❌

Reading view

There are new articles available, click to refresh the page.

ShinyHunters claims attack on FBI exposes almost all agents

The FBI is investigating an attack on its own systems after ShinyHunters claimed responsibility for the incident, putting the prolific cybercrime group in the most direct conflict yet with agents responsible for investigating data extortion attacks.

The Monday breach, first reported by 404 Media, allowed ShinyHunters to temporarily deface the FBI jobs site. The group claimed it stole “very sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job,” in a lengthy post on its data-leak site.

“The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” a spokesperson for the agency said in a statement.

An alert on the FBI jobs site notes that apply.fbijobs.gov and the Special Agent Application Portal are currently unavailable.

The attack marks a sobering escalation by ShinyHunters, a notorious group that previously targeted major cloud platforms, healthcare organizations, universities, technology companies, retailers and education service providers. Previous victims of ShinyHunters this year include Instructure, Salesforce, Snowflake and McKesson.

“The ShinyHunters ransomware group appears to be actively trying to put a target on their back,” Cynthia Kaiser, senior vice president at Halcyon’s ransomware research center, told CyberScoop. 

ShinyHunters claims it targeted the FBI in response to a public service announcement it says contains false allegations about the group. The FBI issued the PSA following ShinyHunters’ May attack on Instructure, the company behind Canvas, a widely used central hub for K-12 and university coursework, exams and communication. 

The group responded with its own “PSA” on its data-leak site, insisting it is not affiliated with The Com, has never conducted swatting attacks or claimed it had sensitive or compromising information, including embarrassing photos or videos, to extort victims. 

The PSA was addressed to Brett Leatherman, assistant director of the FBI’s cyber division, and FBI Director Kash Patel. 

“While ShinyHunters has in the past been hyperbolic about the criticality of the data they’ve accessed, the group has established itself as a legitimate threat,” Flashpoint analysts told CyberScoop. 

“This attack benefits ShinyHunters by bolstering their reputation as a credible threat,” the analysts added. “In the group’s statement on their leak site regarding the breach, they portray the FBI’s PSA as an “attempt to ‘disrupt’ our operations and hinder clients’ trust in our organization hoping nobody pays us.”

The threat group typically uses social engineering, abuses weaknesses in identity systems or exploits vulnerabilities to gain access to cloud-hosted environments containing troves of sensitive or proprietary data, which it threatens to leak if the victim doesn’t pay a ransom.

ShinyHunters doesn’t appear to be seeking a payoff in this case, but rather a bid to coerce the FBI into amending or removing the May PSA. The group didn’t make any direct threat in the data-leak site post to release the stolen data, but it set a deadline of one week for action.

That coercive approach toward the FBI could backfire, according to experts. 

“Ransomware groups are largely successful because they operate like businesses,” said Kaiser, a former deputy assistant in the FBI’s cyber division. “Targeting other criminal groups or law enforcement — especially in ways intended to publicly shame — demonstrates a lack of discipline that historically has led to takedowns, takeovers or defections.”

The post ShinyHunters claims attack on FBI exposes almost all agents appeared first on CyberScoop.

Feds accuse China of ‘systematic’ distillation of U.S. AI models

 The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities. 

According to a joint cybersecurity advisory from the National Security Agency, the Cybersecurity and Infrastructure Security Agency and the FBI, the sheer scale of these efforts since 2024 indicate that distillation is a critical part of China’s AI industrial policy.

“China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy,” the agencies wrote. 

The advisory names Chinese companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, saying they spent billions of tokens across millions of exchanges and requests with frontier U.S. AI models like Anthropic’s Claude, OpenAI’s ChatGPT, Google Gemini, and xAI’s Grok, since at least late 2024.

The U.S. agencies said the companies used data culled from these interactions to strengthen their own domestic models, a practice that is tacitly encouraged but not directed by political leaders in Beijing.

DeepSeek, for example, distilled frontier U.S. models to generate synthetic training data for its R1 and R3 models, including four different versions of Claude, two versions of Gemini, five versions of ChatGPT and Grok 4. Those models helped train DeepSeek’s capabilities in areas like agentic functioning, question and answer optimization, creative and occupational writing and others.

Another Chinese company, Moonshot AI, allegedly distilled 18 different U.S. models – including Fable 5, Anthropic’s current, most advanced commercially available model – to train its Kimi-K2 and Kimi K3 models. The company used millions of queries meant to extract enhanced capabilities in areas like agentic reasoning, coding and data analysis, computer vision, larger logical frameworks, visual processing and others.

Chinese AI companies manage a sophisticated set of tools and systems that route requests and prompts through multiple pathways to avoid detection.

The advisory lists common tactics observed by Chinese companies, including spreading requests across different accounts, models and platforms, using native APIs, remote cloud providers, and third-party aggregators to obfuscate user metadata, and leveraging proxies and gray tech markets to get around geographic restrictions, terms of use and safeguards built into frontier models.

“Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations,” the advisory stated.

For decades, U.S. national security officials and western business leaders have accused China of leveraging cyberattacks, insider threats and other forms of economic espionage to pilfer proprietary or sensitive technologies from U.S. businesses.

In June, Michael Kratsios, White House head of Office of Science and Technology Policy, made a similar accusation about MoonshotAI of distilling Fable 5 to train its own models, and described a similar “sophisticated” system for evading guardrails and restrictions on usage.

The warning Tuesday levies similar charges about Chinese theft of American tech, but for frontier AI companies that are facing lawsuits themselves from artists, authors, media organizations and other parties who say AI companies illegally trained their models on copyrighted or trademarked work.

Even within the competitive AI industry, companies and open-source organizations commonly share weights and measures for AI systems, or distill other AI systems in the course of legitimate work or research.

The agencies acknowledge this reality, but claim that Chinese companies are engaged in “aggressive, malicious, and targeted distillation activities at an industrial scale.”

The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop.

In most cities, nobody owns the whole network

Editor’s note: Waco bought the network segmentation technology described here from Elisity while Mike Searight was the city’s chief information officer. He is now a senior adviser to Elisity, a cybersecurity company.

I stood in front of a network cabinet at one of Waco’s water treatment plants, tracing what systems could reach which. The plant’s controls were on that network. So was the branch library. So was the register at the municipal golf course. During my time as chief information officer of a city with 145,000 residents, nobody had ever been asked to inventory what was on that network.

In July, intruders compromised water and wastewater treatment equipment.  Most of that equipment was reachable over public cellular networks, which means they were outside the boundary most utilities thought they were defending. None of the asset lists I have reviewed would have caught it.

Two decisions stand between a small utility and that equipment: who is accountable for the whole network, and where the funding comes from. Neither is technical. Both rest with city manager and councils. Both can be resolved this fiscal year with money already in a budget request.

What the July reports actually say

Three accounts tell different stories. CISA identified over 100 compromised systems in the water and wastewater sector during July, typically through controllers connected directly to cellular modems. The FBI and the EPA reported on July 30 that utilities in at least seven states had reported incidents to the FBI since July 27. Press accounts citing unnamed officials put the number of affected states at a dozen or more.

No federal agency has attributed the late-July water incidents to anyone, and neither will I. A joint advisory does name Iranian-affiliated actors, but for the broader campaign, which is linked to a separate set of intrusions. The advisory was revised July 22, five days before utilities began reporting. That revision expanded the known targeting from Rockwell Allen-Bradley to Schneider Electric, Siemens and potentially others., So the controller brand on the panel no longer settles anything.

The reported effects were operational: a loss of visibility and, in some cases, function. In Clayton County, Georgia, a pump station failed around 1 a.m. on July 27. The boil-water advisory lifted the next day. In early August, the authority serving more than260,000 people said unauthorized cyber activity may have caused or contributed to the disruption. That hedge is deliberate.

The exposure nobody scanned for

The standard answer: they separated the plant network years ago. That’s legitimate work. But it doesn’t matter. The vulnerable controllers never were on the city network—they ran on public cellular links. A modem installed years ago exists nowhere in the asset list and nowhere on network scans. But every carrier invoice lists every SIM the city pays for. Only accounts payable tracks them. Matching those invoices to actual devices costs nothing and can start Monday. The FBI and the EPA also tell utilities to consider isolated architectures for that equipment, and a private access point name tops their list.

Nobody owns the whole network

Most of these systems sit outside the IT department on the org chart, each with its own budget, vendors, and boss. The plant answers to public works. Cameras and card readers arrived with a building project, and most cities treat them like light fixtures. In every city I’ve worked in, exactly one person in IT understands the whole picture. When that engineer leaves, the security posture leaves with them. And nobody owns accountability for the network they all share.

Reporting rules also miss the point. Texas—my example—requires local governments to report security incidents within 48 hours, but only if they involve personal-information breaches or ransomware. An intrusion that seizes control of a controller while touching either sits outside that trigger., That’s exactly what happened in July.

The federal rule requiring a covered cyber incident to be reported within 72 hours was supposed to be finalized in October 2025; CISA is now targeting this month. But nothing determines who owns the network.

Money the utility already applies for

The second answer is there is no budget. Wrong. The fund mechanics matter more than the size of the check.

For State Fiscal Year 2026, the Texas Water Development Board added cybersecurity to the scoring criteria in its Intended Use Plan for the Drinking Water State Revolving Fund. Two questions on the Project Information Form now carry five priority points between them: Oone asks if the governing body adopted a cybersecurity awareness plan in the last five years; the other asks if a project fixes a deficiency found in a cybersecurity assessment. Five points is modest– I won’t oversell it– but this fund is a ranked competition decided at the margins.

Waco segmented five treatment plants—four drinking water and one wastewater—in 43 days against the 90 I’d promised City Council. No bond. No capital request. The utility director funded it from operating accounts using a contract already on the city’s books, rather than an RFP. They carried it to Council because the network was theirs to own.

Those were budget choices ahead of anything else. An operating line competes with a maintenance contract and can be approved this quarter, while the same money in the capital plan waits for a bond cycle. A smaller city without a CIO will not repeat that schedule. The funding mechanics are the same ones.

Every CIO knows how to segment a network. Almost nobody does it, because they are afraid of taking a plant down. Simulate before you enforce. One operating rule came out of it: being on the network allows a device nothing. Plant controls talk only to their SCADA server. Everything else is denied unless explicitly allowed.

City managers, university presidents, superintendents and chief executives are willing to invest in cybersecurity when they trust the investment will make a measurable difference. These leaders spend taxpayer dollars in public view, and the public’s trust rides on every line item as much as the money does. What earns their approval is transparency: a complete picture of what they are protecting, and evidence that critical infrastructure is defended against threats from the open internet and from inside their own network. That standard—full visibility, provable protection—is what every organization should be working toward.

Microsegmentation protects critical systems without the need for rip-and-replace. It isolates water treatment plants, 911 dispatch, public safety alerts, and traffic management from internal and external threats—all on networks cities already own. Modern platforms deploy in weeks rather than budget cycles, making this control finally achievable. Every CIO and CISO should evaluate it now. Microsegmentation is zero-trust’s foundation and the most direct defense of infrastructure residents depend on.

Somebody to call

None of this reaches a two-person utility that can’t write competitive applications. That’s where states must lean in. New York adopted what it calls the first-in-the-nation water cybersecurity rules in March with grants and free technical support. Texas has stood up a Cyber Command with an explicit water and wastewater mandate. A small city needs a number to call and people who answer.

That number now exists. On Monday, Texas Gov. Greg Abbott and National Cyber Director Sean Cairncross launched Project Watershed 250 in San Antonio — a six-month pilot that puts Texas Cyber Command, the National Cyber Director’s office, the EPA and CISA, and a dozen private cybersecurity and technology companies behind Texas water utilities. Participating systems get red-team testing, vulnerability assessments and help hardening what the assessments find, at no cost, with plans to take the model nationwide after the pilot. If you run a Texas water system, you should be reaching out immediately.

For the smallest systems, DEF CON Franklin and the National Rural Water Association have put volunteers and five managed detection providers behind them.

Where to start

Here are three things CIOs and CISO can do that do not have to wait for a grant or a budget cycle: Name one position accountable for every device on the utility network and put it in writing. Match twelve months of carrier invoices to actual devices and sites. Read your state’s Intended Use Plan scoring criteria before the next application.

Nothing in Waco moved until the first of those was settled. The other two cost nothing more than somebody’s afternoon. Most cities haven’t even put someone in the that position.

The post In most cities, nobody owns the whole network appeared first on CyberScoop.

FBI raises alarm over deceptive phishing campaign targeting prominent people

Attackers are targeting prominent, high-profile people, their family members and acquaintances on a commercial messaging application to gain long-term access to their accounts containing sensitive data, the FBI warned in an alert Tuesday.

Officials did not describe the objectives or origins of the attackers, which have more recently impersonated government officials, journalists and publicly known personalities. Attackers are tricking victims into granting them access to a legitimate cloud service, such as Microsoft or Google, under the guise of reviewing a draft article or document.

The ongoing threat, which the FBI has been tracking since late 2025, showcases a “deceptive, sophisticated approach to access user accounts without requiring a password,” the FBI wrote in the public service announcement. The malicious links, which enable OAuth consent phishing, provide attackers with persistent access to a targeted victim’s account.

“Once permission is obtained, it can only be revoked by the victim invalidating the token in their application security settings — not by changing the password,” the FBI wrote.

Authorities did not provide any details about the victims targeted by the campaign or how many people have already been compromised by these attacks. Threat actors previously impersonated event coordinators and planners, using invitations and identity verification requests as lures to gain access to their accounts.

By social engineering unsuspecting victims via OAuth consent phishing, attackers gain full visibility into the target’s configured permissions, allowing them to access emails, files and other sensitive data.

“If the user approves the request, they unwittingly grant high-level access to a malicious application controlled by the cyber actor,” the FBI added. “By registering malicious applications through legitimate authorization protocols and using social engineering tactics, cyber actors can bypass both passwords and multi-factor authentication, which makes consent phishing especially dangerous.”

OAuth is a standardized and widely adopted protocol for authorizing access to applications and other services, including APIs. The standard uses tokens to establish and maintain authorized access to separate resources or services. 

The FBI encouraged people to scrutinize communications from unfamiliar phone numbers or accounts, independently verify the identity of the sender and only grant access to trusted applications.

The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop.

McKesson copes with fallout from data theft extortion attack

McKesson said its business and distribution centers remain operational in the wake of a cyberattack it disclosed Friday that resulted in data theft and temporary service interruptions.

Attackers gained access to some of the health care vendor’s third-party applications and stole data associated with a subset of customers in the company’s oncology, multispecialty and medical-surgical business units, Francisco Fraga, chief information and technology officer at McKesson, said in a statement Saturday. 

McKesson is a major player in the healthcare sector, claiming it distributes about one-third of all pharmaceuticals used throughout North America. It reported $403.4 billion in revenue for the one-year period ending in March. 

The company’s size and critical role it serves also makes it a high-profile target for cybercriminals. McKesson did not identify the group behind the attack, but ShinyHunters, a cybercrime group known for targeting large organizations with extortion demands after stealing massive amounts of sensitive data, claimed responsibility.

The company declined to answer questions about ShinyHunter’s claims. Yet, on Friday, McKesson disclosed the attack in a regulatory filing while ShinyHunters added the company to its data-leak site. 

McKesson said it discovered the attack Aug. 25. A period of widespread data theft was over by then, following a four-day intrusion beginning Aug. 21, according to researchers.

“Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to support our response,” Fraga said in a statement. 

“We have reasonable assurance of no ongoing unauthorized activity in our systems. Customers can continue to connect to and use our systems and services as intended,” he added. 

While McKesson’s investigation continues, it faces a more urgent deadline of Sept. 1 from ShinyHunters, which is reportedly seeking a ransom demand in excess of $55 million. 

The company did not answer questions about any ransom demand or whether it responded to the alleged attackers. 

The circumstances of the attack against McKesson are similar to other recent victims of ShinyHunters. The threat group typically uses social engineering or abuses weaknesses in identity to gain access to cloud-hosted environments containing troves of sensitive or proprietary data, which it threatens to leak if the victim doesn’t pay a ransom. 

“Opportunistic data extortionists have been able to identify weaknesses within identity and access management, making these campaigns both cheap and scalable,” said Ian Gray, vice president of cyber threat intelligence at Flashpoint. 

“These attacks are particularly difficult to detect early because they often occur entirely within vendor-hosted environments using valid, socially-engineered credentials,” he added. “Since this activity mimics normal support or data-warehouse tasks, it typically doesn’t trip traditional malware alerts or show anomalies, meaning organizations often remain unaware of the breach until the extortionists make contact.”

Researchers have linked ShinyHunters to multiple attack sprees targeting major cloud platforms, including Oracle, Salesforce and Snowflake. The decentralized crew of cybercriminals was also linked to an expansive compromise last summer impacting hundreds of Salesloft Drift customers that put any platform integrated with the AI chat agent at risk as well. 

In April, ShinyHunters broke into the systems of Canvas — a central hub for K-12 and university coursework, exams, grades and communication — causing widespread outages and data theft. When an early deadline passed without payment, ShinyHunters escalated its pressure on Instructure, the company behind Canvas, by defacing the platform’s login pages with an extortion message that was visible to hundreds of schools.

Instructure ultimately relented and said it reached an agreement with the cybercriminals, insisting the stolen data was returned with assurances that other copies were destroyed.

The FBI issued a public service announcement about ShinyHunters days later, warning potential downstream victims of the threat group’s pressure tactics and claims.

In late July, less than a month before McKesson was hit, Health-ISAC warned organizations in the sector of an increase in successful attacks by ShinyHunters.

The post McKesson copes with fallout from data theft extortion attack appeared first on CyberScoop.

What the World Cup can teach us about cybersecurity resilience

With the World Cup now complete, its biggest cybersecurity story may be what didn’t happen. While no major public cyber disruption has been reported, that shouldn’t be mistaken for a lack of risk. 

In the run-up to the tournament, the FBI’s Internet Crime Complaint Center (IC3) issued a public service announcement warning organizations and fans about fraudulent, spoofed websites impersonating the FIFA event – a reminder that the absence of a headline-grabbing breach doesn’t mean bad actors weren’t trying. In many ways, it’s evidence of the planning, coordination, and resilience required to keep an event of this scale running securely.

A global event like the World Cup depends on far more than what happens inside the stadium. It relies on local governments, venues, transportation systems, telecom providers, payment platforms, hotels, vendors, public safety agencies, and law enforcement, all working together. 

When I worked at the FBI, I saw how fast major events test teamwork across agencies, regions, and businesses. The World Cup offered that test at a scale few events can match.

Successful resilience is built months before kickoff

Successful major-event security depends on what happens long before there is a visible incident: trusted relationships, clear roles, shared intelligence and response plans. Planning becomes even more important when an event is not limited to a single city or venue.

In the past, event security consisted of guards, gates, and stadium perimeters. Those still matter, but they’re only part of the picture. Today, an event this big that brings millions of people together depends on many systems working in concert. No single organization owns the full risk picture, which means resilience depends on how well these groups can share information, coordinate response plans, and keep essential services operating under pressure. This means security can’t be planned around one perimeter. The real perimeter is the full event ecosystem.

Resilience starts much earlier, with planning across organizations that may not normally operate as one team. The real test for major events is whether public- and private-sector partners know their roles before pressure hits. That includes who shares information, who validates threats, who communicates with the public, who has decision-making authority and how quickly partners can act if a system slows down or becomes unavailable.

Major events are only as resilient as the systems behind them

Attackers don’t need to compromise the most visible organization to create disruption. They can look for weaker points across the event ecosystem. A disruption may begin with a vendor, ticketing platform, transportation partner, payment provider, hotel, contractor or communications provider, but the impact can quickly become broader than any one organization.

Sports organizations now operate like large businesses, with ticketing systems, VIP data, sponsors, vendors, media partners, stadium operations, payment systems, and fan engagement platforms. They depend on networks of suppliers and partners, and that creates multiple possible entry points.

Operational technology (OT) deserves more attention than it typically gets in these conversations. A ransomware attack that disrupted stadium operations directly, rather than a ticketing site or a fan-facing app, would be one of the most damaging scenarios organizers could face. OT security has to sit alongside the more visible concerns like payment fraud and spoofed domains, not behind them.

Bad actors don’t let a good crisis go to waste. Fans are often an easy target. Excitement drives a fan to buy a last-minute ticket or check a score on an unknown site. That excitement is exactly what fraudsters count on.

This risk grows over time. As the event gets closer and attracts more eyes, it becomes a richer target. A fake FIFA ticket site is useless to a crook a month after the last game. Groups running these systems must act faster as opening day nears, and share threat intelligence without delay.

Threat intelligence turns planning into proactive defense

The World Cup may be over, but the work isn’t. Cities, governments, and private-sector organizations will continue supporting large-scale public events that depend on complex digital and physical ecosystems. The question isn’t whether another major event will face cyber threats, it’s whether the planning starts early enough.

Organizations involved in future major events should focus on resilience, not just prevention. That means planning for what happens if a critical system slows down, goes offline, or becomes unreliable, and ensuring partners know how to coordinate before an incident occurs.

Every major event forces defenders to prepare for known risks. The harder challenge is anticipating the ones that haven’t emerged yet.

The next major disruption may not come from the attack that organizations spent months preparing for. It could target a new dependency, exploit emerging technology, or capitalize on a moment when public attention is at its highest. That’s why resilience can’t be built around yesterday’s playbook. It has to be informed by continuous threat intelligence, regular coordination across public- and private-sector partners, and the flexibility to adapt as the threat landscape changes.

The World Cup demonstrated what’s possible when that preparation comes together. As cities, governments, and private organizations look ahead to future global events, success won’t be measured solely by the attacks they stop. It will be measured by how effectively they can maintain critical operations, share information, and adapt under pressure when the unexpected happens.

The post What the World Cup can teach us about cybersecurity resilience appeared first on CyberScoop.

Leading members of Scattered Spider sentenced in UK to 66 months in jail

A pair of young men were sentenced to 66 months in jail for committing a cyberattack on the Transport for London that brought the network’s operations to a standstill in 2024, the United Kingdom’s National Crime Agency said Thursday.

Thalha Jubair and Owen Flowers were arrested at their homes in September 2025, barely a year after the attack, and pleaded guilty last month just as their trials were set to begin. Flowers was previously arrested in connection with the attack in September, but was released after questioning by officers.

Jubair and Flowers were leading members and highly involved in Scattered Spider, a nebulous hacker subset of The Com, according to researchers. The 20-year-old Jubair was a prolific cybercriminal and core member of the unbound collective. 

U.S. authorities last year accused Jubair of direct, prominent involvement in at least 120 cyberattacks, including extortion of 47 U.S.-based organizations and the January 2025 attack on the federal court system. 

Officials said they traced a combined total of at least $89.5 million in cryptocurrency, at the time of payments, to Bitcoin addresses and servers controlled by Jubair. Two financial services firms paid Jubair $25 million and $36.2 million, respectively, in Bitcoin between June and November 2023, according to an unsealed criminal complaint against Jubair. 

At the time of Jubair’s arrest, “he was one of the four principal people that we associated with Scattered Spider,” and one of the two most core players, Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. 

Jubair and Owens had significant resources and support, and “victim payments were reinvested back into the enterprise,” said Allison Nixon, chief research officer at Unit 221B. 

The lasting impact of Jubair and Owens’ capture and imprisonment remains hazy.

U.K. authorities insist Jubair and Owens’ arrests and punishment “effectively halted the group’s criminal activity,” yet they added that other cybercriminals continue to use the Scattered Spider brand in more recent attacks. 

Thursday’s announcement “represents a significant step in holding accountable two members of Scattered Spider, a group that has repeatedly relied on data extortion, SIM-swap attacks, and other social engineering techniques to infiltrate networks and undermine critical services,” Brett Leatherman, assistant director of the FBI Cyber Division, said in a statement. 

The FBI also noted, in a LinkedIn post, that members of Scattered Spider “continue to victimize organizations around the world and cause significant financial and operational harm.”

When Owens, now 18, was first arrested for the Transport for London attack in 2024, investigators said he was “in the process of hacking the systems of U.S. health care companies SSM Health Care Corporation and Sutter Health, which had been infiltrated and damaged.”

Officials also said Jubair and Owens failed to cooperate after their arrests. 

“This is the largest cybercrime prosecution ever brought before the U.K. courts and the culmination of nearly two years of painstaking work,” Paul Foster, head of the National Crime Center’s National Cybercrime Unit, said in a statement. 

“Scattered Spider has been the most significant cybercrime threat to the U.K. in recent years. Through this investigation, we have severely disrupted that threat and brought key offenders to justice,” Foster added.

Despite the upbeat reaction from U.K. officials, Nixon said the punishment for Jubair and Owens is “remarkably lenient considering the period of continuous reoffending lasted longer than the sentence.”

Nixon hopes the United States will eventually extradite the pair to face additional charges. “If that happens, they won’t be able to use mental illness as a loophole to get back to harming society as soon as possible,” she added.

“No one who worked on their case was surprised they would reoffend, and there seems to be no allowance in the law to protect the public from what everyone knew was going to happen,” Nixon said. “I know the narrative in the cybercriminal culture will glorify them, but they wouldn’t if they knew the full story.”

The post Leading members of Scattered Spider sentenced in UK to 66 months in jail appeared first on CyberScoop.

764 splinter group leader sentenced to 40 years in jail

A San Antonio man who sexually exploited children while leading 8884, an offshoot of the notorious violent extremist collective 764, was sentenced to 40 years in prison in federal court Wednesday, the Justice Department said. 

Alexis Aldair Chavez began associating with 764 as a child in 2022 when a co-conspirator introduced him to 7997, one of many 764 offshoots affiliated with the Com. The sprawling nihilistic network of thousands of people, typically between 11 and 25 years old, seek to foster social unrest by destroying civilized society through the corruption and exploitation of children and other vulnerable populations.

The 19-year-old, also known as “Zack” and “Zack8884,” attempted to coerce a girl to commit suicide and blackmailed another girl into self-mutiliation, animal torture and illicit content production in late 2023, according to court records. He later worked with multiple co-conspirators and blackmailed some of his victims to coerce other girls to degrade themselves on camera and produce child sexual abuse material (CSAM).

Chavez was arrested and has been detained without bail since October 2024. He pleaded guilty to multiple crimes involving the sexual exploitation of children in December 2025 and faced up to 60 years in prison for racketeering, distribution and possession of CSAM.

“Chavez’s crimes reveal the ruthless exploitation and manipulation at the core of nihilistic violent extremist groups,” John A. Eisenberg, assistant attorney general for national security, said in a statement. 

“These organizations target children as part of their broader mission to spread terror. These groups ultimately seek nothing less than the destruction of our society,” he added. “The National Security Division will use every resource at its disposal to identify and prosecute 764-linked criminality and to protect the most innocent among us from these predators.”

The indictment filed against Chavez in the U.S. District Court for the Western District of Texas details a series of horrifying crimes he committed with co-conspirators and some of his victims. 

Prosecutors said Chavez and a co-conspirator coerced a girl to cut her tongue, and torture and kill a cat on a live video call in late 2023. He and co-conspirators also, that same month, groomed and extorted several other girls to commit self harm and degrade themselves on camera.

Allison Nixon, chief research officer at Unit 221B, told CyberScoop the sentence is appropriate even if people understandably dislike imprisoning young people. 

“In this space, a certain personality profile is highly predictive of who will risk a prison sentence like this: an obsession with maximizing harm,” she said. 

“Reoffending after release is a huge problem. All major global hacking incidents from the Com are done by serial reoffenders — all obsessed with harmfulness, some graduated from the 764 sextortion space,” Nixon added.

Too many jurisdictions are naive in how they handle cases involving members or associates of the Com, allowing these criminals to go home to parents who won’t supervise them, she said.

Officials pressed on this in their reaction to Chavez’s sentencing as well. “Parents need to know what their children are doing online and must stay engaged, ask difficult questions, and not fall into the trap of believing their child is ‘just playing games’ or ‘just talking with their friends,’” Justin R. Simmons, U.S. attorney for the Western District of Texas, said in a statement. 

“There is darkness present within many people in this world that want nothing more than to see the United States and western civilization fail. There is no limit to the actions these individuals will take to accomplish that goal, including torturing and abusing children,” Simmons added.

Chavez, who was also ordered to pay $10,000 in restitution and serve lifetime supervised release, joins other 764 members already serving long sentences for similar crimes. Bradley Chance Cadenhed, who founded 764 as a 15-year-old in 2021, was arrested later that year and sentenced to 80 years in prison in 2023. 

When the FBI executed a search warrant at Chavez’s residence in July 2024, prosecutors said he came out the backdoor and threw his phone over a neighbor’s fence in an attempt to hide evidence.

Chavez’s sentencing follows a period of heightened law enforcement activity, which has netted arrests of multiple alleged 764 leaders and members. Some of the alleged 764 members arrested since 2025  include: Leonidas Varagiannis and Prasan Nepal, Baron Cain Martin, Tony Christopher Long, Erik Lee Madison, Zachary Sweeney and Aaron Corey. 

“True rehabilitation is the best outcome, but no one knows how,” Nixon said. 

“The total number of offenders who fit this harm-obsessed profile is vanishingly small. Giving them maximum sentences won’t overflow jails,” she added. 

Law enforcement and judges have to be realistic about what it takes to prevent the victimization of children, and handing down lifelong or lengthy prison sentences strikes the right balance between the rights of the offender and society, Nixon said.

FBI officials and agents who track these offenders and gather evidence on their crimes draw similar conclusions. 

“Nothing is more abhorrent than those who prey on children and other vulnerable members of our society and this defendant will pay a steep price for doing just that,” Coult Markovsky, acting assistant director of the FBI’s counterterrorism division, said in a statement.

“This sentencing demonstrates the FBI’s unwavering resolve to identify, hunt down, investigate, and prosecute criminals like Chavez who prey on children through violent online networks, including 764, and orchestrate horrific, unspeakable acts of exploitation and violence,” Daniel Faith, special agent in charge of the FBI San Antonio field office, said in a statement. 

“These predators use social media, messaging apps, gaming platforms, chat rooms, and video services to groom vulnerable children,” Faith added. “Staying engaged in your child’s online life, maintaining open communication, recognizing the warning signs, and reporting suspicious online activity to law enforcement are critical to stopping these offenders.”

The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop.

❌