Early Scattered Spider member pleads guilty to cybercrime spree

A Key Player in Notorious Cybercrime Ring Pleads Guilty to Extortion Attacks

A 24-year-old Texas man has pleaded guilty to federal charges for his role in a series of extortion attacks carried out by a subset of the notorious cybercrime group, The Com. Ahmed Hossam Eldin Elbadawy’s guilty plea was made last year but only came to light this week when prosecutors filed an order seeking proceeds from his crimes.

Elbadawy and his co-conspirators, including Noah Michael Urban and Tyler Robert Buchanan, formed a subset of The Com known as Scattered Spider. This financially motivated crew used social engineering tactics to obtain sensitive company data, which they then used to identify high-net-worth employees with virtual currency accounts containing millions of dollars.

The gang’s modus operandi was to steal virtual currency from the wallets controlled by their victims. Between 2021 and 2023, Elbadawy and his co-conspirators targeted at least 12 companies across various sectors, including entertainment, telecom, technology, and business process outsourcing. The most significant thefts included virtual currency worth nearly $6.35 million in September 2021, $571,000 in June 2022, and nearly $1.7 million in December 2022.

Prosecutors are now seeking to seize significant assets from Elbadawy, including Bitcoin valued at over $14.19 million, Ethereum worth more than $3.4 million, and nearly $63,000 in cash. The authorities have also requested the forfeiture of luxury items such as a lifted golf cart, three high-end vehicles, a painting of Muhammad Ali, luxury watches, gold jewelry, designer bags, and 150 pairs of shoes.

The guilty plea marks another significant blow to Scattered Spider, but it’s clear that others have taken up the mantle. The Com has grown exponentially since its inception, with thousands of members – mostly young people between 11 and 25 years old – splintered into three primary subsets: Hacker Com, In Real Life Com, and Extortion Com. These interconnected networks are responsible for a wide range of cybercrimes, including swatting, extortion, sextortion, child sexual abuse material production and distribution, violent crime, and more.

As the investigation continues to unfold, it’s essential for businesses and individuals to remain vigilant against social engineering tactics and data breaches. By understanding how these attacks work and being proactive in protecting their assets, companies can reduce their risk of falling victim to these types of cybercrimes.

In light of this case, we recommend that organizations review their security protocols and ensure that employees are trained on identifying and reporting potential phishing attempts. Additionally, businesses should consider implementing robust data protection measures, such as multi-factor authentication and encryption, to safeguard sensitive information. By taking proactive steps to protect themselves, individuals and companies can mitigate the risk of falling prey to these types of extortion attacks.


Source: CyberScoop — 2026-09-18