❌

Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Early Scattered Spider member pleads guilty to cybercrime spree

18 September 2026 at 16:24

Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday.

Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty exactly one year ago to wire fraud conspiracy and aggravated identity theft. His guilty plea wasn’t shared publicly until prosecutors filed an order of forfeiture this week seeking proceeds from Elbadawy’s criminal activities. 

Elbadawy and his co-conspirators — Noah Michael Urban, a Florida man sentenced to 10 years in prison last year, and Tyler Robert Buchanan, a Scottish man who pleaded guilty to multiple cybercrimes in April and awaits sentencing — were part of an aggressive subset of The Com coined Scattered Spider. 

The financially-motivated crew obtained credentials via social engineering and stole sensitive company data to identify high net worth employees with virtual currency accounts containing millions of dollars, according to an indictment filed against Elbadawy and his co-conspirators in late 2024. 

Federal authorities filed charges against five individuals with links to the Scattered Spider cybercrime outfit, including Elbadawy, Urban, Buchanan, Evans Onyeaka Osiebo and Joel Martin Evans in 2024.

Elbadawy’s victims included large businesses in the entertainment, telecom, technology, business process outsourcing, IT, cloud and virtual currency sectors, officials said. Prosecutors linked Elbadawy and his co-conspirators to at least 12 victim companies in the indictment, including three businesses located in Southern California where he awaits sentencing. 

Authorities detailed 29 victims who were compromised by Elbadawy and his co-conspirators. The crew stole virtual currency from wallets controlled by many of those victims. The most high-value thefts included virtual currency worth nearly $6.35 million in September 2021, $571,000 in June 2022 and nearly $1.7 million in December 2022. 

Prosecutors are seeking significant property and asset forfeiture from Elbadawy, including Bitcoin valued at more than $14.19 million, Ethereum valued at more than $3.4 million and nearly $63,000 in cash. Officials also requested the forfeiture of a lifted golf cart, three luxury vehicles, a painting of Muhammad Ali, luxury watches, gold jewelry, a vast collection of designer bags and 150 pairs of shoes.

The terms of Elbadawy’s plea agreement haven’t been released. 

While early leaders of Scattered Spider have been arrested or sentenced for their crimes, others have filled those roles with even more exceptional impact.

The Com has grown to thousands of members, typically between 11 and 25 years old, splintered into three primary subsets the FBI describes as Hacker Com, In Real Life Com and Extortion Com.

Criminal acts committed by these multiple, interconnected networks include swatting, extortion and sextortion of minors, production and distribution of child sexual abuse material, violent crime and various other cybercrimes.

You can read the indictment against Elbadawy and some of his co-conspirators below.

The post Early Scattered Spider member pleads guilty to cybercrime spree appeared first on CyberScoop.

Jail time for Maine child in 764 marks turning point in federal law enforcement

2 September 2026 at 17:03

The FBI said a 17-year-old from Maine is the first child federally charged and adjudicated for crimes stemming from their involvement in 764, a violent extremist collective.

A judge ordered the teen to remain detained after determining they committed multiple crimes, including conspiracy to sexually exploit a child, sexually exploiting and enticing a child, distributing child sexual abuse material, sending interstate threats, cyberstalking victims and identity theft.

“This first-in-the-nation case should make it crystal clear that if you conspire to commit violent, extremist crimes, your age will not shield you from accountability,” Ted Docks, special agent in charge of the FBI’s Boston Division, said in a statement Tuesday. “What this juvenile did would shock most people to their very core, and it is our hope that by publicizing this case, others will be deterred from making the same devastating choices this teen did.”

The nihilistic extremist group the teen participated in, 764, is more broadly affiliated with The Com, a sprawling network of thousands of people, typically between 11 and 25 years old, seeking to foster social unrest by destroying civilized society through the corruption and exploitation of children and other vulnerable populations.

The Justice Department’s resolve in this case — detaining and adjudicating a 764 member before they reach adulthood — marks a turning point and apparent change in internal policy against charging children for federal crimes linked to their involvement in violent extremist groups. 

“Crimes from 764 copycat groups in The Com are extremely serious and it speaks to how law enforcement prioritizes these things,” Allison Nixon, chief research officer at Unit 221B, told CyberScoop. “They recognize this loophole involving minors needs to be closed in order to tackle this social problem of violence arising from minors which crosses state lines.”

The first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime, she added. 

“If you sexually exploit a child, the fact that you yourself are a minor will not protect you from the consequences of your actions,” Andrew Benson, U.S. attorney for the District of Maine, said in a statement.

The Maine teenager, whose identity is being withheld, was ordered to serve a term of official detention followed by supervision, the FBI said. Officials did not provide details about the terms of detention.

Andrew McCormack, assistant U.S. attorney for the U.S. District of Maine, and a spokesperson for the FBI Boston Division, both said federal law restricts what law enforcement can share about cases involving underage criminals and declined to say where the teen lived, where they’re being detained and for how long. 

Nixon conveyed, with some reluctance, the need for more actions like this targeting underage members of 764 and similar groups. 

“I’m not advocating normalizing throwing kids in prison but we very much need to find a new balance to protect society from violent groups that are incentivized by this federal loophole to commit maximum harm before turning 18, and then after 18, to recruit and train kids to do dirty work for them,” she said. “I cannot understate how much this loophole specifically influenced this culture of maximizing harm.”

The teen’s ordered detention marks a continuation of consistently heightened law enforcement activity targeting members of 764 and affiliated groups. 

Kyle William Spitze, an original member of 764 and leader of one of its offshoots, was sentenced to 77 years in prison, the longest imprisonment ever imposed on a nihilistic violent extremist, in federal court in Tennessee in late August.

Alexis Aldair Chavez, who began associating with 764 as a child in 2022 before leading an offshoot 8884, was sentenced to 40 years in prison in July for blackmailing and coercing multiple girls to commit self-harm, torture animals and degrade themselves on camera to produce CSAM. 

Other alleged 764 members arrested since 2025  include: Leonidas Varagiannis and Prasan Nepal, Baron Cain Martin, Tony Christopher Long, Erik Lee Madison, Zachary Sweeney and Aaron Corey.

The FBI said it is currently investigating more than 500 subjects nationwide who are allegedly involved in 764 and its many offshoots. 

“These groups actively target minors and are made up of a large percentage of minors. They are intentionally recruiting juveniles here in the U.S. to conduct criminal acts because, simply put, they think they can get away with it because historically, the federal justice system has rarely prosecuted juveniles,” Docks said. 

“We’re here to tell you, they’re wrong, and if they don’t stop this abhorrent behavior, they too could find the FBI on their doorstep and themselves in federal court. We are going to do everything in our power to protect kids and ensure those who harm them don’t get away with it,” Docks added.

Nixon, who has studied the rise of these violent extremist groups and helped law enforcement identify some of its members, said she’s pleased with this development. 

“Right now the prevailing sentiment within these violent groups is that you can do anything you want with no accountability before you turn 18, so therefore you should commit the most heinous acts possible because it’s your last chance. That’s why there are so many 17 year olds who become a major public nuisance, because it’s their last hurrah — but for bomb threatening schools and abusing little kids,” Nixon said. 

“They slow down on their 18th birthday and pivot to using minors to hide behind, and teaching them this lifestyle,” she added. “Closing that loophole will do a ton to break this cycle. They pay close attention to law enforcement, and just one arrest shatters their sense of safety. I don’t think the FBI will stop at just one arrest.”

The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop.

Interpol targets Black Axe’s illicit financial web in latest international sting

By: Greg Otto
25 August 2026 at 10:25

An international law enforcement operation carried out against organized crime groups in West Africa resulted in 58 arrests and identified 263 suspects, Interpol announced Tuesday.

The operation, known as Operation Jackal IV, aimed to disrupt money laundering, locate high-value targets, seize assets and support prosecutions tied to various Africa-based criminal groups, including Black Axe. 

Black Axe is a highly structured, hierarchical group that generates billions of dollars in criminal proceeds annually from many small-scale operations spanning dozens of countries. The group’s leaders are Nigerian nationals, according to a Europol release issued earlier this year. In January, European law enforcement arrested dozens of the group’s members for adversary-in-the-middle scams such as business email compromise, money laundering and vehicle trafficking. 

“Operation Jackal IV demonstrates the power of international cooperation,” Tomonobu Kaya, director of Interpol’s Financial Crime and Anti-Corruption Centre, said in a release. “By following illicit financial flows across borders, we are attacking the very lifeblood of organized crime and making it increasingly difficult for criminal networks to profit from their activities.”

The agency said it will continue to work to unravel the full details of each case, but detailed several preliminary discoveries from partner organizations Tuesday.

Romanian authorities broke up a group that ran an investment scam from a call center promising high returns in stocks or cryptocurrencies. Victim payments were routed to electronic wallets controlled by the operators, with police estimating the full value at 143 million euros (approximately $166 million). They arrested 11 people and seized about 330,000 euros ($379,000) in cash and cryptocurrency, six properties and several luxury watches.

In South Africa, where 39 of the 58 arrests occurred, police raided seven sites in Johannesburg tied to a syndicate that targeted retirees in English-speaking countries with romance and investment scams. Investigators seized $2.67 million and blocked 257 bank accounts.

Authorities in Argentina identified 196 people linked to a Crime-as-a-Service network suspected of supplying website domains and laundering support to West African groups, making 17 arrests. 

In Italy, one person was identified in connection with a pan-European laundering network built on shell companies, remittance services and cash withdrawals. A single account moved 845,000 euros ($736,000) through 560 transactions.

Investigators also noted the group’s growing focus on sextortion, with victims as young as 14. Similar to actions taken by The Com, Interpol says offenders are contacting teenagers on social media, coercing them into taking explicit images, then demanding payment to keep the material private.

This is not the first time Interpol has taken measures to disrupt African-based groups. In 2024, a similar Interpol operation led to 300 arrests, $3 million in assets seized and 720 blocked bank accounts.

The post Interpol targets Black Axe’s illicit financial web in latest international sting appeared first on CyberScoop.

Apollo discloses data breach from ongoing wave of attacks hitting financial sector

21 August 2026 at 15:14

Apollo Global Management confirmed it was among several financial institutions impacted by a string of social engineering attacks that hit the sector last month, the company said Friday. 

Attackers gained unauthorized access to some of the private equity firm’s cloud platforms between July 6 and July 10, the company said in a data breach notification filed in California. Apollo did not say when or how it became aware of the intrusion and did not respond to a request for comment.

Apollo is the first victim to formally disclose that sensitive personal data under its care was compromised by a wave of attacks that have hit large private equity firms, law firms, financial rating agencies and medical technology companies. 

The company did not name the group responsible for the attack. Yet, Google earlier this month attributed the ongoing campaign to BlackFile, a threat group affiliated with The Com, that recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon. 

“Upon detecting the incident, we promptly notified law enforcement, engaged leading outside cybersecurity and forensic experts, enhanced our security protocols, and launched an investigation,” Matthew Breitfelder, global head of human capital at Apollo, wrote in the disclosure notice. 

As part of its ongoing investigation, Apollo said it determined on Aug. 12 that personal data including names, dates of birth, contact information, home addresses and Social Security numbers were compromised. The company did not say how many people were impacted, but noted it’s thus far found no evidence any data was posted online or used for identity theft or fraud.

Apollo is one of the world’s largest private equity firms, with $1.05 trillion in assets under its management at the end of June, according to a regulatory filing.

Researchers previously told CyberScoop some of Apollo’s largest competitors, including Blackstone and Bain Capital, were also targeted with malicious infrastructure, but it’s unclear if those firms were compromised.

BlackFile and its various affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, and retail and hospitality since the beginning of this year.

The extortion group shifts from one sector to the next, impersonating IT support in voice-phishing and social-engineering attacks before threatening its alleged victims with extortion demands, which often start around $3 million and are typically negotiated down to less than $1 million.

Google researchers also previously said some of the group’s recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents, a tactic adopted by several subsets of The Com.

The post Apollo discloses data breach from ongoing wave of attacks hitting financial sector appeared first on CyberScoop.

Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist

20 August 2026 at 14:34

An original member of 764 and leader of one of its offshoots was sentenced to 77 years in prison, the longest imprisonment ever imposed on a nihilistic violent extremist, the Justice Department said Wednesday.

Kyle William Spitze pleaded guilty in December 2024 to two counts of producing child sexual abuse material, possession of CSAM and distributing animal crush videos. A federal judge in the U.S. District Court for the Eastern District of Tennessee sentenced Spitze to the maximum punishment for each count and ordered him to serve all terms consecutively.

The 27-year-old of Friendsville, Tenn., victimized dozens of girls and coerced multiple victims under threats of doxing and swatting to produce CSAM of themselves, self-mutilate and produce Spitze’s online moniker in their blood. 

When investigators obtained Spitze’s cell phone under a search warrant in February 2024, they found about 25 photo albums titled with nicknames or first names containing the same images and videos he uploaded to his Telegram channel depicting some of these acts. Officials also found videos of dogs, rabbits and chickens being decapitated by his victims under coercion.

In Spitze’s plea agreement, he admitted he had a terrorist motive in committing his crimes. 

“These types of crimes are the worst of the worst: preying on vulnerable children in the name of a violent and twisted ideology. Federal law enforcement will not stop until nihilistic violent extremist groups and their depraved members are identified and prosecuted to the fullest extent of the law,” Attorney General Todd Blanche said in a statement.

Spitze, also known as “Chrimhn,” “Criminal,” and “Criminaloli,” was also an administrator of the 764 network “Harm Nation.” 

The groups, which are affiliated with The Com, are part of a sprawling network of thousands of people, typically between 11 and 25 years old, seeking to foster social unrest by destroying civilized society through the corruption and exploitation of children and other vulnerable populations.

“Today’s sentence of 77 years, the longest federal sentence ever imposed on a nihilistic violent extremist, sends a strong message that civil society will not tolerate such depravity,” John A. Eisenberg, assistant attorney general for national security, said in a statement Wednesday. 

Allison Nixon, chief research officer at Unit 221B, applauded the long sentence. “I wish other countries could recognize that these people are not the kind that rehabilitate, and adjust sentences accordingly,” she said. 

Spitze’s sentencing follows a period of heightened law enforcement activity, which has netted arrests and lengthy prison terms for multiple alleged 764 leaders and members. 

Alexis Aldair Chavez, who began associating with 764 as a child in 2022 before leading an offshoot 8884, was sentenced to 40 years in prison last month for blackmailing and coercing multiple girls to commit self-harm, torture animals and degrade themselves on camera to produce CSAM. 

Other alleged 764 members arrested since 2025  include: Leonidas Varagiannis and Prasan Nepal, Baron Cain Martin, Tony Christopher Long, Erik Lee Madison, Zachary Sweeney and Aaron Corey.

The FBI said it began investigating Harm Nation in December 2023 after Discord sent the agency a report about the group, including members and victims’ use of the platform. Investigators quickly identified Spitze as one of the most prolific members of Harm Nation and the administrator of an affiliated Telegram channel. 

“Today’s sentencing sends a strong message that this FBI and our Department of Justice partners will relentlessly hold accountable any individual who preys on children,” FBI Director Kash Patel said in a statement. 

“This FBI is laser focused on identifying, locating, and arresting any participants in nihilistic violent extremist (NVE) networks — and we have dedicated personnel across all 50 states working on these high-priority investigations,” Patel added. “We arrested 500% more NVE offenders with our partners last year for a reason — because we have a renewed mission to bring these predators to justice, and that’s exactly what we’ll do.”

The post Early 764 member sentenced to 77 years, longest prison term to date for a nihilistic violent extremist appeared first on CyberScoop.

Details emerge on BlackFile’s recent attacks on financial companies

17 August 2026 at 16:41

A cybercrime group responsible for a string of recent attacks against private equity firms, law firms and financial rating agencies remains active and continued to target new victims as of late last week, according to researchers.

BlackFile, which Google Threat Intelligence Group tracks as UNC6671 and associates more broadly with The Com, has been active since the start of the year, shifting its focus from one sector to the next. 

“We have seen continued targeting against the financial sector with additional targeting of other organizations including in the med tech space,” Austin Larsen, principal threat analyst at GTIG, told CyberScoop.

The extortion group impersonates IT support in voice-phishing and social engineering attacks, and recently split its extortion operations across four brands with shared infrastructure: Redact, Pink, Helix and Falcon.

Several organizations received new extortion demands from Redact in the last week, according to Google. 

BlackFile and its various affiliates have impacted organizations in multiple industries, including healthcare, technology, transportation, logistics, wholesale, retail and hospitality.

“BlackFile does go after some of the largest organizations in the sectors that they go for. They’re not going after small companies,” Larsen said. “This is big-game hunting.”

The group’s extortion demands often start around $3 million and payments, including several in the past few weeks, have typically been negotiated down to less than $1 million, according to Google.

Flashpoint researchers told CyberScoop they have observed malicious infrastructure targeting Blackstone, Bain Capital, Moody’s, CME and Apollo, but it’s unclear if any of those firms were compromised. 

BlackFile’s steady pace of activity underscores the persistent threat it poses, as it targets an average of 1.5 new victims daily, researchers said.

Some of the group’s recent victims have been subject to threatening messages and other forms of escalation, including swatting incidents, a tactic adopted by several subsets of The Com, according to Google. 

The attackers use hundreds of callers, often lower-level people that are recruited for a small fee or an opportunity to earn goodwill with the group, who make the voice phishing calls to obtain initial access. Larsen estimates less than a dozen core operators run the different brands under the BlackFile umbrella.

“From the intrusion data that we’re seeing, this does appear to be essentially the same group,” he said, adding that different people may be operating the various brands, but they’re all linked back to the same threat cluster using shared infrastructure.

Mandiant incident responders encounter BlackFile often, having been engaged by more than two dozen organizations successfully compromised by the threat group since January. New victims in the financial sector were calling Mandiant in for help earlier this month.

Voice-based phishing attacks for data theft extortion aren’t sophisticated or novel, but BlackFile and other cybercrime groups consistently prove their continued effectiveness across virtually any sector or organization. “They’re really hitting on the human weakness element here,” Larsen said.

The post Details emerge on BlackFile’s recent attacks on financial companies appeared first on CyberScoop.

UK man tied to The Com sentenced for abusing 117 victims

By: Greg Otto
10 August 2026 at 11:09

A 20-year-old man in the United Kingdom was sentenced to two years in prison Monday after admitting to running an online abuse campaign that affected 117 victims across multiple countries during his time in the loosely organized online criminal network known as The Com.

Justin Swaddle, who was a minor when committed the crimes, pleaded guilty last month to a series of child sexual abuse offenses and blackmail. He was sentenced Monday at the same court and will be required to register as a sex offender.

The National Crime Agency, the U.K.’s lead law enforcement agency, had been investigating Swaddle since January 2024 after local police arrested him in October 2023 on charges of possessing, making and distributing indecent images. Investigators eventually found a broad online presence on Snapchat, Telegram and Discord, where he operated under usernames including “Epstein,” “Rugen” and “Moscow.”

A search of his phone and computer also turned up hundreds of sexually explicit conversations with young females, according to the NCA. Investigators determined Swaddle was part of The Com, a sprawling cybercriminal network of minors and young adults who engage in violence, extortion, sextortion and various forms of cybercrime. 

The NCA identified 117 female victims worldwide between the ages of 13 and 17, eight of them in the United Kingdom. One victim, 17, told investigators she met Swaddle on Discord in November 2022 before their conversations moved to Snapchat. She said Swaddle obtained her name, address and school details, then used that information to pressure her into various acts, threatening to expose her personal information unless she provided further images and videos.

“Justin Swaddle targeted young and vulnerable victims all over the world to abuse and scare them into carrying out shocking self-harm and sexual activity, purely to gain popularity with his peers online,” Danielle Pownall, an operations manager from the NCA, said in a release. “While the number of people involved in Com groups are relatively small, the impact it has on victims is high and long-lasting, as Swaddle’s offending shows.”

Law enforcement in both the U.K. and United States has been extremely active over the past few months in bringing Com-affiliated members to justice. Last week, a Canadian man who was linked with the group pleaded guilty for the widespread compromise of more than 165 Snowflake customer environments. Last month, a pair of young men tied to the Com were sentenced in the U.K. to 66 months in jail for committing a cyberattack on the Transport for London in 2024. 

The post UK man tied to The Com sentenced for abusing 117 victims appeared first on CyberScoop.

Snowflake hacker pleads guilty, faces up to 32 years in prison

5 August 2026 at 17:29

A Canadian man pleaded guilty to playing a central role in one of the most far-reaching cyberattacks of 2024 — the widespread compromise of more than 165 Snowflake customer environments, resulting in massive data theft for extortion, the Justice Department said Wednesday. 

Connor Moucka earned $495,000 by extorting his victims, offering stolen data for sale online, and in one case re-extorted a victim with stolen data of a government official and members of a then-former government official’s immediate family, authorities said.

Moucka and his alleged co-conspirators John Binns and Cameron Wagenius stole billions of sensitive records and received more than $2.5 million in extortion payments combined, according to prosecutors. Victims of the attack spree included AT&T, Ticketmaster, Advance Auto Parts and Santander.

“Hiding behind a screen is no shield from justice,” Brett Leatherman, assistant director of the FBI’s Cyber Division, said in a statement. “Moucka learned that when he was arrested just months after he began targeting U.S. companies, stealing sensitive information, and extorting victims for millions of dollars.”

Authorities arrested Moucka relatively quickly because he caused significant damage, said Allison Nixon, chief research officer at Unit 221B. 

“His gang went on a spree of maximizing harm, which directly correlated to maximizing the resources devoted to stopping it,” she said. 

“His behavior was bizarre throughout. Even while stealing data and extorting victims, he did many unnecessary things like threatening me because he thought I was working on his case. I was not working on his case before he threatened me,” Nixon added.

Moucka, who used several aliases online, including “Waifu,” “Judische,” “Catist” and “Ellyel8,” was arrested Oct. 30, 2024, in Kitchener, a city in the Canadian province of Ontario, at the behest of U.S. authorities. He was extradited to the United States in March 2025.

Moucka and his co-conspirators used stolen credentials to access the data storage platform’s customers’ accounts en masse. Records of more than 100 million people were exposed by the data theft campaign, including call and text history records, banking and other financial information, payroll records, government ID numbers and other personally identifiable data. 

Officials said victim companies bore more than $9.5 million in losses combined, not including losses attributable to their respective customers. 

Moucka’s threats and re-extortion tactics were calculated and predatory, and his actions did real harm to his victims, be they companies targeted for theft and extortion or the millions of everyday people who are their customers,” W. Mike Herrington, special agent in charge of the FBI Seattle field office, said in a statement.

Researchers said Moucka and his co-conspirators are all associated with The Com, a sprawling cybercriminal network of minors and young adults who engage in violence, extortion, sextortion and various forms of cybercrime.

“His legacy is one of failure. He extorted and then scammed his victims by not deleting the data, casting doubt on all future pay-or-leak extortion gangs,” Nixon said. 

“The pay-or-leak business model was popularized by him and his gang,” and his claims of data deletion were a lie, she added. “With copycat gangs, defenders grapple with the uncertainty of whether the threat actors are honest.”

Moucka pleaded guilty to computer fraud, wire fraud, aggravated identity theft and a related conspiracy. He is scheduled for sentencing Oct. 27 and faces up to 32 years in prison.

The post Snowflake hacker pleads guilty, faces up to 32 years in prison appeared first on CyberScoop.

Suspect arrested in investigation into sadistic “764” group

By: Dissent
24 July 2026 at 09:47
From the Dutch Police: In an investigation into so-called online sadistic COM networks, a suspect from North Holland was arrested on Monday, July 20. As a member of the group ‘764’, the suspect allegedly asked girls to cut themselves and write his online username on surfaces such as walls with their blood—known as ‘bloodsigns’. He...

Source

Leading members of Scattered Spider sentenced in UK to 66 months in jail

17 July 2026 at 10:12

A pair of young men were sentenced to 66 months in jail for committing a cyberattack on the Transport for London that brought the network’s operations to a standstill in 2024, the United Kingdom’s National Crime Agency said Thursday.

Thalha Jubair and Owen Flowers were arrested at their homes in September 2025, barely a year after the attack, and pleaded guilty last month just as their trials were set to begin. Flowers was previously arrested in connection with the attack in September, but was released after questioning by officers.

Jubair and Flowers were leading members and highly involved in Scattered Spider, a nebulous hacker subset of The Com, according to researchers. The 20-year-old Jubair was a prolific cybercriminal and core member of the unbound collective. 

U.S. authorities last year accused Jubair of direct, prominent involvement in at least 120 cyberattacks, including extortion of 47 U.S.-based organizations and the January 2025 attack on the federal court system. 

Officials said they traced a combined total of at least $89.5 million in cryptocurrency, at the time of payments, to Bitcoin addresses and servers controlled by Jubair. Two financial services firms paid Jubair $25 million and $36.2 million, respectively, in Bitcoin between June and November 2023, according to an unsealed criminal complaint against Jubair. 

At the time of Jubair’s arrest, “he was one of the four principal people that we associated with Scattered Spider,” and one of the two most core players, Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, told CyberScoop. 

Jubair and Owens had significant resources and support, and “victim payments were reinvested back into the enterprise,” said Allison Nixon, chief research officer at Unit 221B. 

The lasting impact of Jubair and Owens’ capture and imprisonment remains hazy.

U.K. authorities insist Jubair and Owens’ arrests and punishment “effectively halted the group’s criminal activity,” yet they added that other cybercriminals continue to use the Scattered Spider brand in more recent attacks. 

Thursday’s announcement “represents a significant step in holding accountable two members of Scattered Spider, a group that has repeatedly relied on data extortion, SIM-swap attacks, and other social engineering techniques to infiltrate networks and undermine critical services,” Brett Leatherman, assistant director of the FBI Cyber Division, said in a statement. 

The FBI also noted, in a LinkedIn post, that members of Scattered Spider “continue to victimize organizations around the world and cause significant financial and operational harm.”

When Owens, now 18, was first arrested for the Transport for London attack in 2024, investigators said he was “in the process of hacking the systems of U.S. health care companies SSM Health Care Corporation and Sutter Health, which had been infiltrated and damaged.”

Officials also said Jubair and Owens failed to cooperate after their arrests. 

“This is the largest cybercrime prosecution ever brought before the U.K. courts and the culmination of nearly two years of painstaking work,” Paul Foster, head of the National Crime Center’s National Cybercrime Unit, said in a statement. 

“Scattered Spider has been the most significant cybercrime threat to the U.K. in recent years. Through this investigation, we have severely disrupted that threat and brought key offenders to justice,” Foster added.

Despite the upbeat reaction from U.K. officials, Nixon said the punishment for Jubair and Owens is “remarkably lenient considering the period of continuous reoffending lasted longer than the sentence.”

Nixon hopes the United States will eventually extradite the pair to face additional charges. “If that happens, they won’t be able to use mental illness as a loophole to get back to harming society as soon as possible,” she added.

“No one who worked on their case was surprised they would reoffend, and there seems to be no allowance in the law to protect the public from what everyone knew was going to happen,” Nixon said. “I know the narrative in the cybercriminal culture will glorify them, but they wouldn’t if they knew the full story.”

The post Leading members of Scattered Spider sentenced in UK to 66 months in jail appeared first on CyberScoop.

764 splinter group leader sentenced to 40 years in jail

9 July 2026 at 10:34

A San Antonio man who sexually exploited children while leading 8884, an offshoot of the notorious violent extremist collective 764, was sentenced to 40 years in prison in federal court Wednesday, the Justice Department said. 

Alexis Aldair Chavez began associating with 764 as a child in 2022 when a co-conspirator introduced him to 7997, one of many 764 offshoots affiliated with the Com. The sprawling nihilistic network of thousands of people, typically between 11 and 25 years old, seek to foster social unrest by destroying civilized society through the corruption and exploitation of children and other vulnerable populations.

The 19-year-old, also known as “Zack” and “Zack8884,” attempted to coerce a girl to commit suicide and blackmailed another girl into self-mutiliation, animal torture and illicit content production in late 2023, according to court records. He later worked with multiple co-conspirators and blackmailed some of his victims to coerce other girls to degrade themselves on camera and produce child sexual abuse material (CSAM).

Chavez was arrested and has been detained without bail since October 2024. He pleaded guilty to multiple crimes involving the sexual exploitation of children in December 2025 and faced up to 60 years in prison for racketeering, distribution and possession of CSAM.

“Chavez’s crimes reveal the ruthless exploitation and manipulation at the core of nihilistic violent extremist groups,” John A. Eisenberg, assistant attorney general for national security, said in a statement. 

“These organizations target children as part of their broader mission to spread terror. These groups ultimately seek nothing less than the destruction of our society,” he added. “The National Security Division will use every resource at its disposal to identify and prosecute 764-linked criminality and to protect the most innocent among us from these predators.”

The indictment filed against Chavez in the U.S. District Court for the Western District of Texas details a series of horrifying crimes he committed with co-conspirators and some of his victims. 

Prosecutors said Chavez and a co-conspirator coerced a girl to cut her tongue, and torture and kill a cat on a live video call in late 2023. He and co-conspirators also, that same month, groomed and extorted several other girls to commit self harm and degrade themselves on camera.

Allison Nixon, chief research officer at Unit 221B, told CyberScoop the sentence is appropriate even if people understandably dislike imprisoning young people. 

“In this space, a certain personality profile is highly predictive of who will risk a prison sentence like this: an obsession with maximizing harm,” she said. 

“Reoffending after release is a huge problem. All major global hacking incidents from the Com are done by serial reoffenders — all obsessed with harmfulness, some graduated from the 764 sextortion space,” Nixon added.

Too many jurisdictions are naive in how they handle cases involving members or associates of the Com, allowing these criminals to go home to parents who won’t supervise them, she said.

Officials pressed on this in their reaction to Chavez’s sentencing as well. “Parents need to know what their children are doing online and must stay engaged, ask difficult questions, and not fall into the trap of believing their child is ‘just playing games’ or ‘just talking with their friends,’” Justin R. Simmons, U.S. attorney for the Western District of Texas, said in a statement. 

“There is darkness present within many people in this world that want nothing more than to see the United States and western civilization fail. There is no limit to the actions these individuals will take to accomplish that goal, including torturing and abusing children,” Simmons added.

Chavez, who was also ordered to pay $10,000 in restitution and serve lifetime supervised release, joins other 764 members already serving long sentences for similar crimes. Bradley Chance Cadenhed, who founded 764 as a 15-year-old in 2021, was arrested later that year and sentenced to 80 years in prison in 2023. 

When the FBI executed a search warrant at Chavez’s residence in July 2024, prosecutors said he came out the backdoor and threw his phone over a neighbor’s fence in an attempt to hide evidence.

Chavez’s sentencing follows a period of heightened law enforcement activity, which has netted arrests of multiple alleged 764 leaders and members. Some of the alleged 764 members arrested since 2025  include: Leonidas Varagiannis and Prasan Nepal, Baron Cain Martin, Tony Christopher Long, Erik Lee Madison, Zachary Sweeney and Aaron Corey. 

“True rehabilitation is the best outcome, but no one knows how,” Nixon said. 

“The total number of offenders who fit this harm-obsessed profile is vanishingly small. Giving them maximum sentences won’t overflow jails,” she added. 

Law enforcement and judges have to be realistic about what it takes to prevent the victimization of children, and handing down lifelong or lengthy prison sentences strikes the right balance between the rights of the offender and society, Nixon said.

FBI officials and agents who track these offenders and gather evidence on their crimes draw similar conclusions. 

“Nothing is more abhorrent than those who prey on children and other vulnerable members of our society and this defendant will pay a steep price for doing just that,” Coult Markovsky, acting assistant director of the FBI’s counterterrorism division, said in a statement.

“This sentencing demonstrates the FBI’s unwavering resolve to identify, hunt down, investigate, and prosecute criminals like Chavez who prey on children through violent online networks, including 764, and orchestrate horrific, unspeakable acts of exploitation and violence,” Daniel Faith, special agent in charge of the FBI San Antonio field office, said in a statement. 

“These predators use social media, messaging apps, gaming platforms, chat rooms, and video services to groom vulnerable children,” Faith added. “Staying engaged in your child’s online life, maintaining open communication, recognizing the warning signs, and reporting suspicious online activity to law enforcement are critical to stopping these offenders.”

The post 764 splinter group leader sentenced to 40 years in jail appeared first on CyberScoop.

❌
❌