A 20-year-old member of the infamous cybercrime gang often called Scattered Spider has been sentenced to 10 years in jail within the U.S. in reference to a sequence of main hacks and cryptocurrency thefts.
Noah Michael City pleaded responsible to fees associated to wire fraud and aggravated identification theft again in April 2025. Information of City’s sentencing was reported by Bloomberg and Jacksonville information outlet News4JAX.
As well as, 120 months in federal jail, City faces an extra three years of supervised launch and has been ordered to pay $13 million in restitution to victims. In a press release shared with security journalist Brian Krebs, City known as the sentence unjust.

City, who additionally glided by the aliases Sosa, Elijah, King Bob, Gustavo Fring, and Anthony Ramirez, was arrested by U.S. authorities in Florida in January 2024 for committing wire fraud and aggravated identification theft between August 2022 and March 2023. These incidents led to the theft of a minimum of $800,000 from a minimum of 5 completely different victims, per the U.S. Division of Justice (DoJ).
Prosecutors mentioned City and his co-conspirators engaged in SIM swapping assaults to hijack victims’ cryptocurrency accounts and plunder the digital belongings.
Later that November, the DoJ unsealed legal fees towards City and 4 different members of Scattered Spider for utilizing social engineering strategies to focus on staff of firms throughout the U.S. and to interrupt into company networks and steal proprietary information and to siphon tens of millions of {dollars} in cryptocurrency.
Tyler Robert Buchanan, who’s amongst these indicted, was extradited from Spain to the U.S. in April following his arrest within the European nation final June.
The event comes as Scattered Spider has joined forces with different risk teams ShinyHunters and LAPSUS$ to type a brand new cybercrime alliance. The group, related to a broader English-speaking cybercriminal collective known as The Com, has a historical past of conducting social engineering, credential theft, and SIM swapping, preliminary entry, ransomware deployment, information theft, and extortion assaults.
“Scattered Spider has traditionally leaned on ways that generate urgency, drive media and trade consideration, create worry of publicity, and assist power victims to payout faster,” Adam Darrah, vp of intelligence at ZeroFox, instructed The Hacker Information in a press release.
“Timed leaks, countdown threats, and taunts directed at security corporations are all a part of their playbook. They’ve ties to a wider community of like-minded actors, which has given them entry to extra instruments, information, and infrastructure, multiplying their effectiveness. We commonly see teams staff up when there is a rise in exterior pressures, like legislation enforcement crackdowns. To outlive, these teams must consolidate. And the result’s typically a extra versatile and probably harmful mixed operation.”

Cybersecurity agency Flashpoint, which printed a profile of Scattered Spider final week, mentioned the financially-motivated hacking group adopts a wave-like method by selecting a particular sector and attacking as many organizations inside that vertical over a brief span of time.
“The ways employed by Scattered Spider show their means to use weaknesses in security applications by focusing on folks relatively than strictly methods or technical vulnerabilities,” it mentioned. “Their use of social engineering, by way of vishing, smishing, and MFA fatigue assaults, proves that even probably the most superior technical defenses could be circumvented by human deception.”



