Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Federal prosecutors unsealed charges against five people described as alleged members of the Scattered Spider cybercrime collective on November 20, 2024. The charges accuse them of using SMS impersonation and stolen credentials to access company systems and cryptocurrency accounts; they are allegations, not convictions.

Who are the five people charged?

The defendants named in Hogan Lovells’ summary of the charging papers are Ahmed Hossam Eldin Elbadawy, Noah Michael Urban, Evans Onyeaka Osiebo, Joel Martin Evans, and Tyler Robert Buchanan. The charges were unsealed on November 20, 2024, and IT Pro reported the case the following day.

The charges differed for Buchanan. Hogan Lovells says the first four were charged with conspiracy, conspiracy to commit wire fraud, and aggravated identity theft. Buchanan was charged with conspiracy to commit wire fraud, conspiracy, wire fraud, and aggravated identity theft. These are charges alleged by prosecutors, not findings of guilt. The available reporting does not establish a current disposition for all five defendants.

What did prosecutors accuse them of?

Hogan Lovells’ summary of the charging papers describes alleged activity from at least September 2021 through April 2023. The campaign allegedly targeted at least 45 companies, including companies based in the United States, Canada, the United Kingdom, and India.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

IT Pro reported that prosecutors alleged the five stole $11 million in cryptocurrency from at least 29 victims. That figure measures reported cryptocurrency losses and victims; it is distinct from the 45-company target figure in Hogan Lovells’ summary. Both figures describe allegations, not adjudicated findings.

How did the alleged scheme work?

According to the charging summary, the defendants allegedly sent SMS messages impersonating victims’ employers or their IT or business-services contractors. The messages were intended to obtain credentials. With those credentials, the perpetrators allegedly gained unauthorized access to company data and used stolen information to access cryptocurrency accounts and wallets.

The alleged SMS impersonation fits a broader pattern described in the FBI and CISA’s November 2023 advisory about Scattered Spider. The advisory says the group targeted large companies and contracted IT help desks and describes social engineering, phishing, repeated multifactor-authentication prompts (often called MFA fatigue), SIM swapping, credential acquisition, and data theft for extortion among observed or reported behaviors. Those group-level observations are threat context; they do not establish that every tactic was used in this specific case.

What does the case say about Scattered Spider—and what does it not?

U.S. Attorney Martin Estrada described the alleged activity as a scheme to steal intellectual property, proprietary information, and personal information. IT Pro reported his statement: “We allege that this group of cybercriminals perpetrated a sophisticated scheme to steal intellectual property and proprietary information worth tens of millions of dollars and steal personal information belonging to hundreds of thousands of individuals.”

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Later threat reporting should not be mistaken for evidence in the five-defendant case. A multi-agency advisory updated July 29, 2025 says its activity details draw on FBI investigations through June 2025 and notes that Scattered Spider changed tactics and had used DragonForce ransomware alongside its usual methods. It provides later group-level context, not proof of conduct by these five defendants.

Is the 2026 Peter Stokes arrest part of this case?

No. The Department of Justice announced on July 1, 2026, that Peter Stokes was arrested in Finland in April 2026 and extradited to the United States in a separate Northern District of Illinois case. That announcement concerns a distinct complaint and should not be combined with the five-defendant case unsealed in 2024. DOJ said the complaint is an allegation and defendants are presumed innocent.

The same 2026 announcement attributes allegations of more than 100 network intrusions and more than $100 million in ransom payments to the separate Stokes matter. Those group-wide figures are not the alleged cryptocurrency losses in the 2024 case and should not be attributed to its five defendants.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What can companies do to reduce the risk?

The FBI and CISA’s November 2023 advisory recommends defensive measures aimed at the access techniques described in its threat reporting:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Use phishing-resistant multifactor authentication. This helps reduce reliance on credentials that can be captured through phishing or social engineering.
  • Keep offline backups. Backups disconnected from everyday systems can help organizations recover if data is encrypted or systems are disrupted.
  • Apply application controls. Restricting which applications can run can make unauthorized activity harder.
  • Prepare help desks and staff for impersonation attempts. The advisory identifies social engineering against organizations and contracted IT help desks as part of the group’s reported activity.

These are measures recommended in the advisory, not a guarantee against compromise. Organizations should apply them as part of a broader security and incident-response program.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.