Texas Hacker Pleaded Guilty to Federal Extortion Charges
The Scattered Spider group member targeted high-net-worth employees through social engineering tactics.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust that your employer provides adequate training to prevent social engineering extortion attempts?
In September 2025, 24-year-old Texas resident Ahmed Hossam Eldin Elbadawy pleaded guilty to federal extortion charges. He was a member of the cybercrime organization Scattered Spider, which conducted high-profile virtual currency thefts between 2021 and 2022.
Why it matters
This case highlights the increasing success of social engineering attacks against employees at high-value firms, which remain a primary vector for financially motivated cybercrime. Prosecutors are now focused on reclaiming assets linked to these persistent threats.
The Scattered Spider group successfully breached 12 companies across the entertainment, telecom, technology, and virtual currency sectors. The criminal operation leveraged social engineering to harvest employee credentials and target individuals holding significant digital asset reserves.
The players
Ahmed Hossam Eldin Elbadawy
A 24-year-old Texas resident and member of the Scattered Spider cybercrime organization.
Scattered Spider
A cybercrime group specialized in using social engineering to breach and extort major companies.
The details
The group utilized social engineering—a process of manipulating individuals into divulging confidential information or granting unauthorized system access—to bypass standard cybersecurity perimeters. By specifically targeting high-net-worth employees with substantial holdings in virtual currency, they gained access to sensitive organizational data and financial systems. This methodology allowed the group to sustain a series of financially motivated attacks across multiple high-value industries.
Timeline
2021-2022: Scattered Spider committed high-profile virtual currency thefts.
September 2025: Ahmed Hossam Eldin Elbadawy entered his guilty plea.
September 2026: Court filings regarding criminal asset forfeiture were made public.
The Tech Race
This case reflects a broader trend of criminal groups using social engineering tactics, similar to the 2023 MGM Resorts cyberattack, to penetrate secure corporate environments. It marks a significant milestone in efforts to dismantle the infrastructure used by sophisticated digital extortion syndicates.
Employees at technology and financial firms should remain vigilant against targeted social engineering attempts, which remain a primary threat to credentials. The recovery of the $17 million in assets serves as a reminder of the significant financial consequences tied to these cybercrime investigations.
The takeaway
The successful prosecution of Elbadawy underscores the legal system's focus on recovering stolen digital assets. Readers should monitor future court disclosures in September 2026 for updates on the final forfeiture of the seized $17 million.
Further reading
For more on evolving threats, read the latest coverage on Cybersecurity.
Live Poll
Do you trust that your employer provides adequate training to prevent social engineering extortion attempts?









