# Senior Scattered Spider Operator Pleads Guilty to Coordinated Cryptocurrency Theft Campaign
A prominent member of the international cybercrime collective known as Scattered Spider has accepted responsibility for his role in a sophisticated scheme that compromised major technology firms and resulted in the theft of millions in digital assets from investors across the United States. The guilty plea represents a significant law enforcement victory against one of the most operationally successful criminal hacking networks of the past five years.
## Who Is Tylerb?
Tyler Robert Buchanan, a 24-year-old from Dundee, Scotland, operated under the hacker moniker "Tylerb" within the criminal underground. His reputation in hacking circles was substantial enough to earn a position on informal leaderboards that tracked the exploits of top-performing cyber thieves—a digital hall of infamy within criminal communities. His eventual downfall demonstrates how even carefully hidden digital identities can be unraveled through forensic investigation and international law enforcement cooperation.
Buchanan's journey from prominent cybercriminal to federal custody illustrates the inherent instability of criminal enterprise, particularly when participants operate in jurisdictions without consistent protective infrastructure. His case also highlights how orchestrated pressure from rival criminal actors forced operational mistakes that ultimately made prosecution possible.
## The Attack Campaign: Scope and Methods
Between 2022 and the present, Buchanan and his co-conspirators orchestrated a coordinated assault targeting technology sector organizations. The operation commenced with a volley of text message-based phishing attacks designed to harvest employee credentials from companies with valuable networks and sensitive data.
Targeted Companies:
The initial phishing phase succeeded in breaching multiple organizations, granting the attackers access to internal systems and sensitive data repositories. The stolen information then became raw material for a secondary exploitation strategy: coordinated attacks against individual cryptocurrency investors.
## The SIM-Swap Mechanism
Once Scattered Spider possessed employee credentials and had compromised corporate networks, members leveraged stolen data to execute SIM-swap attacks—a technically unsophisticated but devastatingly effective social engineering technique.
In a typical SIM-swap operation, the attacker contacts a telecommunications provider's customer service department, impersonating an account holder. Through a combination of social engineering, pretexting, and occasionally threats or intimidation against customer service representatives, the attacker convinces the telecom to transfer the target's phone number to a SIM card under the attacker's control.
Once the number is activated on the attacker's device, all incoming communications route to them instead: text-based authentication codes, password reset links, two-factor authentication messages. With these intercepted credentials, the attacker gains access to cryptocurrency exchange accounts, wallet management platforms, and other financial services relying on SMS-based verification.
Attack Pipeline:
1. Deploy SMS phishing to corporate targets
2. Harvest employee credentials and internal data
3. Identify cryptocurrency-holding victims from stolen data
4. Execute SIM-swaps against individual targets
5. Transfer digital assets to attacker-controlled wallets
This multi-stage approach proved remarkably effective. Federal prosecutors documented that Buchanan alone stole at least $8 million in cryptocurrency from individual victims throughout the United States.
## Digital Forensics and Attribution
Buchanan's operational security proved insufficient against dedicated federal investigation. The FBI traced Buchanan's involvement through digital infrastructure evidence rather than witness testimony or insider information.
Investigators discovered that the same username and email address used to register phishing domains appeared repeatedly across the entire 2022 campaign. Domain registration logs revealed that the account owner accessed their registrar account from an Internet address located in the United Kingdom. Working with domain registry NameCheap and coordinating with Scottish law enforcement, the FBI confirmed that the IP address belonged to internet service leased to Buchanan throughout 2022.
A subsequent search of Buchanan's residence in Scotland yielded physical evidence corroborating the digital forensics: devices containing data stolen from SMS phishing victims and cryptographic seed phrases from cryptocurrency theft victims.
## Flight, Capture, and Extradition
In February 2023, Buchanan fled the United Kingdom after a confrontation with rival cybercriminals. A competing criminal organization hired individuals to physically assault Buchanan, including an assault on his mother, accompanied by threats to use a blowtorch against him unless he surrendered cryptocurrency wallet credentials. The violent confrontation forced Buchanan into international exile.
His hiding period ended in June 2024 when Spanish authorities apprehended him at an airport while attempting to board a flight to Italy. Following extradition proceedings, Buchanan was transferred to U.S. federal custody in April 2025, where he remained until his guilty plea.
## Legal Proceedings and Sentencing
Buchanan's plea agreement addresses two primary charges: wire fraud conspiracy and aggravated identity theft. Under sentencing guidelines, he faces a statutory maximum of 22 years in federal prison. However, his ultimate sentence may be substantially reduced through mitigating factors including his relatively young age, limited prior criminal history, time served in custody, and any cooperation he provides to federal authorities.
His sentencing hearing is scheduled for August 21, 2026.
## Broader Criminal Network Context
Buchanan represents the second known Scattered Spider member to enter guilty pleas in federal court. Noah Michael Urban, 21, previously received a 10-year sentence and was ordered to pay $13 million in restitution. Three other alleged co-conspirators remain under active criminal charges in the United States, while two additional suspected Scattered Spider operators face trial in the United Kingdom on charges related to attacks against British retailers, transit systems, and American healthcare organizations.
The Scattered Spider collective operates within a larger ecosystem called "The Com"—a sprawling online community where hackers from various independent criminal groups boast about high-profile breaches on messaging platforms including Telegram and Discord. Members coordinate across organizational boundaries, sharing techniques, exchanging information, and celebrating successful attacks. The group's operational methodology centers on social engineering: manipulating individuals through phone calls, email, and text messages into voluntarily surrendering credentials that grant access to corporate internal networks.
## HackWire Analysis
The Scattered Spider prosecution demonstrates that the gap between cybercriminal notoriety and actual legal accountability, while substantial, remains bridgeable through systematic forensic investigation. Buchanan cultivated an online reputation as an elite cyber thief, yet fundamental operational security lapses—consistent use of the same username, registration from residential ISP addresses, physical evidence retained at home—provided the evidential foundation for prosecution.
The case also illustrates how transnational crime increasingly encounters transnational consequences. Buchanan's journey from Scotland to Spain to federal custody reflects law enforcement's capacity to pursue suspects across borders and prosecute in jurisdictions where damages were sustained. The primary vulnerability in Scattered Spider's operational model remains its reliance on social engineering and telecommunications infrastructure that governments have begun defending more systematically.
For enterprise security teams, the tactical implications are clear: SMS-based authentication continues to represent a critical vulnerability, rival criminal groups pose physical threats to former operators, and operational security failures compound over time rather than resolve.