Full Report
Ahmed Elbadawy pocketed massive proceeds from his crimes. Prosecutors are seeking the forfeiture of about $17.6 million in virtual currency, luxury vehicles, and a vast collection of jewelry and designer bags. The post Early Scattered Spider member pleads guilty to cybercrime spree appeared first on CyberScoop.
Analysis Summary
# Threat Actor: Ahmed Elbadawy (Scattered Spider / The Com)
## Attribution & Identity
* **Individual:** Ahmed Hossam Eldin Elbadawy (24-year-old from Texas).
* **Aliases/Associations:** Known member of the "Hacker Com" subset of **The Com**.
* **Group Affiliation:** **Scattered Spider** (also known by various industry names like UNC3944).
* **Co-conspirators:** Noah Michael Urban (Florida), Tyler Robert Buchanan (Scotland), Evans Onyeaka Osiebo, and Joel Martin Evans.
## Activity Summary
Elbadawy was involved in a highly aggressive cybercrime and extortion spree spanning from at least 2021 to 2023. His operations focused on breaching corporate networks to facilitate the theft of millions of dollars in virtual currency. In late 2024, he was charged alongside four others, and in September 2026, details of his guilty plea to wire fraud conspiracy and aggravated identity theft were made public following asset forfeiture filings.
## Tactics, Techniques & Procedures
* **Social Engineering:** Primary method for obtaining initial access and employee credentials.
* **Credential Theft:** Targeted harvesting of login information to infiltrate corporate environments.
* **Data Exfiltration:** Stealing sensitive company data to identify high-net-worth employees.
* **Account Takeover:** Targeting virtual currency accounts belonging to specific employees to drain funds.
* **Identity Theft:** Used to facilitate fraud and gain unauthorized access.
* **Extortion:** Part of a broader pattern within The Com involving pressure tactics to secure payments.
## Targeting
* **Sectors:** Entertainment, Telecommunications, Technology, Business Process Outsourcing (BPO), IT, Cloud Services, and Virtual Currency.
* **Geography:** Primarily United States (specifically Southern California and Texas mentioned) with global reach.
* **Victims:** At least 29 individual victims and 12 victim companies were specifically detailed by authorities.
## Tools & Infrastructure
* **Virtual Currency:** Heavily utilized Bitcoin and Ethereum for laundering and storing proceeds.
* **Communications:** The Com typically utilizes platforms like Discord and Telegram (though specific C2 infrastructure for this case was not detailed in the summary).
* **Infrastructure:** Involved in identifying and compromising cloud and IT service provider environments.
## Implications
The case underscores the significant financial threat posed by loosely organized but highly skilled "Com" communities. These groups, often composed of young individuals (ages 11–25), bridge the gap between digital social engineering and sophisticated technical intrusions. Despite the arrests of early leaders like Elbadawy, the ecosystem remains resilient, with new members quickly filling leadership voids and expanding into more violent or harmful activities like swatting and physical threats ("In Real Life Com").
## Mitigations
* **Phishing-Resistant MFA:** Implement FIDO2-based hardware keys to defend against the social engineering and SIM-swapping tactics favored by Scattered Spider.
* **Social Engineering Awareness:** Enhanced training for IT help desks and customer support representatives to identify sophisticated impersonation attempts.
* **Strict Access Controls:** Implement "Least Privilege" models for sensitive employee data and administrative consoles.
* **Cryptocurrency Security:** For employees in high-risk sectors, utilize cold storage or multi-signature requirements for virtual currency assets.