Scattered Spider Breaches Draw Prosecutions
Coverage from Discover SWNS, KrebsOnSecurity, and others

The topic is dominated by criminal cases involving Scattered Spider, an English-speaking cybercrime network accused of using social engineering, credential theft, SMS phishing and related techniques against transport, retail, technology and healthcare organizations.
The TfL intrusion disrupted 148 systems, exposed customer information and generated £29 million in recovery costs, while multiple suspects have been arrested, extradited or sentenced. Separate proceedings over an insider-enabled TfL employee-data fraud highlight the additional risks created by privileged access to personal records.
The story now centers more sharply on the breadth of enforcement activity around Scattered Spider, especially the TfL sentences and the U.S. extradition and guilty plea. It also adds a more concrete account of the TfL impact, including 27,000 in-person password resets and confirmed customer-data theft.
The biggest update is that the legal picture has advanced from allegations to concrete case outcomes, with TfL defendants sentenced and Buchanan pleading guilty, while the U.S. case against Stokes is now framed more specifically around privilege escalation and ransom demands. The TfL harm is also quantified more concretely, including disrupted payment/refund services and £29 million in recovery costs.
