A 20‑year‑old member of the notorious cybercrime collective Scattered Spider has been sentenced to 10 years in prison and ordered to pay $13 million in restitution following his involvement in SIM‑swapping attacks and cryptocurrency theft.

Noah Michael Urban, known by aliases such as Sosa, Elijah, King Bob, Gustavo Fring, and Anthony Ramirez, pleaded guilty to charges of wire fraud and aggravated identity theft, committing these crimes across multiple victims from August 2022 to March 2023. The U.S. Department of Justice noted that at least $800,000 was stolen from five individuals.

Urban was arrested by authorities in Florida in January 2024. His sentencing reflects both the severity of the crimes and the broader crackdown on the group’s sophisticated criminal operations, which combined social engineering, SIM‑swapping, and cryptocurrency heists.

In a noted twist following his conviction, Urban expressed dismay over the length of the sentence. In a jailhouse interview conducted via the X platform with independent cybersecurity reporter Brian Krebs, he characterized the ruling as unjust. He also claimed that the sentencing judge was upset after another Scattered Spider affiliate managed to hack into the judge’s email and retrieve a sealed indictment.

Who Is Scattered Spider?

Scattered Spider, also known as UNC3944, is a British-American hacking collective formed around May 2022, composed largely of teenagers and young adults. Members are believed to be located across both the U.S. and the U.K., portions of which have links to the broader cybercriminal network known as “The Com”.

The group is notorious for high-profile ransomware and extortion operations, including attacks on MGM Resorts and Caesars Entertainment, as well as targeting financial and technology companies like Visa, Marks & Spencer, Transamerica, New York Life, Synchrony Financial, Truist Bank, and Twilio. Additionally, Scattered Spider has been tied to data thefts involving Snowflake cloud customers.

Their methods are alarmingly sophisticated: they exploit human vulnerabilities—via social engineering, phishing, vishing, smishing, and even multi-factor authentication fatigue attacks—rather than relying solely on traditional technical exploits. This “people-first” approach has allowed them to bypass advanced defenses with alarming effectiveness.

Broader Context: Arrests and Ongoing Threat

Urban’s sentencing comes amid a broader U.S. law enforcement effort to dismantle the group. In April 2025, Urban pleaded guilty to his charges. Prior to his arrest, his co-conspirators, including Tyler Robert Buchanan, were also brought into custody. Buchanan, believed to be among the leadership, was extradited from Spain to the U.S. after authorities unsealed criminal charges last November.

In addition to Urban’s penalties, Buchanan faces severe charges including fraud and identity theft, with potential sentencing stretching up to 47 years in prison.

The Threat Landscape

Cybersecurity analysts describe Scattered Spider as a highly flexible and opportunistic criminal enterprise. Flashpoint, a security firm, notes that the group often adopts a “wave-like approach”—concentrating attacks within one industry vertical in rapid succession.

Adam Darrah, Vice President of Intelligence at ZeroFox, observed that Scattered Spider frequently employs tactics designed to create urgency: media attention, timed leaks, countdown threats, and taunting of security teams are part of their psychological arsenal. Notably, they also establish alliances with other cybercrime groups like ShinyHunters and LAPSUS$ to expand capabilities and resilience.

Conclusion

The sentencing of Noah Michael Urban marks a significant milestone in the fight against Scattered Spider’s cybercriminal operations. It sends a strong message: exploiting human weaknesses through SIM-swapping, social engineering, and deep-tech-enabled phishing will not go unpunished.

As Buchanan and other affiliates face legal repercussions, this case highlights the urgency of reinforcing both technical safeguards and human resilience. Cybercriminals are increasingly agile—targeting individuals within organizations rather than systems alone. Defenders must adapt accordingly.

If you’d like, I can expand this article with details about remediation best practices, industry-specific risks, or the broader pending cases against Scattered Spider affiliates.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *