Virtual Event: Threat Detection & Incident Response Summit - Watch Now
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

Suspected Scattered Spider Member Arrested in UK

UK authorities have arrested a 17-year-old suspected of being a member of the Scattered Spider cybercrime gang.

Authorities in the UK on Friday announced the arrest of a 17-year-old suspected of being involved in cyberattacks against multiple organizations, including MGM Resorts.

The teenager was arrested in Walsall as part of a global investigation into a large-scale cybercrime group known for hacking large organizations worldwide and deploying ransomware, the West Midlands Police announced, specifically naming MGM as one of the victims.

“The suspect was taken into custody on suspicion of Blackmail and Computer Misuse Act offenses and has been released on bail while we continue with our enquiries. We also recovered evidence at the address including a number of digital devices which will undergo forensic examination,” the authorities said.

The attack on MGM occurred on September 10, 2023, and resulted in the hospitality and entertainment giant taking many of its systems offline, which impacted its casinos, website, email systems, and systems used for bookings, reservations, and digital hotel room keys.

The company managed to restore its systems roughly ten days after the attack and confirmed several weeks later that the costs associated with the incident exceeded $110 million.

Shortly after the attack came to light, a subgroup of the AlphV/BlackCat ransomware group claimed responsibility for hacking MGM, boasting about how easy social engineering granted them access to the giant’s systems.

Advertisement. Scroll to continue reading.

Several days after the attack on MGM, Caesars Entertainment disclosed in a regulatory filing that it fell victim to a ransomware attack on September 7. The casino owner reportedly made a $15 million ransom payment to the Scattered Spider cybercrime group.

AlphV/BlackCat was one of the ransomware families that Scattered Spider (also known as Muddled Libra, Øktapus, Scatter Swine, Starfraud, and UNC3944) was known to deploy in attacks along with remote access tools and information stealers such as Raccoon and Vidar.

The cybergang reportedly switched to RansomHub and Qilin ransomware after BlackCat pulled an exit scam earlier this year, reportedly bagging a $22 million ransom from the Change Healthcare hack and leaving the threat landscape.

The new arrest comes roughly one month after a British man was arrested in Palma de Mallorca for his alleged leadership role in the Scattered Spider gang. Another alleged member of the group, a 19-year-old from Florida, was arrested in January.

Related: Two Arrested in UK for Smishing Campaign Powered by Homemade SMS Blaster

Related: Interpol Arrests 300 People in a Global Crackdown on West African Crime Groups Across 5 Continents

Related: US Offers $10 Million for Information on BlackCat Ransomware Leaders

Related: European Police Arrest 42 After Cracking Covert App

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.