Scattered Spider Hackers Plead Guilty on Day 1 of Trial
2026-06-27T19:23:29Z•4465465e15cd47073aef22c2cb77f41cb1b13dc493f3d67cf730fe8b86c5d45e
AWS GovCloud credentialsAlarum TechnologiesCISA data leakDDoSInstagram account takeoverKimwolf botnetMeta AI support bot abuseMicrosoft Patch TuesdayNetNutNetherlands server seizurePopa botnetRussian influence operationsScattered SpiderThe Gentlemen ransomwareTransport for London outagecongressional inquirycritical vulnerabilitieslaw enforcement arrestspublic GitHub leakresidential proxy abuse
What happened
Multiple high-impact cyber incidents reported: a CISA contractor publicly exposed highly privileged AWS GovCloud credentials and internal build/deploy artifacts on GitHub, prompting congressional inquiries and large-scale containment efforts; researchers linked the years‑old Popa Android TV‑box botnet to NetNut (Alarum Technologies), implicating a commercial residential‑proxy provider in massive ad fraud, account takeover and scraping operations; two members of Scattered Spider pleaded guilty in the U.K. for an August 2024 attack that crippled Transport for London; investigators profiled The G
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 4465465e15cd47073aef22c2cb77f41cb1b13dc493f3d67cf730fe8b86c5d45e
- Enrichment time
- 2026-06-27T19:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.