A Core Member of Scattered Spider Pleads Guilty to Extortion Attacks, Faces Millions in Forfeiture
In a significant blow to one of the most notorious subsets of The Com, Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, has pleaded guilty to federal charges related to a string of extortion attacks. Between 2021 and 2023, Elbadawy and his co-conspirators, part of the Scattered Spider subset, targeted high-net-worth employees with virtual currency accounts containing millions of dollars.
The group’s modus operandi involved using social engineering tactics to obtain sensitive company data, which they then used to identify and extort individuals with lucrative cryptocurrency holdings. This is not an isolated incident – Elbadawy’s co-conspirators, including Noah Michael Urban and Tyler Robert Buchanan, have also faced charges and sentencing in recent months. The Scattered Spider subset of The Com has been linked to at least 12 victim companies across various sectors, including entertainment, telecom, technology, and cloud services.
The cybercrime spree resulted in significant financial losses for the victims, with some cases involving thefts worth millions of dollars. In one instance, Elbadawy’s co-conspirators stole virtual currency valued at nearly $6.35 million in September 2021 alone. Authorities have also seized various assets from Elbadawy, including Bitcoin and Ethereum worth over $17 million, as well as luxury vehicles, jewelry, designer bags, and other high-end items.
The indictment against Elbadawy and his co-conspirators highlights the complex nature of The Com’s operations. As one of the largest hacking collectives in existence, it has splintered into three primary subsets: Hacker Com, In Real Life Com, and Extortion Com. These interconnected networks have been linked to a wide range of cybercrimes, including swatting, extortion, and production of child sexual abuse material.
The guilty plea by Elbadawy marks a significant victory for federal authorities in their efforts to dismantle Scattered Spider’s operations. However, it remains to be seen whether this will have any impact on the collective’s overall activity levels or membership numbers. As The Com continues to evolve and adapt, businesses must remain vigilant against these types of threats.
If you’re a business owner or executive, take heed: scammers often use social engineering tactics to obtain sensitive data. To protect your organization, ensure that all employees are aware of the risks associated with phishing and other types of cyberattacks. Implement robust security measures, including multi-factor authentication and regular software updates, to prevent unauthorized access to sensitive systems and data. By staying informed and taking proactive steps, you can reduce the risk of falling victim to these types of attacks.
Source: CyberScoop — 2026-09-18