Scattered Spider Hackers Plead Guilty on Day 1 of Trial
2026-06-30T13:23:31Z•a468fb87c37742086c6fea1d39b0c8c7c7898d35684660d6d7068c761a41f5df
account takeoveradvertising fraudai social engineeringalarum technologiesaws govcloudcisacredential leakdata leakexploit codeinstagramkimwolf botnetmetamicrosoft patch tuesdaynetherlandsnetnutpopa botnetransomwareresidential proxyrussia-linked operationsscattered spiderserver seizurethe gentlementransport for londonvulnerabilitiesweb scraping
What happened
This collection of KrebsOnSecurity items (May–Jun 2026) highlights multiple high-impact cyber developments: guilty pleas by two Scattered Spider members for the August 2024 Transport for London disruption; research tying the large Android-based “Popa” botnet to NetNut (Alarum Technologies) — raising concerns about commercial proxy abuse for ad fraud, account takeovers and scraping; investigative clues identifying the administrator of The Gentlemen ransomware group (noting an aggressive 90% affiliate payout model); a record Microsoft Patch Tuesday (nearly 200 CVEs, 30+ rated critical and at-leb
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- a468fb87c37742086c6fea1d39b0c8c7c7898d35684660d6d7068c761a41f5df
- Enrichment time
- 2026-06-30T13:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.