Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11The British man arrested at Palma airport in 2024 was later identified by the U.S. Department of Justice as Tyler Robert Buchanan, 24, of Dundee, Scotland. On April 17, 2026, Buchanan pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. His guilty plea establishes the counts he admitted; it does not, by itself, confirm every allegation made when he was arrested or the campaign labels attached to him in 2024 reporting.
Who was the British man arrested in Spain?
The DOJ identified the suspect as Tyler Robert Buchanan, a 24-year-old from Dundee, Scotland. Spanish police arrested him at Palma airport in May 2024 as he was preparing to board a charter flight to Naples. At the time, authorities had not publicly identified him, according to contemporaneous reporting by CyberScoop and TechCrunch. The DOJ later announced his identity and guilty plea in its April 17, 2026 release.
What did Buchanan plead guilty to?
Buchanan pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. The DOJ says he admitted participating in an SMS-phishing scheme that targeted at least a dozen companies and stole at least $8 million in virtual currency from individual victims in the United States. These are the scope and losses described in the DOJ’s account of the plea agreement, not a reconciliation of the separate figures police cited at the time of his arrest.
How did the admitted phishing scheme work?
According to the DOJ’s description of the conduct admitted in the plea agreement, the operation sent bulk text messages impersonating companies or their suppliers. The messages directed targets to fake login websites designed to capture credentials. The operation also used SIM swapping to take over some cryptocurrency accounts.
#1 Best Overall
The DOJ defines SIM swapping as a criminally induced transfer of a phone number from its legitimate subscriber’s SIM card to a SIM card controlled by someone else, without the subscriber’s authorization or knowledge. SMS phishing—often called smishing—is phishing delivered by text message; it is distinct from email phishing.
What were police alleging when he was arrested?
In 2024, Spanish police described Buchanan as the leader of an organized group and alleged that he was responsible for attacks on 45 U.S. companies. CyberScoop reported that police said the group controlled 391 bitcoin, then valued at more than $27 million. Those were arrest-stage claims attributed to Spanish police in the contemporaneous reporting, not findings established by Buchanan’s later guilty plea as summarized by the DOJ.
| Claim | Source and date | Scope and status |
|---|---|---|
| 45 U.S. companies | Spanish National Police, as reported by CyberScoop in 2024 | Arrest-stage allegation about attacks |
| 391 bitcoin, valued at more than $27 million | Spanish National Police, as reported by CyberScoop in 2024 | Arrest-stage claim about cryptocurrency under the group’s control |
| Nearly 10,000 credentials associated with more than 130 companies | An unnamed researcher quoted by CyberScoop in 2024 | Researcher’s reported claim; not a DOJ figure |
| At least a dozen companies and at least $8 million in virtual currency stolen from individual U.S. victims | DOJ summary of Buchanan’s plea agreement, 2026 | Conduct Buchanan admitted, as described by the government |
The figures differ in source, date, and scope: the 2024 reports describe police allegations about company attacks and bitcoin, while the DOJ’s 2026 release describes conduct admitted in a plea and losses to individual victims. The available accounts do not explain how the figures relate, so they should not be treated as competing measurements of the same thing.
Was the arrest linked to 0ktapus or Scattered Spider?
CyberScoop’s 2024 report connected the suspect to 0ktapus based on an unnamed researcher familiar with the matter, who claimed that nearly 10,000 credentials tied to more than 130 companies had been stolen. That report also said it was unclear whether Buchanan participated in the MGM attack. TechCrunch likewise reported a 0ktapus connection based on a source familiar with the operations, while noting that authorities had not named the suspect or group at the time.
Scattered Spider and the Com appeared in reporting as ecosystem labels. They should not be read as interchangeable names for one fixed organization or as a court-established finding of Buchanan’s membership. The DOJ’s 2026 plea announcement identifies Buchanan and summarizes admitted conduct but does not use the 0ktapus label.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Has Buchanan been sentenced?
The DOJ release said sentencing was scheduled for August 21, 2026, and listed a statutory maximum of 22 years. A statutory maximum is not the sentence imposed. The reviewed DOJ release does not report the result of the scheduled hearing, so the actual sentence is not established here.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

