❌

Reading view

Alleged β€˜Scattered Spider’ Member Extradited to U.S.

A 23-year-old Scottish man thought to be a member of the prolific Scattered Spider cybercrime group was extradited last week from Spain to the United States, where he is facing charges of wire fraud, conspiracy and identity theft. U.S. prosecutors allege Tyler Robert Buchanan and co-conspirators hacked into dozens of companies in the United States and abroad, and that he personally controlled more than $26 million stolen from victims.

Scattered Spider is a loosely affiliated criminal hacking group whose members have broken into and stolen data from some of the world’s largest technology companies. Buchanan was arrested in Spain last year on a warrant from the FBI, which wanted him in connection with a series of SMS-based phishing attacks in the summer of 2022 that led to intrusions at Twilio, LastPass, DoorDash, Mailchimp, and many other tech firms.

Tyler Buchanan, being escorted by Spanish police at the airport in Palma de Mallorca in June 2024.

As first reported by KrebsOnSecurity, Buchanan (a.k.a. β€œtylerb”) fled the United Kingdom in February 2023, after a rival cybercrime gang hired thugs to invade his home, assault his mother, and threaten to burn him with a blowtorch unless he gave up the keys to his cryptocurrency wallet. Buchanan was arrested in June 2024 at the airport in Palma de Mallorca while trying to board a flight to Italy. His extradition to the United States was first reported last week by Bloomberg.

Members of Scattered Spider have been tied to the 2023 ransomware attacks against MGM and Caesars casinos in Las Vegas, but it remains unclear whether Buchanan was implicated in that incident. The Justice Department’s complaint against Buchanan makes no mention of the 2023 ransomware attack.

Rather, the investigation into Buchanan appears to center on the SMS phishing campaigns from 2022, and on SIM-swapping attacks that siphoned funds from individual cryptocurrency investors. In a SIM-swapping attack, crooks transfer the target’s phone number to a device they control and intercept any text messages or phone calls to the victim’s device β€” including one-time passcodes for authentication and password reset links sent via SMS.

In August 2022, KrebsOnSecurity reviewed data harvested in a months-long cybercrime campaign by Scattered Spider involving countless SMS-based phishing attacks against employees at major corporations. The security firm Group-IB called them by a different name β€” 0ktapus, because the group typically spoofed the identity provider Okta in their phishing messages to employees at targeted firms.

A Scattered Spider/0Ktapus SMS phishing lure sent to Twilio employees in 2022.

The complaint against Buchanan (PDF) says the FBI tied him to the 2022 SMS phishing attacks after discovering the same username and email address was used to register numerous Okta-themed phishing domains seen in the campaign. The domain registrar NameCheap found that less than a month before the phishing spree, the account that registered those domains logged in from an Internet address in the U.K. FBI investigators said the Scottish police told them the address was leased to Buchanan from January 26, 2022 to November 7, 2022.

Authorities seized at least 20 digital devices when they raided Buchanan’s residence, and on one of those devices they found usernames and passwords for employees of three different companies targeted in the phishing campaign.

β€œThe FBI’s investigation to date has gathered evidence showing that Buchanan and his co-conspirators targeted at least 45 companies in the United States and abroad, including Canada, India, and the United Kingdom,” the FBI complaint reads. β€œOne of Buchanan’s devices contained a screenshot of Telegram messages between an account known to be used by Buchanan and other unidentified co-conspirators discussing dividing up the proceeds of SIM swapping.”

U.S. prosecutors allege that records obtained from Discord showed the same U.K. Internet address was used to operate a Discord account that specified a cryptocurrency wallet when asking another user to send funds. The complaint says the publicly available transaction history for that payment address shows approximately 391 bitcoin was transferred in and out of this address between October 2022 and
February 2023; 391 bitcoin is presently worth more than $26 million.

In November 2024, federal prosecutors in Los Angeles unsealed criminal charges against Buchanan and four other alleged Scattered Spider members, including Ahmed Elbadawy, 23, of College Station, Texas; Joel Evans, 25, of Jacksonville, North Carolina; Evans Osiebo, 20, of Dallas; and Noah Urban, 20, of Palm Coast, Florida. KrebsOnSecurity reported last year that another suspected Scattered Spider member β€” a 17-year-old from the United Kingdom β€” was arrested as part of a joint investigation with the FBI into the MGM hack.

Mr. Buchanan’s court-appointed attorney did not respond to a request for comment. The accused faces charges of wire fraud conspiracy, conspiracy to obtain information by computer for private financial gain, and aggravated identity theft. Convictions on the latter charge carry a minimum sentence of two years in prison.

Documents from the U.S. District Court for the Central District of California indicate Buchanan is being held without bail pending trial. A preliminary hearing in the case is slated for May 6.

  •  

Nicole Kidman admits these steamy bathroom appliances are key to successful 18-year marriage to Keith Urban

Nicole Kidman says the key to her successful 18-year marriage to Keith Urban is in their bathroom β€” more specifically, their shower.

The 57-year-old actress admitted that she sings in the shower and, no surprise, so does her country music star husband.

"I also hear Keith singing in the shower, and I’ll hear his new songs forming," Kidman told W Magazine.

"We have a double shower. The double-headed shower: key to a successful marriage. Separate commodes and a double-headed shower!"

'THE PERFECT COUPLE' STAR NICOLE KIDMAN LIVES 'NORMAL LIFE' IN TENNESSEE WHILE DOMINATING HOLLYWOOD

The Hollywood actress previously shared another key factor in their relationship.Β 

NICOLE KIDMAN'S TENNESSEE HOME ALLOWS HER TO BE 'JUST A CITIZEN': 'MY KIDS LOVE THAT'

The couple decided from the beginning that they would only communicate by voice, Kidman told Parade magazine.

"We don't text," Kidman said at the time. "We call. We've done this since the very beginning. The reason it started at the beginning was because I didn’t know how to text, and it just kind of worked for us. So, now we don’t."

LIKE WHAT YOU’RE READING? CLICK HERE FOR MORE ENTERTAINMENT NEWS

"We just do voice to voice or skin to skin, as we always say. We talk all the time, and we FaceTime, but we just don’t text because I feel like texting can be misrepresentative at times," she added.

Besides their no-texting rule, their secret to a lasting marriage is easy: "Not having secrets," Kidman continued.

In 2023, the country music star told Fox News Digital another way they keep their marriage strong.

"It’s always family first," Urban explained ahead of the ACM Awards.Β 

"It's balanced, so it means it goes out of balance sometimes, and we just put it back in balance," he said. "It's never perfectly in balance, but we get it back on track."

CLICK HERE TO SIGN UP FOR THE ENTERTAINMENT NEWSLETTER

Kidman and Urban share two daughters: Sunday Rose and Faith Margaret.

The "Big Little Lies" actress additionally has two adopted children with Tom Cruise: Connor and Isabella.Β 

Kidman has a reportedly strained relationship with those children, in part because of their participation in Scientology, alongside Cruise.

Kidman and Cruise met while working on the 1989 film "Days of Thunder" and married in 1990. They adopted Isabella in 1992 and Connor in 1995. During their divorce in 2001, they shared joint custody.

  •