Para garantizar la mejor experiencia de navegación, active JavaScript en su navegador web. Sin él, muchas funciones del sitio web no estarán disponibles.


Total de pruebas:
485,773,462
737,046
130,956

El hacker «Scattered Spider» se declara culpable

24 de septiembre de 2026

Read also: a Ryuk affiliate sentenced to 2 years; the EvilTokens phishing service disrupted; and more.

Vistas: 1.6k Tiempo de lectura:3 min.

El hacker «Scattered Spider» se declara culpable

A Scattered Spider hacker pleads guilty

A key member of the Scattered Spider cybercrime group has reportedly pleaded guilty in the US to federal charges linked to a series of extortion and cryptocurrency theft attacks.

Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, pleaded guilty last year to conspiracy to commit wire fraud and aggravated identity theft. His guilty plea was not made public at the time. Prosecutors said Elbadawy worked with Noah Michael Urban and Tyler Robert Buchanan as part of Scattered Spider, a group linked to the wider cybercrime network known as The Com.

Scattered Spider used social engineering to steal login credentials and access sensitive company data. The group targeted companies in sectors including technology, telecommunications, entertainment and cryptocurrency. Some attacks resulted in major cryptocurrency thefts, including nearly $6.35 million in September 2021 and nearly $1.7 million in December 2022.

In August 2025, Noah Urban was sentenced to 10 years in prison; Tyler Buchanan, a British national, pleaded guilty in the US in April this year and is awaiting sentencing. Elbadawy’s sentencing date and the full terms of his plea agreement have not yet been released.

The EvilTokens phishing service used to steal access to Microsoft 365 accounts shut down

Microsoft and law enforcement agencies in the US and UK have disrupted EvilTokens, a phishing service used by criminals to steal access to Microsoft 365 accounts.

EvilTokens, which first appeared in February, was used to compromise about 12,000 email accounts at more than 10,000 organizations around the world. The service was sold to criminals as a subscription. It helped threat actors bypass multi-factor authentication (MFA) and access victims’ Microsoft 365 accounts. EvilTokens also used AI to analyze victims’ emails. The tool could help criminals find important contacts, decide who to impersonate, and choose ways to carry out scams.

As part of the operation, Microsoft seized more than 50 websites linked to EvilTokens and disabled over 150 other domains. On September 18, London police arrested two men, aged 32 and 38, who are suspected of running the service.

Both men were released on bail as the investigation continues. Microsoft and law enforcement agencies are also notifying people whose email accounts may have been compromised.

A Ryuk affiliate sentenced to 2 years in prison after stealing over $1M

An Armenian citizen extradited from Ukraine to the US has been sentenced to two years in federal prison for his role in Ryuk ransomware attacks targeting companies, schools and other organizations. Karen Vardanyan, 35, was sentenced to 24 months in prison and three years of supervised release. He was also ordered to pay more than $1.2 million in restitution to victims.

According to court documents, Vardanyan used the monikers ‘Maneeken’ and ‘Karl Lagerfeld’ and was part of a group that carried out Ryuk ransomware attacks from March 2019 to June 2020. The attacks locked victims out of their computer systems and demanded payment, usually in cryptocurrency. The group extorted more than $1 million from several victims, prosecutors said.

Vardanyan was indicted by a federal grand jury in Portland in February 2024. He was extradited from Ukraine and appeared in US federal court in June 2025. He pleaded guilty to conspiracy and computer fraud charges on July 8, 2026.

In an unrelated case, Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information, and demanding money to keep the data private. He allegedly exploited website security weaknesses and used tools to hide his identity and location.

Officials said one of the victims was the household appliance and smart device repair company TSC, a subsidiary of the LMT group. TSC disclosed the hack earlier in September, revealing that an attacker exploited a vulnerability in its website and got access to personal data related to the processing of TSC customers' repair orders.

Police found evidence of possible attacks on other businesses in Latvia and abroad. The suspect could face up to five years in prison. Authorities said there is no evidence that the stolen data was shared with others.

Boletín informativo de ImmuniWeb

Recibe Cybercrime Weekly, invitaciones a nuestros eventos y seminarios web en tu bandeja de entrada:


Privado y confidencialSus datos permanecerán privados y confidenciales.

Police crack down on cyber scam networks in Ukraine

Ukrainian police have dismantled several scam networks and blocked thousands of phishing websites during a major operation targeting online fraud.

The operation, called “WallHack,” took place from July to August 2026. Law enforcement officers searched locations in Kyiv and 19 regions of Ukraine. The suspects allegedly used messaging apps to organize fraud and share links to fake websites.

The websites mimicked online stores, banks, government services and international organizations and were used to steal payment details and gain access to victims’ online banking accounts in Ukraine and the EU.

Police carried out 239 searches and seized almost 600 pieces of computer equipment. Authorities also blocked thousands of phishing links and shut down 300 Telegram channels with more than 5,000 members in total. So far, 23 people have been formally suspected of involvement, while eight were detained. Four of them were placed in custody. Five criminal cases have already been sent to court, including one involving an organized criminal group.

ImmuniWeb puede ayudarle a prevenir brechas de datos y cumplir con los requisitos normativos.

Spanish police take down a criminal network behind mass online scams

Spanish police have dismantled a criminal organization accused of carrying out large-scale online scams and laundering the money through cryptocurrencies.

Police arrested 44 people and identified at least 146 victims who lost more than €430,000 in total. The group allegedly used phone and text scams, fake rental advertisements, and fraudulent tickets for concerts and other events.

The investigation began in May 2024 after a victim reported losing 0.5 Bitcoin. Police followed the money and found that the group converted illegal profits into cryptocurrencies to make the funds harder to trace.

Police carried out 14 searches in Tarragona, Barcelona, Almería, Cádiz, Málaga and Ciudad Real. Officers seized cash, cryptocurrencies worth around €54,000, 57 bank cards, 43 SIM cards, 24 mobile phones and other electronic devices.

The suspects face charges including fraud, money laundering and involvement in a criminal organization.

Próximos pasos:

Hable con un experto