Scattered Spider's 'Tylerb' Pleads Guilty: How a 24-Year-Old Scot Helped Loot Millions from Silicon Valley
Tyler Robert Buchanan's guilty plea exposes the brutal efficiency of SMS phishing as a weapon against even the most sophisticated tech firms.
Written by OutOfToken AI
May 24, 2026 · 4 min read · Synthesized from reporting by Krebs on Security · How this works
Tyler Robert Buchanan, a 24-year-old from Dundee, Scotland, has pleaded guilty in a U.S. federal court to wire fraud conspiracy and aggravated identity theft — charges stemming from his senior role in Scattered Spider, one of the most disruptive cybercriminal organizations to emerge this decade. Operating under the handle 'Tylerb,' Buchanan was a key architect of a phishing campaign that ripped through at least a dozen major technology companies in the summer of 2022, ultimately funneling tens of millions of dollars in stolen cryptocurrency into the group's coffers. Now in U.S. custody and facing more than 20 years behind bars, his guilty plea marks the most significant legal milestone yet in the government's pursuit of Scattered Spider's core membership.
The SMS Trap That Brought Down Corporate Giants
Scattered Spider — also tracked by cybersecurity firms under the designation UNC3944 — built its reputation on a deceptively low-tech entry point: text messages. The group's 2022 campaign deployed mass SMS phishing, or 'smishing,' blasts impersonating internal IT departments and authentication portals. Employees at targeted companies received urgent-sounding texts directing them to credential-harvesting sites that mimicked legitimate corporate login pages with near-perfect fidelity. Once inside, operatives like Buchanan leveraged stolen credentials and SIM-swapping techniques to bypass multi-factor authentication, escalate privileges, and pivot deep into corporate infrastructure. The approach required no zero-day exploits — just social engineering executed at industrial scale against human psychology.
Cryptocurrency at the Center of the Scheme
While the initial intrusions targeted technology companies — the specific names of which have not been fully disclosed in public court records — the financial endgame was consistently cryptocurrency. Scattered Spider's operatives used their deep network access to identify and drain the digital asset holdings of individual investors whose accounts were custodied through or accessible via the compromised platforms. The group's ability to chain together corporate breaches, SIM swaps, and crypto theft into a single fluid operation illustrated a level of operational sophistication that belied the relatively young ages of its members. U.S. prosecutors allege the total haul reached tens of millions of dollars across the campaign's targets.
"Scattered Spider's 2022 phishing campaign penetrated at least a dozen major technology companies — not through exotic exploits, but through text messages and manipulated employees. Buchanan alone now faces over 20 years in federal prison."
A Wider Web: Scattered Spider's Expanding Legal Reckoning
Buchanan's plea does not exist in isolation. Scattered Spider — a loosely organized, English-speaking collective with members spanning the United States and United Kingdom — has been under sustained law enforcement pressure following a string of high-profile breaches that extended well beyond 2022, most notably the devastating ransomware attacks against MGM Resorts International and Caesars Entertainment in 2023 that collectively cost those companies hundreds of millions of dollars. Multiple alleged members have been arrested across both countries, and the Buchanan plea signals that prosecutors are methodically working through the group's known hierarchy. The DOJ's strategy appears focused on securing cooperating witnesses and guilty pleas rather than protracted trials — a tactic designed to accelerate accountability and potentially unlock intelligence on the group's remaining active members.
Tyler Buchanan's guilty plea is a data point in an ongoing reckoning, not a conclusion. Scattered Spider's model — nimble, socially engineered, and cryptocurrency-focused — proved devastatingly effective precisely because it exploited the gap between enterprise security investments and the irreducible vulnerability of human employees. As sentencing approaches and cooperation potentially deepens, the case will test whether aggressive prosecution can meaningfully deter a generation of cybercriminals who grew up treating corporate networks as both playground and ATM. The answer will reverberate well beyond one courtroom in the United States.
Editorial Note
Krebs on Security is a highly reputable cybersecurity news outlet with strong track record for accuracy in reporting on cybercrime. The Scattered Spider group (also known as UNC3944) is a documented cybercriminal organization that has been publicly attributed to major breaches by cybersecurity firms and law enforcement. Guilty pleas in federal cases are matters of public record and readily verifiable through court documents.
Claim Tracker
AI-assessed
Confirmed in U.S. federal court proceedings and indictments
Public court record documented in federal filings
Confirmed in FBI and cybersecurity firm reports tracking the campaign
Exact amount not precisely quantified in available disclosures; 'tens of millions' is approximate
Confirmed by Mandiant and other threat intelligence organizations
Ask AI about this story
// discussion
sign in to join the discussion