Last week, U.S. prosecutors filed hacking charges against Thalha Jubair, a 19-year-old from the United Kingdom, alleging his central role in Scattered Spider, a major cybercriminal organization linked to extorting no fewer than $115 million from victims. The charges coincided with Jubair and a suspected accomplice appearing before a London court on allegations of infiltrating and extorting major U.K. retailers, the London public transit network, and American healthcare organizations.

During a court proceeding last week, prosecutors in the U.K. presented numerous charges against Jubair and 18-year-old Owen Flowers, linking both individuals to a destructive cyberattack in August 2024 that disabled Transport for London's operations across the Greater London region.

On July 10, 2025, reporting revealed that Flowers and Jubair had been apprehended in the United Kingdom following recent Scattered Spider extortion campaigns targeting the retailers Marks & Spencer and Harrods, as well as the British grocery chain Co-op Group.

According to investigation sources, Flowers was the Scattered Spider operative who gave anonymous media interviews immediately following the group's September 2023 ransomware strikes that disrupted Las Vegas casinos run by MGM Resorts and Caesars Entertainment.

Jubair's suspected usernames on cybercrime-oriented Telegram channels displayed considerably more extensive criminal histories tied to significant and widely publicized data breaches spanning the past four years. The following account documents cybercriminal conduct that prosecutors have attributed to Jubair's alleged hacker identities, drawn from posts on public Telegram channels monitored by numerous cyber intelligence organizations.

Early Days (2021-2022)

Jubair allegedly served as a key participant in the LAPSUS$ cybercriminal organization, which penetrated numerous technology firms starting in late 2021 and obtained source code and confidential information from major corporations including Microsoft, Nvidia, Okta, Rockstar Games, Samsung, T-Mobile, and Uber.

This assertion comes from the former head of the now-defunct LAPSUS$. In April 2022, internal communications from a LAPSUS$ server were made public, revealing that Jubair collaborated with the organization under the aliases Amtrak and Asyntax. During the group's criminal operations, Asyntax cautioned the LAPSUS$ leader against sharing T-Mobile's branding in group communications, noting he had previously faced consequences for SIM-swapping and his parents would grow suspicious if such activity resumed.

The LAPSUS$ leader responded by publicly posting Asyntax's actual name, contact number, and other hacker pseudonyms into a public Telegram chat:

[Asyntax's real name, phone number, and other hacker handles were posted to a public Telegram chat room]

LAPSUS$ leader

The disclosure of LAPSUS$ communications also linked Amtrak/Asyntax to earlier hacker identities, including "Everlynn," who in April 2021 began marketing a cybercriminal service offering fraudulent "emergency data requests" directed at major social networking and email platforms.

The roster of the now-defunct “Infinity Recursion” hacking team, which sold fake EDRs between 2021 and 2022. The founder “Everlynn” has been tied to Jubair. The member listed as “Peter” became the leader of LAPSUS$ who would later post Jubair’s name, phone number and hacker handles into LAPSUS$’s chat channel.

In these "fake EDR" operations, perpetrators compromise email accounts belonging to law enforcement and government bodies, then transmit unauthorized requests for subscriber information (such as usernames, IP addresses, or email addresses), falsely claiming the data cannot wait for judicial authorization due to urgent life-threatening circumstances.

EarthtoStar

New Jersey prosecutors last week asserted that Jubair participated in a threat collective known variously as Scattered Spider, 0ktapus, and UNC3944, employing the nicknames EarthtoStar, Brad, Austin, and Austistic.

Jubair allegedly used the handle “Earth2Star,” a core member of a prolific SIM-swapping group operating in 2022. This ad produced by the group lists various prices for SIM swaps.

Starting in 2022, EarthtoStar jointly managed a thriving Telegram channel titled Star Chat, which housed an active SIM-swapping operation that persistently deployed voice and SMS phishing tactics to obtain credentials from personnel at major wireless carriers in the U.S. and U.K.

The operation subsequently leveraged this access to market a SIM-swapping capability that could reroute a target's phone line to a device controlled by the attackers, enabling them to capture the victim's calls and messages (including one-time authentication codes). Though Star Chat members targeted multiple wireless providers through SIM-swapping, their primary focus centered on compromising T-Mobile staff.

A redacted receipt from Star Chat’s SIM-swapping service targeting a T-Mobile customer after the group gained access to internal T-Mobile employee tools.

In February 2023, analysis of more than seven months of SIM-swapping solicitations on Star Chat revealed the channel regularly posted "Tmo up!" and "Tmo down!" announcements signaling periods when the group claimed operational access to T-Mobile's infrastructure.

The 104 days in the latter half of 2022 in which different known SIM-swapping groups claimed access to T-Mobile employee tools. Star Chat was responsible for a majority of these incidents. Image: krebsonsecurity.com.

The data indicated that Star Chat—alongside two competing SIM-swapping operations active during the same period—collectively breached T-Mobile over one hundred times during the final seven months of 2022. Star Chat proved substantially more prolific than its rivals, accounting for approximately 70 of those intrusions.

An examination of EarthtoStar's Star Chat communications, as documented by threat intelligence firm Flashpoint, demonstrates this individual also marketed "AT&T email resets" and AT&T call forwarding capabilities priced up to $1,200 per line. EarthtoStar clarified the functionality of this offering in a Telegram post:

Ok people are confused, so you know when u login to chase and it says '2fa required' or whatever the fuck, well it gives you two options, SMS or Call. If you press call, and I forward the line to you then who do you think will get said call?

EarthtoStar

New Jersey prosecutors contend Jubair participated in a widespread SMS phishing operation during summer 2022 that harvested single sign-on credentials from personnel at hundreds of organizations. The text communications directed recipients to access a fraudulent login portal mimicking their employer's Okta authentication interface, claiming they needed to review pending modifications to work schedules.

The phishing sites employed a Telegram bot to transmit submitted credentials instantaneously, permitting the perpetrators to leverage the captured username, password, and one-time code to authenticate as that worker at the legitimate employer system.

A visual depiction of the attacks by the SMS phishing group known as 0ktapus, ScatterSwine, and Scattered Spider. Image: Amitai Cohen twitter.com/amitaico.

This extended SMS phishing effort resulted in breaches and data exfiltration affecting more than 130 companies, including LastPass, DoorDash, Mailchimp, Plex, and Signal.

Da, Comrade

Star Chat concentrated on infiltrating business process outsourcing (BPO) firms that furnish customer service functions for numerous multinational enterprises, including several of the planet's largest telecom operators. In May 2022, EarthtoStar posted to the Telegram channel "Frauwudchat":

Hi, I am looking for partners in order to exfiltrate data from large telecommunications companies/call centers/alike, I have major experience in this field, [including] a massive call center which houses 200,000+ employees where I have dumped all user credentials and gained access to the [domain controller] + obtained global administrator I also have experience with REST API's and programming. I have extensive experience with VPN, Citrix, cisco anyconnect, social engineering + privilege escalation. If you have any Citrix/Cisco VPN or any other useful things please message me and lets work.

EarthtoStar

During the same period in summer 2022, at minimum two separate Star Chat-linked accounts—"RocketAce" and "Lopiu"—promoted the group's capabilities to members of the Russian-language cybercrime forum Exploit, offering:

The user “Lopiu” on the Russian cybercrime forum Exploit advertised many of the same unique services offered by EarthtoStar and other Star Chat members. Image source: ke-la.com.
  • SIM-swapping capabilities targeting Verizon and T-Mobile subscribers
  • Phishing pages customized for single sign-on service clients like Okta
  • Malware creation services
  • Extended validation (EV) code signing certificate distribution

These Exploit accounts established multiple sales postings in which they claimed administrative privileges at U.S. telecom companies and solicited other Exploit participants for assistance in monetizing such access. In June 2022, RocketAce, seemingly one of EarthtoStar's numerous pseudonyms, submitted a message to Exploit:

Hello. I have access to a telecommunications company's citrix and vpn. I would like someone to help me break out of the system and potentially attack the domain controller so all logins can be extracted we can discuss payment and things leave your telegram in the comments or private message me ! Looking for someone with knowledge in citrix/privilege escalation

RocketAce

On November 15, 2022, EarthtoStar announced in their Star Sanctuary Telegram channel that they were recruiting malware programmers with minimum three years of background and competency in creating rootkits, backdoors, and malware delivery mechanisms.

Optional: Endorsed by advanced APT Groups (e.g. Conti, Ryuk). Part of a nation-state / ex-3l (3 letter-agency).

EarthtoStar

2023-Present Day

The Telegram and Discord communication channels where Flowers and Jubair allegedly coordinated and executed their extortion schemes constitute components of a decentralized network termed the Com, an English-language cybercriminal ecosystem dominated by inhabitants of the United States, the United Kingdom, Canada, and Australia.

Numerous Com chat servers maintain hundreds to thousands of participants, and some noteworthy postings within these networks are employment announcements for physical assignments discoverable through searches for titles like "If you live near" or "IRL job"—meaning "in real life" job.

These "violence-as-a-service" solicitations typically involve "brickings," where individuals are compensated to hurl a brick through a window at a designated location. Additional IRL employment opportunities include tire puncturing, Molotov cocktail deployments, drive-by assaults, and residential break-ins. The intended targets of these services are typically other criminals within the network, though Com participants regularly seek assistance in harassing or intimidating cybersecurity professionals and law enforcement personnel investigating their suspected crimes.

The precise catalyst for this incident remains undetermined, but on January 13, 2023, an account associated with EarthtoStar on Star Sanctuary solicited a home invasion targeting a sitting U.S. federal prosecutor from New York. The posting contained a photograph of the prosecutor sourced from the Justice Department's public materials, accompanied by the message:

Need irl niggas, in home hostage shit no fucking pussies no skinny glock holding 100 pound niggas either

EarthtoStar

Throughout late 2022 and into early 2023, EarthtoStar's persona "Brad" (also known as "Brad_banned") regularly promoted Star Chat's malware creation services, featuring specialized malicious programs engineered to maintain attacker presence on compromised systems:

We can develop KERNEL malware which will achieve persistence for a long time,bypass firewalls and have reverse shell access.This shit is literally like STAGE 4 CANCER FOR COMPUTERS!!!Kernel meaning the highest level of authority on a machine.This can range to simple shells to Bootkits.Bypass all major EDR's (SentinelOne, CrowdStrike, etc)Patch EDR's scanning functionality so it's rendered useless!Once implanted, extremely difficult to remove (basically impossible to even find)Development Experience of several years and in multiple APT Groups.Be one step ahead of the game. Prices start from $5,000+. Message @brad_banned to get a quote

Brad

In September 2023, both MGM Resorts and Caesars Entertainment experienced ransomware incidents perpetrated by ALPHV and BlackCat, a Russian ransomware affiliate network. Caesars reportedly transferred a $15 million ransom payment in connection with that attack.

Shortly after MGM publicly disclosed the 2023 breach, Scattered Spider operatives claimed responsibility and informed journalists they had gained entry through social engineering of a third-party IT contractor. During the London court hearing last week, U.K. prosecutors informed the judge that Jubair possessed over $50 million in illegally obtained cryptocurrency, including assets traceable to the Las Vegas casino incidents.

Telegram terminated the Star Chat channel on March 9, 2025. Nevertheless, U.S. prosecutors allege Jubair and other Scattered Spider participants sustained their hacking, phishing, and extortion operations through September 2025.

Thalha Jubair (right), without his large-rimmed glasses, in an undated photo posted in The Com Cast.

In April 2025, the Com community circulated "The Com Cast," an extensive account detailing Jubair's purported cybercriminal background and various pseudonyms over time. The document contained photographs and audio recordings allegedly featuring Jubair and asserted that during his initial Com involvement, Jubair operated under the identities Clark and Miku (both pseudonyms previously employed by Everlynn for fake EDR activities).

More recently, the unidentified Com Cast authors contended that Jubair had employed the moniker "Operator," which aligns with a Com participant who administered an automated Telegram-powered doxing tool extracting consumer records from compromised data broker databases. This public revelation followed Operator's alleged seizure of Doxbin, a longstanding and widely despised platform utilized for "doxing" or disseminating sensitive personal details about individuals.

Operator/Clark/Miku: A key member of the ransomware group Scattered Spider, which consists of a diverse mix of individuals involved in SIM swapping and phishing. The group is an amalgamation of several key organizations, including Infinity Recursion (owned by Operator), True Alcorians (owned by earth2star), and Lapsus, which have come together to form a single collective.

The Com Cast

The New Jersey complaint alleges Jubair and additional Scattered Spider operatives perpetrated computer fraud, wire fraud, and money laundering offenses connected to no fewer than 120 computer network breaches impacting 47 U.S. organizations between May 2022 and September 2025. The complaint asserts that victims disbursed at minimum $115 million in ransom funds.

U.S. authorities traced certain ransom payments directed to Scattered Spider to an internet server operated by Jubair. According to the complaint, a digital wallet discovered on that server facilitated purchases of gift cards, one of which was used at a food delivery service to order meals to his residence. An additional gift card procured with cryptocurrency from the identical server allegedly financed online gaming profiles registered under Jubair's identity. When authorities confiscated that server, they also secured $36 million in cryptocurrency.

The complaint additionally charges Jubair in connection with a January 2025 breach of the U.S. courts infrastructure that targeted a U.S. magistrate judge overseeing a separate Scattered Spider prosecution. That investigation concerns Noah Michael Urban, a 20-year-old from Florida charged in November 2024 by Los Angeles prosecutors as one of five alleged Scattered Spider operatives.

Noah “Kingbob” Urban, posting to Twitter/X around the time of his sentencing on Aug. 20.

Urban entered a guilty plea in April 2025 to wire fraud and conspiracy allegations, and in August received a 10-year federal prison sentence. Following his sentencing, Urban communicated from incarceration that the judge imposed a lengthier term than prosecutors recommended because the judge was angered that Scattered Spider had compromised his email account.

A court document from a February 2025 status conference confirms Urban's account of the hacking incident that transpired while he was in federal custody. The judge informed both counsel that a co-defendant in the California prosecution was attempting to obtain information regarding Urban's involvement in the Florida case, and that the perpetrator accessed the account by impersonating a judge via telephone and requesting a password reset.

Allison Nixon serves as chief research officer at Unit 221B, a New York-based security organization, and stands among the world's foremost authorities on Com-related cybercriminal conduct. Nixon identified the principal obstacle in prosecuting prominent Com cybercriminals: the most significant perpetrators frequently remain under 18 years of age, complicating their prosecution under federal hacking legislation.

In the U.S., prosecutors customarily delay charging underage cybercrime suspects until they reach adulthood. Until that transition occurs, Nixon noted, Com participants frequently feel uninhibited in perpetrating—and frequently publicizing—serious criminal activities.

Here we have a special category of Com offenders that effectively enjoy legal immunity. Most get recruited to Com groups when they are older, but of those that join very young, such as 12 or 13, they seem to be the most dangerous because at that age they have no grounding in reality and so much longevity before they exit their legal immunity.

Allison Nixon

U.K. authorities encounter comparable difficulties when they detain and examine homes of underage Com participants: The juvenile suspects simply rejoin their respective Com networks and resume victimizing and harming individuals immediately upon release.

The U.K. court learned from prosecutors last week that both Scattered Spider defendants underwent detention and/or home searches by regional law enforcement on multiple occasions, yet each returned to the Com within 24 hours of discharge.

What we see is these young Com members become vectors for perpetrators to commit enormously harmful acts and even child abuse. The members of this special category of people who enjoy legal immunity are meeting up with foreign nationals and conducting these sometimes heinous acts at their behest.

Allison Nixon

According to Nixon, numerous such individuals maintain minimal real-world social connections because they dedicate virtually all available time to Com channels, causing their entire sense of belonging, community, and self-esteem to become intertwined with participation in these digital collectives. She suggested that modifying legislation to enable prosecutors to penalize these individuals proportionally to the societal harm they inflict would likely substantially mitigate this phenomenon.

If law enforcement was allowed to keep them in jail, they would quit reoffending.

Allison Nixon

The Times of London reports that Flowers confronts three charges under the Computer Misuse Act: two counts of conspiracy to perpetrate an unauthorized computer act resulting in or creating danger of severe harm to human welfare or national security, and one count of attempting to perpetrate such an act. Potential penalties for these violations range from 14 years to life imprisonment, contingent on the offense's consequences.

Jubair reportedly faces two charges in the U.K.: one of conspiracy to perpetrate an unauthorized computer act creating danger of severe harm to human welfare or national security, and one of noncompliance with a section 49 notice demanding disclosure of protected information encryption keys.

In the United States, Jubair is charged with computer fraud conspiracy, two counts of computer fraud, wire fraud conspiracy, two counts of wire fraud, and money laundering conspiracy. Should he be extradited to the U.S., tried, and convicted on all counts, he could face a maximum sentence of 95 years in prison.

In July 2025, the United Kingdom implemented restrictions preventing hacking victims from transferring ransom payments to cybercriminal organizations without governmental authorization. Organizations designated as critical infrastructure reportedly face absolute prohibition, as does the entire public sector. U.K. hacking victims are now obligated to report incidents to authorities to enhance policymakers' comprehension of Britain's ransomware threat landscape.

Source: Krebs on Security