperator,\u201d which corresponds to a Com member who ran an automated Telegram-based doxing service that pulled consumer records from hacked data broker accounts. That public outing came after Operator allegedly seized control over the <strong>Doxbin<\/strong>, a long-running and highly toxic community that is used to \u201cdox\u201d or post deeply personal information on people.<\/p>\n<p>\u201cOperator\/Clark\/Miku: A key member of the ransomware group Scattered Spider, which consists of a diverse mix of individuals involved in SIM swapping and phishing,\u201d the Com Cast account stated. \u201cThe group is an amalgamation of several key organizations, including Infinity Recursion (owned by Operator), True Alcorians (owned by earth2star), and Lapsus, which have come together to form a single collective.\u201d<\/p>\n<p>The New Jersey <a href=\"https:\/\/s3.documentcloud.org\/documents\/26103409\/thalhajubaircomplaint.pdf\" target=\"_blank\" rel=\"noopener\">complaint<\/a> (PDF) alleges Jubair and other Scattered Spider members committed computer fraud, wire fraud, and money laundering in relation to at least 120 computer network intrusions involving 47 U.S. entities between May 2022 and September 2025. The complaint alleges the group\u2019s victims paid at least $115 million in ransom payments.<\/p>\n<p>U.S. authorities say they traced some of those payments to Scattered Spider to an Internet server controlled by Jubair. The complaint states that a cryptocurrency wallet discovered on that server was used to purchase several gift cards, one of which was used at a food delivery company to send food to his apartment. Another gift card purchased with cryptocurrency from the same server was allegedly used to fund online gaming accounts under Jubair\u2019s name. U.S. prosecutors said that when they seized that server they also seized $36 million in cryptocurrency.<\/p>\n<p>The complaint also charges Jubair with involvement in a hacking incident in January 2025 against the U.S. courts system that targeted a U.S. magistrate judge overseeing a related Scattered Spider investigation. That other investigation appears to have been the prosecution of <strong>Noah Michael Urban<\/strong>, a 20-year-old Florida man <a href=\"https:\/\/krebsonsecurity.com\/2024\/11\/feds-charge-five-men-in-scattered-spider-roundup\/\" target=\"_blank\" rel=\"noopener\">charged in November 2024 by prosecutors in Los Angeles<\/a> as one of five alleged Scattered Spider members.<\/p>\n<p>Urban pleaded guilty in April 2025 to wire fraud and conspiracy charges, and in August he was sentenced to 10 years in federal prison. Speaking with KrebsOnSecurity from jail after his sentencing, Urban asserted that the judge case gave him more time than prosecutors requested because <a href=\"https:\/\/krebsonsecurity.com\/2025\/08\/sim-swapper-scattered-spider-hacker-gets-10-years\/\" target=\"_blank\" rel=\"noopener\">he was mad that Scattered Spider hacked his email account<\/a>.<\/p>\n<div id=\"attachment_71970\" style=\"width: 611px\" class=\"wp-caption aligncenter\">\n<img data-recalc-dims=\"1\" aria-describedby=\"caption-attachment-71970\" decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-71970\" src=\"https:\/\/i0.wp.com\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/kingbobtweets.png?resize=601%2C485&#038;ssl=1\" alt=\"\" width=\"601\" height=\"485\"><\/p>\n<p id=\"caption-attachment-71970\" class=\"wp-caption-text\">Noah \u201cKingbob\u201d Urban, posting to Twitter\/X around the time of his sentencing on Aug. 20.<\/p>\n<\/div>\n<p>A\u00a0<a href=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2025\/08\/urban-status-hack.pdf\" target=\"_blank\" rel=\"noopener\">court transcript<\/a> (PDF) from a status hearing in February 2025 shows Urban was telling the truth about the hacking incident that happened while he was in federal custody. The judge told attorneys for both sides that a co-defendant in the California case was trying to find out about Mr. Urban\u2019s activity in the Florida case, and that the hacker accessed the account by impersonating a judge over the phone and requesting a password reset.<\/p>\n<p><strong>Allison Nixon<\/strong> is chief research officer at the New York based security firm <strong>Unit 221B<\/strong>, and easily one of the world\u2019s leading experts on Com-based cybercrime activity. Nixon said the core problem with legally prosecuting well-known cybercriminals from the Com has traditionally been that the top offenders tend to be under the age of 18, and thus difficult to charge under federal hacking statutes.<\/p>\n<p>In the United States, prosecutors typically wait until an underage cybercrime suspect becomes an adult to charge them. But until that day comes, she said, Com actors often feel emboldened to continue committing \u2014 and very often bragging about \u2014 serious cybercrime offenses.<\/p>\n<p>\u201cHere we have a special category of Com offenders that effectively enjoy legal immunity,\u201d Nixon told KrebsOnSecurity. \u201cMost get recruited to Com groups when they are older, but of those that join very young, such as 12 or 13, they seem to be the most dangerous because at that age they have no grounding in reality and so much longevity before they exit their legal immunity.\u201d<\/p>\n<p>Nixon said U.K. authorities face the same challenge when they briefly detain and search the homes of underage Com suspects: Namely, the teen suspects simply go right back to their respective cliques in the Com and start robbing and hurting people again the minute they\u2019re released.<\/p>\n<p>Indeed, the U.K. court heard from prosecutors last week that both Scattered Spider suspects were detained and\/or searched by local law enforcement on multiple occasions, only to return to the Com less than 24 hours after being released each time.<\/p>\n<p>\u201cWhat we see is these young Com members become vectors for perpetrators to commit enormously harmful acts and even child abuse,\u201d Nixon said. \u201cThe members of this special category of people who enjoy legal immunity are meeting up with foreign nationals and conducting these sometimes heinous acts at their behest.\u201d<\/p>\n<p>Nixon said many of these individuals have few friends in real life because they spend virtually all of their waking hours on Com channels, and so their entire sense of identity, community and self-worth gets wrapped up in their involvement with these online gangs. She said if\u00a0the law was such that prosecutors could treat these people commensurate with the amount of harm they cause society, that would probably clear up a lot of this problem.<\/p>\n<p>\u201cIf law enforcement was allowed to keep them in jail, they would quit reoffending,\u201d she said.<\/p>\n<p><em>The Times of London<\/em> <a href=\"https:\/\/www.thetimes.com\/uk\/technology-uk\/article\/teenagers-charged-tfl-cyberattack-scattered-spider-trdhs5rwf\" target=\"_blank\" rel=\"noopener\">reports<\/a> that Flowers is facing three charges under the Computer Misuse Act: two of conspiracy to commit an unauthorized act in relation to a computer causing\/creating risk of serious damage to human welfare\/national security and one of attempting to commit the same act. Maximum sentences for these offenses can range from 14 years to life in prison, depending on the impact of the crime.<\/p>\n<p>Jubair is reportedly facing two charges in the U.K.: One of conspiracy to commit an unauthorized act in relation to a computer causing\/creating risk of serious damage to human welfare\/national security and one of failing to comply with a section 49 notice to disclose the key to protected information.<\/p>\n<p>In the United States, Jubair is charged with computer fraud conspiracy, two counts of computer fraud, wire fraud conspiracy, two counts of wire fraud, and money laundering conspiracy. If extradited to the U.S., tried and convicted on all charges, he faces a maximum penalty of 95 years in prison.<\/p>\n<p>In July 2025, the United Kingdom followed Australia\u2019s example in banning victims of hacking from paying ransoms to cybercriminal groups unless approved by officials. U.K. organizations that are considered part of critical infrastructure <a href=\"https:\/\/www.thetimes.com\/uk\/technology-uk\/article\/ransoms-hackers-cyber-crime-t5kjldwwm\" target=\"_blank\" rel=\"noopener\">reportedly<\/a> will face a complete ban, as will the entire public sector. U.K. victims of a hack are now required to notify officials to better inform policymakers on the scale of Britain\u2019s ransomware problem.<\/p>\n<p>For further reading (bless you), check out <a href=\"https:\/\/www.bloomberg.com\/news\/features\/2025-09-19\/multimillion-dollar-hacking-spree-scattered-spider-teen-s-jailhouse-confessions\" target=\"_blank\" rel=\"noopener\">Bloomberg\u2019s poignant story<\/a> last week based on a year\u2019s worth of jailhouse interviews with convicted Scattered Spider member Noah Urban.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    BrianKrebs<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/krebsonsecurity.com\/2025\/09\/feds-tie-scattered-spider-duo-to-115m-in-ransoms\/\">Go to krebsonsecurity<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Feds Tie \u2018Scattered Spider\u2019 Duo to $115M in Ransoms U.S. prosecutors last week levied criminal hacking charges against 19-year-old U.K. national Thalha Jubair for allegedly being a core member of Scattered Spider, a prolific cybercrime group blamed for extorting at least $115 million in ransom payments from victims. The charges came as Jubair and an [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[188,481,1864,1536,1537,1865,1866,1867,189,1868,1542,1319,1543,1869,55,1870,1545,1871,158,190,221,1872,223,1549,231,1873,1874,1875,225,1876,1877,227,1551,1878,1879,483],"tags":[72],"class_list":["post-7181","post","type-post","status-publish","format-standard","hentry","category-a-little-sunshine","category-allison-nixon","category-alphv","category-amtrak","category-asyntax","category-blackcat","category-caesars-entertainment","category-com","category-data-breaches","category-earthtostar","category-everlynn","category-flashpoint","category-harrods","category-infinity-recursion","category-krebsonsecurity","category-lopiu","category-marks-spencer","category-mgm-resorts","category-microsoft","category-neer-do-well-news","category-noah-michael-urban","category-nvidia","category-okta","category-owen-david-flowers","category-ransomware","category-rocketace","category-rockstar-games","category-samsung","category-scattered-spider","category-star-chat","category-star-sanctuary","category-t-mobile","category-thalha-jubair","category-transport-for-london","category-uber","category-unit-221b","tag-krebsonsecurity"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7181"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7181"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7181\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7181"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7181"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7181"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}