US charges five accused of multi-year hacking spree targeting tech and crypto giants

Date:

Share post:


The U.S. government announced charges against five individuals accused of carrying out a multi-year hacking spree targeting tech giants and cryptocurrency owners, which security researchers dubbed 0ktapus.

On Wednesday, the U.S. Department of Justice published a press release announcing the charges against the five alleged hackers: Ahmed Hossam Eldin Elbadawy, 23, of College Station, Texas; Noah Michael Urban, 20, of Palm Coast, Florida; Evans Onyeaka Osiebo, 20, of Dallas, Texas; Joel Martin Evans, 25, of Jacksonville, North Carolina; and Tyler Robert Buchanan, 22, from the United Kingdom, who was arrested in Spain earlier this year. 

The press release said that the five accused hackers targeted employees at American companies with phishing text messages with the goal of stealing their credentials, which they then used to break in and steal company data, as well as cryptocurrency worth millions of dollars. The hackers also allegedly used SIM swapping attacks to steal employee’s phone numbers and get their passwords by using password reset features. 

Victims mentioned in the court documents published on Wednesday include U.S. based organizations providing entertainment products, virtual currency, cloud communication platforms, and telecommunication services. The hackers allegedly stole $6.3 million in cryptocurrency from a single unnamed victim, the indictment says. 

“We allege that this group of cybercriminals perpetrated a sophisticated scheme to steal intellectual property and proprietary information worth tens of millions of dollars and steal personal information belonging to hundreds of thousands of individuals,” said U.S. Attorney Martin Estrada, as quoted in the press release.

As part of the announcement, the DOJ unsealed three court documents related to the case.

Security researchers have previously linked the alleged hackers to a prolific hacking group called 0ktapus, for their use of spoofing Okta login portals used by tech giants. The hackers targeted hundreds of companies over a months-long hacking campaign in 2022, including Twilio, Coinbase, and Doordash, and again in 2023 to target game makers, including Riot Games. 

The hackers were later believed to be involved with other criminal cyberattacks under the group Scattered Spider. Ciaran McEnvoy, a spokesperson for the DOJ, confirmed to TechCrunch that the five hackers are suspected of being part of the group known as Scattered Spider. 

In one of the court documents, prosecutors describe the cybercriminal gang as “a loosely organized financially motivated cybercriminal group whose members primarily target large companies and their contracted telecommunications, information technology, and business process outsourcing suppliers.”

According to one of the court documents, which cites the FBI’s investigation, Buchanan and the other hackers targeted at least 45 companies in Canada, the U.S., the U.K., and other countries. 

Orban is accused of having stolen more than $800,000 in Bitcoin and Ethereum from several victims, one of the court documents says. One of the documents also mentions an “unindicted co-conspirator,” and “other co-conspirators,” suggesting there’s more suspects that have yet to be publicly accused of crimes. 

The hackers are said to be part of a wider cybercriminal community referred to by researchers as “the Com,” a largely nebulous network of mostly young adults and teenagers, who are highly proficient in impersonation and social engineering techniques capable of tricking employees into handing over their corporate passwords.

The National Crime Agency did not respond to a request for comment on Buchanan’s arrest. 

Carly Page contributed reporting.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

OpenAI’s GPT-5 reportedly falling short of expectations

OpenAI’s efforts to develop its next major model, GPT-5, are running behind schedule, with results that don’t...

OpenAI announces new o3 model — but you can’t use it yet

Welcome back to Week in Review. This week, we’re looking at OpenAI’s last — and biggest —...

Google pushes back against DOJ’s ‘interventionist’ remedies in antitrust case

Google has offered up its own proposal in a recent antitrust case that saw the US Department...

If climate tech is dead, what comes next?

Humans have an innate desire to name things, but to be honest, we’re not always that good...

Hollywood angels: Here are the celebrities who are also star VCs

Becoming a venture capitalist has become the latest status symbol in Hollywood.  Everyone these days, from Olivia Wilde...

Meet Skyseed, a VC fund and incubator backing the Bluesky and AT Protocol ecosystem

On November 15, Peter Wang posted a message requesting ideas for a new incubator and fund to...

Sam Altman disputes Marc Andreessen’s description of AI meetings with Biden administration

Famed investor Marc Andreessen recently talked about meetings with Biden administration staff who gave him the impression...

EV startup Canoo places remaining employees on a ‘mandatory unpaid break’

Struggling electric van startup Canoo has placed its remaining employees on what it’s calling a “mandatory unpaid...