TL;DR: Tyler Robert Buchanan, 24, from Dundee, Scotland (described by investigators as the suspected ringleader of the Scattered Spider hacking group) pleaded guilty on April 17, 2026, in a California federal court. He admitted to conspiracy to commit wire fraud and aggravated identity theft. Between 2021 and 2023, Buchanan and his crew phished their way into at least a dozen companies (Twilio, LastPass, DoorDash, Mailchimp), stole employee credentials, ran SIM-swap attacks to bypass two-factor authentication, and drained $8 million in cryptocurrency from individual victims. He was arrested at Palma de Mallorca airport in June 2024 trying to board a flight to Italy. He faces up to 22 years in federal prison. Sentencing is set for August 21, 2026.
Caught at the Airport, Convicted in California
Buchanan's run ended at a Spanish airport. On June 10, 2024, police arrested him at Palma de Mallorca as he tried to board a flight to Italy. He'd been in custody ever since, held in Spain, then extradited to U.S. federal custody in April 2025.
On April 17, 2026, in a California federal courtroom, he said the word that matters: guilty.
One count of conspiracy to commit wire fraud. One count of aggravated identity theft. The statutory maximum: 22 years in federal prison.
According to the Department of Justice, "Buchanan and others gained unauthorized access to victims' online accounts and conducted SIM swaps of victims' mobile telephone numbers to devices that the conspirators controlled." Translation: they hijacked phone numbers, intercepted authentication codes, and cleaned out crypto wallets.
How They Did It
Scattered Spider didn't write sophisticated malware. They didn't buy zero-days on the dark web. Their weapon was simpler: they lied convincingly.
The playbook, running from September 2021 to April 2023:
- Step 1: Phishing at scale. Mass SMS messages warning employees their VPN was about to expire. Click here to fix it. The link went to a credential-harvesting site that looked identical to the real thing.
- Step 2: Credential collection. The group built phishing kits that captured login credentials entered into copycat websites. Stolen creds were shared via Telegram channels between conspirators.
- Step 3: SIM swapping. Once inside corporate networks, they identified targets with valuable crypto holdings. They convinced mobile carriers to transfer victims' phone numbers to attacker-controlled SIM cards, killing the victim's two-factor authentication.
- Step 4: Drain the wallets. With full account access and intercepted 2FA codes, they moved fast. At least $8 million in cryptocurrency vanished from individual victims' accounts.
The companies hit reads like a tech-industry roster: Twilio, LastPass, DoorDash, Mailchimp. Each breach cascaded. When Scattered Spider compromised Twilio in August 2022, it gave them access to thousands of downstream accounts that relied on Twilio for authentication, a textbook example of how third-party vendor compromises cascade. When they hit LastPass, they eventually compromised password vaults containing the keys to everything.
Five Down, Three Still Standing
Buchanan is the second Scattered Spider member to plead guilty in the United States. Here's the scorecard:
Noah Michael Urban ("Sosa")
First to plead guilty. Sentenced August 2025 to 10 years in federal prison. Ordered to pay $13 million in restitution. He was 19 when he started.
Tyler Robert Buchanan
Pleaded guilty April 17, 2026. Faces up to 22 years. Sentencing August 21, 2026. Arrested at a Spanish airport with a SIM card in someone else's name.
Ahmed Hossam Eldin Elbadawy (24)
Charged November 2024. Wire fraud conspiracy. Awaiting trial.
Evans Onyeaka Osiebo (21) & Joel Martin Evans (26)
Both charged November 2024. Wire fraud, aggravated identity theft. Awaiting trial. Face up to 20 years each.
All five were charged as part of the same conspiracy. They met online (Discord, Telegram) and organized a criminal operation that outperformed many nation-state hacking groups. The youngest was a teenager when it started.
The Damage Beyond $8 Million
Buchanan's guilty plea covers $8 million in crypto theft. But the real cost of Scattered Spider's operations dwarfs that number.
The same group (sometimes called Octo Tempest or UNC3944 by security researchers) is linked to:
- MGM Resorts hack (September 2023). Casino and hotel systems shut down for days. Estimated cost: over $100 million.
- Caesars Entertainment ransom (2023). Paid $15 million to make them go away.
- Aflac breach (June 2025). 22.7 million people's SSNs, passports, and medical records stolen.
- Allianz Life breach (2025). 1.4 million affected via vendor compromise.
- ESA breach (2025). 500GB of data exfiltrated from the European Space Agency.
Not all of these are directly tied to Buchanan's charges. Scattered Spider isn't a traditional gang. It's more like a loose collective where members drift in and out, collaborate on specific jobs, and share tools over encrypted channels. But the FBI considers Buchanan a central figure.
Why SIM Swapping Still Works
The core technique Buchanan admitted to, SIM swapping, shouldn't still be this easy. A SIM swap attack means convincing a mobile carrier (T-Mobile, AT&T, Verizon) to transfer someone's phone number to a new SIM card. Once an attacker controls your phone number, they receive your text messages. Including those two-factor authentication codes you thought were protecting your accounts.
The FCC finalized new SIM-swap protection rules in November 2023. Carriers were supposed to implement additional authentication before porting numbers. And yet:
- SIM-swap complaints to the FBI's IC3 totaled $68 million in losses in 2024 alone
- T-Mobile settled a class action over SIM-swap failures for $33 million in 2024
- Attackers still bribe carrier employees, use social engineering, or exploit weak authentication at retail stores
If you're protecting anything valuable with SMS-based two-factor authentication, stop. Use a hardware security key (YubiKey) or an authenticator app. Your phone number is not secure.
Protect Yourself
Ditch SMS 2FA
Switch every account to an authenticator app (Authy, Google Authenticator) or a hardware key. SMS codes are the weakest link in your security chain.
Add a Carrier PIN
Set a PIN or passphrase on your mobile carrier account. This adds an extra barrier before anyone can request a SIM swap. Call your carrier or set it in their app.
Number Lock/Port Freeze
T-Mobile, AT&T, and Verizon offer number lock features that prevent unauthorized porting. Enable it. Takes 30 seconds.
Watch for the Signs
If your phone suddenly loses service, don't assume it's a dead zone. Call your carrier immediately. Someone may have just stolen your number.
The Bottom Line
A 24-year-old from Dundee, Scotland sent some text messages, built some fake websites, and stole $8 million. His group (a collection of young hackers who organized on Discord and Telegram) breached MGM, Caesars, Twilio, LastPass, and dozens more. They stole data on tens of millions of people. They caused hundreds of millions in damage.
Two are now in custody. Three are still awaiting trial. But Scattered Spider's playbook is public knowledge, and copycat groups are already using the same techniques. The guilty pleas are satisfying. They're not a solution.
The solution is the same as it's always been: stop trusting phone numbers for security. Stop trusting that the person on the other end of a call is who they say they are. And stop assuming that multi-billion-dollar companies are any better at this than you are, because Buchanan proved they aren't.
References
- The Record - British hacker tied to Scattered Spider campaign pleads guilty in $8M scheme (April 2026)
- The Register - US gets second Scattered Spider-linked guilty plea (April 2026)
- Security Affairs - Scattered Spider member Tyler Buchanan pleads guilty to major crypto theft (April 2026)
- BleepingComputer - British Scattered Spider hacker pleads guilty to crypto theft charges (April 2026)
- Hackread - British Hacker Tyler Buchanan Pleads Guilty to $8M Hacking Scheme (April 2026)