Cybercrime DB

Teenage Hackers Indicted for Major Breaches

Social engineering and stolen credentials, not fancy hacks, fueled billion-dollar breaches.

Staff Writer · · 11 min read
Cover illustration for “Teenage Hackers Indicted for Major Breaches”
hacker arrests and indictments · September 16, 2026 · 11 min read · 2,418 words

The teenagers behind some of the biggest breaches of the last three years didn't need a zero-day or a nation-state budget. They needed a phone, a LinkedIn profile, and about ten minutes. That's the entire story of Scattered Spider, Lapsus$, and the loose network calling itself "The Com," roughly 1,000 people, mostly young, mostly English-speaking, who've hit companies worth a combined $1 trillion-plus since 2022. This piece walks through how they did it, who's been charged, and what the pattern means for anyone running a security team.

The MGM and Caesars attacks as a case study in what social engineering looks like at scale

The 2023 MGM Resorts breach started with a phone call. Someone found an MGM IT support employee on LinkedIn, called the helpdesk pretending to be that person, and asked for a password reset. That's the whole trick. No malware, no exploit kit, no exotic infrastructure. Just a phone call and a password reset. Within minutes, attackers had control of internal systems across multiple MGM properties on the Strip. Slot machines went dark, reservations failed, room keys stopped working, payroll got disrupted.

MGM refused to pay. Its own SEC filing put losses at $110 million, though the Clark County DA's office claimed the number was closer to $200 million, which MGM disputes. Caesars took the opposite bet and paid $15 million after attackers got into loyalty program data containing sensitive personal information. More than 65,000 Social Security numbers were stolen between the two incidents, and paying didn't buy Caesars any less exposure than MGM got by refusing. The ransom payment bought Caesars nothing that MGM's refusal cost it.

The suspect in both intrusions was 15 at the time. He surrendered to Las Vegas authorities in September 2025, facing extortion and conspiracy charges, with Clark County pursuing adult prosecution. When the FBI raided his home in Illinois in February 2025, they found multiple laptops, one hidden under the bathroom sink. The investigation stretched across Las Vegas, Illinois, New Jersey, and one country overseas, and the FBI still hasn't recovered more than $1.8 million in bitcoin tied to the case.

Clorox, hit by the same group, filed a $380 million lawsuit alleging its IT vendor Cognizant handed over credentials to attackers without checking who was actually asking. Strip away the legal language and it's a helpdesk agent picking up the phone and trusting the voice on the other end. Not a firewall gap. Not a patch that never shipped. A person who said yes too fast.

How stolen credentials from the PowerSchool breach travel further than their original theft

Matthew Lane was 19, a college freshman, when he got into PowerSchool's network in the summer of 2024 using stolen contractor credentials he found sitting online. Those credentials didn't originate with PowerSchool at all. Lane and his accomplices had already broken into a telecom company, stealing customer data and login credentials in that earlier job. Lane went on to extort that same telecom company for $200,000 between April and May 2024, months before he ever touched PowerSchool.

By December 2024, PowerSchool faced a ransom demand of roughly $2.85 million in Bitcoin, with the stolen files sitting on a leased server in Ukraine. The exposure was enormous: Social Security numbers, birth dates, medical records, grades, family information, covering 60 million students and 10 million teachers. PowerSchool's software ran in three-quarters of school districts across the continent at the time. North Carolina alone counted 4 million affected residents, enough that its attorney general called it probably the most impacted state in the country.

PowerSchool paid. The data leaked anyway, resurfacing in follow-on extortion attempts. Paying a ransom just buys a pause, and sometimes not even that. It just buys a pause, and sometimes not even that.

Lane got four years in federal prison and a restitution order over $14 million. In his own words, hacking became its own addiction: "I was addicted to hacking. That gave me the most natural high ever." He started in online gaming communities, taught himself the rest, and was studying cybersecurity in college while still actively offending. The real lesson for security teams is in the timeline: credentials stolen in an earlier telecom breach surfaced again as a factor in an unrelated breach in a completely different industry, years later. Credentials don't expire just because the news cycle moves on.

Diagram: One Phone Call, $110 Million: The MGM–Caesars Damage Comparison. Visualizes: Show the contrasting outcomes of MGM and Caesars after the same attacker breached both in 2023.

SIM-swapping as infrastructure: how the group converts phone access into financial theft and network entry

SIM-swapping means convincing a cell carrier to move a target's phone number onto a SIM card the attacker controls. Every call, every text, every SMS one-time code routes straight to the attacker's device instead of the real owner's. The "second factor" in two-factor authentication becomes whatever the attacker wants it to be, since it's just handing the code to whoever won the phone call.

Noah Michael Urban, of Palm Coast, Florida, pleaded guilty to wire fraud and conspiracy. Prosecutors say he helped steal at least $800,000 from five victims by hijacking their phone numbers onto devices the attackers controlled. He got 120 months in federal prison and owes $13 million in restitution. November 2024 indictments describe a companion tactic running alongside it: mass texts warning employees their accounts would be deactivated, pushing them toward credential-harvesting links. SIM-swapping and phishing-by-text aren't competing methods here. They get used together, on the same target, in the same week.

Tyler Buchanan, believed to be a ringleader, was arrested at Palma Airport in Spain in June 2024 while trying to board a flight to Italy. He faces up to 22 years. Three more defendants named in the same November indictment, Ahmed Hossam Eldin Elbadawy (24, Texas), Evans Onyeaka Osiebo (21, Dallas), and Joel Martin Evans (26, North Carolina), are still awaiting prosecution.

Once an attacker owns the phone number, SMS-based multi-factor authentication is worthless operationally, since the code goes straight to them regardless of what the login screen thinks it's protecting. The vulnerability lives in the human process of verifying a caller's identity before making account changes. A carrier support agent talked into a SIM transfer over the phone is the exact same failure mode as the MGM helpdesk call, just with a different company logo on it.

How Scattered Spider constructs its social engineering scripts to succeed against trained employees

Research from cyber intelligence firm Silent Push shows the group pivoted hard back toward social engineering starting in March 2025, treating it as the backbone of the ransomware operation rather than a side tactic. The recon process is methodical. The process often starts with LinkedIn searches to map out who reports to whom and identify targets by name and title.

From there, attackers call employees directly, posing as a new hire asking harmless-sounding questions about which platforms the company uses or how cloud access works. Low suspicion, easy answers. Before making the call, they'll often read through internal Slack channels to pick up the company's actual lingo and acronyms, so they sound like they already belong there.

Researcher Allison Nixon flagged a nastier escalation: phishing calls claiming HR is investigating something the employee supposedly said, often a fabricated and distressing accusation. The goal is psychological, meant to make the target "quite upset, quite motivated to shut this down" fast, without stopping to verify anything.

Researchers have described the group reading red team and blue team research blogs, copying the techniques, and swapping notes in chat rooms. They lean on legitimate software tools to get where they need to go, so there's often no malware for detection systems to flag. Zach Edwards, a senior threat researcher at Silent Push, says the group runs something close to A/B testing on its call scripts, tracking which pretexts succeed and locking those in. That's a tested, iterated method, and it beats plenty of training programs precisely because it treats social engineering like a product to optimize.

Federal advisories on the group's tactics lay out the specific helpdesk techniques: posing as IT staff to get employees to run commercial remote-access tools, talking employees into sharing one-time passcodes, posing as employees to get a helpdesk to reset a password or move MFA registration to a new device, and MFA fatigue attacks, where the attacker floods someone with push notifications until they tap "approve" just to make it stop. None of that breaks a technical control. It just needs one tired employee saying yes.

What the Lapsus$ cases add to the picture of how young attackers handle data extortion

Two UK teenagers, Arion Kurtaj (18) and a 17-year-old who can't be named for legal reasons, were charged as key figures in Lapsus$. Both face charges tied to breaches of BT Group and Nvidia, covering computer misuse, blackmail, and fraud. Kurtaj alone was separately charged over intrusions at Rockstar Games and Uber.

The Nvidia breach alone involved roughly a terabyte of stolen data, part of it released publicly as leverage, with a ransom demand threatening to dump the rest. Kurtaj was found unfit to stand trial for medical reasons, so a jury can only rule on whether he did it, not convict him. He'd avoid jail even if found liable.

Strip away the personalities, and the model is identical to Lane's playbook at PowerSchool and Scattered Spider's approach at MGM and Caesars: steal the data, threaten to release it, demand payment. There's no visible coordination between these groups, yet they've converged on the exact same tactic, which says more about how well the tactic works than about any shared leadership. None of it needed malware in the traditional sense. The leverage was the data itself.

What cross-border enforcement in the UK prosecutions reveals about the group's operational reach

Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, admitted to conspiring against Transport for London's computer systems in a way that risked serious harm to public safety. Flowers separately admitted to a conspiracy targeting healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.

In September 2025, prosecutors unsealed an indictment alleging Jubair and other Scattered Spider members carried out 120 network intrusions against 47 organizations, involving computer fraud, wire fraud, and money laundering. That same indictment names Jubair as a core member responsible for extorting at least $115 million.

A separate case in Finland shows the flip side. A Scattered Spider-linked defendant, arrested and extradited from Finland, allegedly breached a luxury jewelry retailer, stole data, and demanded roughly $8 million in cryptocurrency in May 2025. That one didn't work. The retailer's security team caught it, evicted the attackers, and paid nothing. Most of these stories end with a payout. This one didn't, and the difference wasn't luck. It was a team that noticed fast and acted faster.

The geography spans four countries, and no single country's law enforcement owns this investigation. Arrests happen years after the damage is already done. Waiting for handcuffs was never a security strategy to begin with.

The recruitment pipeline that keeps replacing arrested members

The Com recruits openly on Telegram. Posts offer $300 per "successful call," paid in crypto, and explicitly welcome people with zero experience: "we can train you from scratch." One post from December 15 asked for availability between 12pm and 6pm EST on weekdays, a schedule that lines up suspiciously well with a school day. Some postings prioritize female candidates, and nearly all of them require accent-free English, meaning native speakers only.

Zach Edwards of Silent Push compares the structure to classic organized crime, where the youngest members take on the riskiest, most exposed work. "These kids are just throwing themselves to the slaughter," he's said. Recruitment starts in online gaming communities, where hacking gets treated as normal and older members flash cash and expensive gear as bait. There's no teacher in the hallway, no security guard walking by, nothing to interrupt it.

Cynthia Kaiser, a former FBI deputy assistant director of cyber, says parents usually find out only when federal agents show up at the door. The online world strips away every early-warning sign that would normally tip a parent off to other kinds of trouble. She describes the families involved as "loving parents, involved parents, kids who really did have a lot of advantages." Lane's own account backs this up: gaming communities, admiration for the "lavish, luxurious lifestyle" older hackers displayed, self-taught skills, and formal cybersecurity coursework running in parallel with active crimes.

Edwards notes the group's activity even slows down around the holidays, "because they're opening presents from Mom under the Christmas tree." Funny, until it isn't, because it's also the clearest possible reminder of exactly who's doing this. For defenders, the operational takeaway is blunt: arrests don't end the threat. The techniques outlive whoever gets caught, since the pipeline behind them just plugs in the next recruit.

The attack chains require defenders to treat as primary controls, not secondary ones

Every case above traces back to the same failure point: a person did something a process should have stopped. MGM's helpdesk reset a password without verifying who was calling. Cognizant handed credentials to a caller nobody checked. Carriers moved phone numbers to new SIM cards without confirming identity first. None of that is a technology gap. It's a process built around trusting a voice on the phone, and no amount of network hardening fixes a habit.

Helpdesks and IT support desks are the attack surface now, full stop. CISA's July 2025 advisory names five specific helpdesk techniques, and every one depends on a human being taking an action. A firewall rule doesn't stop any of them, because none of them touch the firewall.

SMS-based MFA collapses into whatever the attacker can access once they control the phone number, since the code goes straight to whoever holds it. Phishing-resistant authentication, hardware keys, and verified callback procedures for any credential reset stop this kind of takeover before it starts, in a way another layer of network monitoring never will. Getting ahead of this pattern means tracking these actors across incidents and sectors instead of treating each breach as its own isolated event, since the same crew that hit a casino this year hit a school software vendor the year before. Research-focused firms like Cyberou build that continuity into their threat analysis, following methods and infrastructure across time instead of starting fresh with every headline.

The technique is old. The scripts get refined. The people behind them turn over fast, arrested one month, replaced the next. The fix was always the same, and it was never technical: a helpdesk that doesn't take a stranger's word over the phone.

Sources

  1. 15-year-old accused in major casino cyberattacks; Caesars paid $15M after extortion, Las Vegas prosecutor says
  2. Minor Mayhem: The Gen Z hackers behind major data breaches
  3. Feds are hunting teenage hacking groups like 'Scattered Spider' who have targeted $1 trillion worth of the Fortune 500 since 2022 | Fortune
  4. Did a teenager take down Vegas? Casino cyberattack shows how AI can make anyone a hacker
  5. krebsonsecurity.com
  6. cybersecuritydive.com

More in hacker arrests and indictments