logo

Feds Tie ‘Scattered Spider’ Duo to $115M in Ransoms

ID: 800919b5-14d9-5975-86ac-c168cdb45fdf

STIX ID: report--800919b5-14d9-5975-86ac-c168cdb45fdf

Feed Name: Krebs on Security

Threat Score
85/100

Date Published: 2025-09-24

Date Updated: 2026-04-19

Author: BrianKrebs

...
...

**Executive summary:** The report profiles alleged core member Thalha Jubair and his involvement in the Scattered Spider (aka 0ktapus/UNC3944) cybercrime group, detailing years of SIM‑swapping, large-scale SMS phishing, dynamic phishing pages, doxing services, malware development, and ransomware/extortion campaigns that reportedly led to at least $115 million in ransom payments, dozens of intrusions (120+ incidents affecting 47 U.S. entities), and high-profile disruptions (e.g., MGM, Caesars, Transport for London); it also covers aliases, Telegram/Com community activity, law enforcement charges, and seizure of cryptocurrency tied to the crimes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.