Scattered Spider Hackers Plead Guilty on Day 1 of Trial

2026-06-27T19:23:29Z4465465e15cd47073aef22c2cb77f41cb1b13dc493f3d67cf730fe8b86c5d45e
AWS GovCloud credentialsAlarum TechnologiesCISA data leakDDoSInstagram account takeoverKimwolf botnetMeta AI support bot abuseMicrosoft Patch TuesdayNetNutNetherlands server seizurePopa botnetRussian influence operationsScattered SpiderThe Gentlemen ransomwareTransport for London outagecongressional inquirycritical vulnerabilitieslaw enforcement arrestspublic GitHub leakresidential proxy abuse

What happened

Multiple high-impact cyber incidents reported: a CISA contractor publicly exposed highly privileged AWS GovCloud credentials and internal build/deploy artifacts on GitHub, prompting congressional inquiries and large-scale containment efforts; researchers linked the years‑old Popa Android TV‑box botnet to NetNut (Alarum Technologies), implicating a commercial residential‑proxy provider in massive ad fraud, account takeover and scraping operations; two members of Scattered Spider pleaded guilty in the U.K. for an August 2024 attack that crippled Transport for London; investigators profiled The G

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
4465465e15cd47073aef22c2cb77f41cb1b13dc493f3d67cf730fe8b86c5d45e
Enrichment time
2026-06-27T19:23:29Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.