Security & Risk5 minNewsroom

Scattered Spider Defendant Guilty; Confiscation of $16.5M

Tribunal federal americano com advogado apresentando documentos judiciais desselados sob luz de fim de tarde.

Ahmed Elbadawy from Texas admitted to conspiracy for wire fraud and aggravated identity theft; prosecutors seek 175 BTC and 1,306 ETH confiscation.

On September 16, the United States Department of Justice announced that Ahmed Hossam Eldin Elbadawy, a resident of College Station, Texas, pleaded guilty to two crimes related to the operations of the Scattered Spider group: conspiracy for wire fraud and aggravated identity theft. The confession was signed in October 2025 and remained sealed until this week, when the prosecution filed for a preliminary forfeiture order. Elbadawy is approximately 25 years old.


The forfeiture request lists 175 Bitcoin and 1,306 Ethereum. At the market prices this Wednesday, the Bitcoins total $13.3 million and the Ethereums $3.2 million, amounting to $16.5 million in crypto. The conspiracy for wire fraud carries a potential sentence of up to 20 years in federal prison, which increases to 30 years if the crime affected a financial institution. Aggravated identity theft imposes an additional mandatory two years on top of any other sentence. The third item in the initial indictment, a conspiracy to launder, is still pending.


The group the prosecution is dismantling piece by piece


Scattered Spider, also listed as UNC3944 and Octo Tempest, was responsible for a ten-day outage at MGM Resorts in September 2023, an incident that the operator estimated resulted in over $100 million in EBITDA losses, and for the successful extortion of Caesars Entertainment, which paid approximately $15 million in ransom during the same period. Federal prosecutors attribute more than 100 intrusions and $100 million in accumulated ransom payments to the group by mid-2026.


The sequence of charges is now a case study in how the DOJ is piecing together the puzzle. Noah Urban, the first convicted member of the group, received a ten-year sentence in August 2025 with restitution of $13 million. Tyler Buchanan, arrested in Palma de Mallorca in June 2024 and extradited to the United States, is another of the five indicted in the federal charges filed in November 2024. A British citizen also admitted guilt in April, following SMS frauds linked to the same group. Elbadawy is now the next brick removed from the wall.


How the group’s model fell into the FBI’s lap


The differentiator of Scattered Spider was operational, not technical: native fluency in English, voice social engineering, and mastery of password reset flows at American help desks. An operator would call pretending to be an employee, capture the SMS, create an MFA token, and log in. This linguistic fluency made the members identifiable: English forums, traceable regional accents, and observable crypto movements examined by blockchain analysts. The DOJ transformed what was an on-field advantage into a forensic vulnerability.


Insights for the other side of the Atlantic and Pacific


The jurisdiction of the case is American, but the victims are global. Hotel and casino chains in Las Vegas, mobile operators in London, technology providers in Singapore, a U.S.-based sporting goods retailer with Canadian operations, all appeared in incidents attributed to the same group. For a CISO at a German bank or a Dutch insurer, the lesson is not the value of the confiscation, but the fact that the attack vector, social engineering against the help desk, remains cheap and available. The money trails that the DOJ is unraveling depend on exchanges that cooperate with American orders, which excludes a significant portion of the Asian parallel market.


The United Kingdom has operated in parallel, with the National Crime Agency arresting suspects linked to the group in 2024 and 2025, cooperating with U.S. authorities. Australia and New Zealand have observed similar social engineering attempts against regional banks. In Brazil, the Scattered Spider pattern has not migrated as a brand, but the playbook—attacking the help desk—has become the template for local groups engaging in extortion against retail and finance.


A silent risk remains: parts of the group have never been identified. The DOJ continues with the open indictment against other individuals, and the prosecution avoids commenting on how many defendants are still beyond reach. A call for internal forums to report atypical crypto transactions or unusual use of credentials at help desks remains the script for the week.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk