Brit pleads guilty amid Scattered Spider hacking spree claims
Tyler Robert Buchanan faces 10 years in jail if found guilt
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
A British man alleged to be a member of the Scattered Spider cyber crime group has pleaded guilty to hacking the computers of at least a dozen companies, stealing more than $8 million in virtual currency from individual victims in the US.
Tyler Robert Buchanan, 24, of Dundee, Scotland, pleaded guilty to one count of conspiracy to commit wire fraud and one count of aggravated identity theft. He was arrested in 2024.
Between September 2021 and April 2023, according to Buchanan's plea agreement, he and his co-conspirators carried out cyber attacks against a range of organizations, including:
- Interactive entertainment companies
- Telecommunications firms
- Technology companies
- IT & business process outsourcing (BPO) suppliers
- Cloud communications providers
- Virtual currency companies
They carried out phishing attacks by sending hundreds of SMS phishing messages to the mobile phones of their victim company’s employees.
The messages purported to be from the company itself, or a contracted IT or BPO supplier, and contained links to phishing websites designed to look like the legitimate websites of the company or supplier.
Victims were then duped into providing confidential information, including personal identifying information (PII) and account usernames and passwords.
These stolen credentials were used to access the accounts of the company’s employees and computer systems, with the ultimate aim of stealing confidential information.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
In some cases, this stolen information included confidential work products, intellectual property, and account access credentials, names, email addresses, and telephone numbers.
Links to Scattered Spider
Those involved in the scheme created a phishing kit that captured the login credentials that were entered into the fraudulent phishing websites, with the stolen credentials sent to an online Telegram channel allegedly administered by Buchanan and one of his co-conspirators.
In a raid on Buchanan's home in April 2023, the names and addresses of numerous individual victims, including a text file that contained cryptocurrency seed phrases and login information for one victim’s account, were found on a digital device.
Sentencing will be carried out on August 21, with a statutory maximum sentence of 22 years in federal prison.
One of Buchanan's co-conspirators, Noah Michael Urban, is already serving a ten-year sentence, and has been ordered to pay $13 million in restitution. Three more men, all from the US - Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo and Joel Martin Evans – still face criminal charges in the case.
The men are believed to be part of the Scattered Spider cyber crime group and are thought to have been behind attacks on some of the world’s largest technology companies, including Twilio, LastPass, DoorDash, and Mailchimp.
Since Buchanan's arrest, the group's activity has continued, with attacks on MGM Group and, more recently, British firms Marks and Spencer, Jaguar Land Rover, and the Co-op.
The group has now evolved into a broader extortion ecosystem, operating under the name Scattered LAPSUS$ Hunters.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Scattered Spider evolved massively in 2025 – here’s what to expect in 2026In-depth If 2025 was the year of Scattered Spider, 2026 could see the hacking collective ramp up further
-
15-year-old revealed as key player in Scattered LAPSUS$ HuntersNews 'Rey' says he's trying to leave Scattered LAPSUS$ Hunters and is prepared to cooperate with law enforcement
-
The Scattered Lapsus$ Hunters group is targeting Zendesk customers – here’s what you need to knowNews The group appears to be infecting support and help-desk personnel with remote access trojans and other forms of malware
-
Hackers behind Jaguar Land Rover announce their 'retirement' – should we believe them?News Is this really the end for Scattered Lapsus$ Hunters?
-
The Scattered Spider ransomware group is infiltrating Slack and Microsoft Teams to target vulnerable employeesNews The group is using new ransomware variants and new social engineering techniques - including sneaking into corporate teleconferences
-
Millions of customers have been exposed in the Qantas cyber attack – here’s everything we know so farNews While details remain murky, cyber experts told ITPro the Qantas incident bears all the hallmarks of the Scattered Spider ransomware group.
-
The Scattered Spider hacker group has a new industry in its crosshairsNews The notorious Scattered Spider threat group is now turning its attention to the airline industry, with attacks on operators intensifying.
-
Scattered Spider: Who are the alleged hackers behind the M&S cyber attack?News The Scattered Spider group has been highly active in recent years


