Teenage member of Scattered Spider cybercrime group arrested in the UK

Teenage member of Scattered Spider cybercrime group arrested in the UK

West Midlands police, in collaboration with the Regional Organised Crime Unit for the West Midlands (ROCUWM), the National Crime Agency (NCA), and the United States Federal Bureau of Investigation (FBI), have arrested a 17-year-old boy from Walsall linked to the notorious cybercrime group known as Scattered Spider. This group is implicated in numerous high-profile ransomware attacks, including a breach at MGM Resorts in the United States.

The teen was taken into custody on suspicion of Blackmail and Computer Misuse Act offences and has been released on bail.

Scattered Spider (aka Octo Tempest, 0ktapus, Scatter Swine, and UNC3944) has been active since at least May 2022 and is known for its sophisticated social engineering attacks. These attacks often involve SMS phishing, SIM swapping, and account hijacking to gain on-premises access. The group, primarily operating through underground communities on Telegram, hacking forums, and Discord servers, has developed a reputation for its aggressive and varied tactics.

Initially, UNC3944 concentrated on credential harvesting and SIM swapping attacks. Over time, the threat actor expanded its operations to include ransomware and data theft extortion. Recently, however, the group has focused more on data theft extortion without deploying ransomware. To intimidate victims into compliance, UNC3944 has employed various tactics, including threats of doxxing personal information, physical harm, and the distribution of compromising material.

More recently, the group has shifted its focus towards data theft from software-as-a-service (SaaS) applications.


Back to the list

Latest Posts

Ulefone and Krüger&Matz smartphones found with dangerous preloaded app flaws

Ulefone and Krüger&Matz smartphones found with dangerous preloaded app flaws

The flaws allow attackers to steal PIN codes, perform unauthorized factory resets, and gain system-level access.
3 June 2025
New cryptojacking campaign exploits DevOps servers via misconfigurations

New cryptojacking campaign exploits DevOps servers via misconfigurations

The threat actors are compromising services like Docker, Gitea, and HashiCorp’s Consul and Nomad platforms.
3 June 2025
Google rolls out emergency Chrome update to patch actively exploited flaw

Google rolls out emergency Chrome update to patch actively exploited flaw

The flaw could allow attackers to corrupt memory on the heap via specially crafted HTML pages, potentially leading to remote code execution.
3 June 2025