Fortune | FORTUNE 09月20日
黑客组织“Scattered Spider”成员被控电脑欺诈与共谋
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

一名19岁的嫌疑人Thalha Jubair被指控为名为“Scattered Spider”的黑客组织成员,涉嫌自2022年5月至2025年9月期间,通过欺骗公司帮助台重置用户密码、运行密码破解软件等方式,入侵至少47家美国公司及美国联邦法院系统。该组织被指控加密或窃取数据,并勒索巨额赎金。部分金融服务公司支付了高达2500万美元和3620万美元的比特币。Jubair还在今年1月试图入侵美国法院网络,并窃取了包括法院雇员信息在内的18兆字节数据。此次逮捕是美国与英国执法部门合作的成果,凸显了网络犯罪对商业和关键基础设施的威胁。

🛡️ **黑客组织“Scattered Spider”的活动与指控**:文章详细描述了19岁的Thalha Jubair被指控是名为“Scattered Spider”的恶意黑客组织成员,该组织涉嫌在2022年5月至2025年9月期间进行大规模网络犯罪活动。Jubair被指控使用多个假名,并可能在15-16岁时就开始参与该组织活动。该组织据称攻击了包括航空公司、制造商、零售商、科技公司、金融服务公司以及美国联邦法院系统在内的至少47家美国公司。

🔑 **网络入侵与勒索手段**:据称,Jubair及其同伙采用多方面策略进行网络入侵。他们会联系公司帮助台,诱骗客服人员重置其他用户的密码,并运行密码破解软件。一旦成功进入公司网络,他们会加密或窃取数据,并威胁删除或公开这些信息,除非收到赎金。其中,金融服务公司据称支付了高达2500万美元和3620万美元的比特币。

⚖️ **对美国法院系统的攻击**:文章特别指出,Jubair在2025年1月8日试图入侵美国法院网络,欺骗客服人员重置了另一名员工的密码,并利用该账户访问了联邦治安法官的账户。他们随后在法官的邮件中搜索了与案件相关的关键词,并窃取了包括法院雇员姓名、职位、工作地点、用户名和手机号码在内的18兆字节数据。

🤝 **国际合作与逮捕行动**:此次对Jubair的逮捕是美国司法部、FBI与英国国家犯罪局(NCA)及伦敦警察厅等多国执法机构及合作伙伴协同合作的成果。Jubair和另一名英国青少年Owen Flowers在家中被捕,并已在英国接受审判,两人均被羁押。这次联合行动表明了打击跨国网络犯罪的决心,并强调了追究此类犯罪行为的责任。

📈 **网络犯罪的广泛威胁**:司法部官员表示,此次行动揭示了“Scattered Spider”组织在全球范围内至少发动了120起攻击,勒索金额超过1.15亿美元。这些攻击对美国企业和组织造成了广泛的破坏,包括关键基础设施和联邦法院系统,凸显了网络犯罪分子带来的重大且日益增长的威胁。

A complaint unsealed in New Jersey this week charged Thalha Jubair, 19, with computer and wire fraud, and three counts of conspiracy charges. Authorities claim Jubair was allegedly part of the malicious hacking group known as “Scattered Spider,” from May 2022 to September 2025. Jubair allegedly used aliases including “Austin,” “Brad” and “EarthtoStar” in his role with the group, which could have begun when he was as young as 15 or 16. The complaint lists 47 unnamed companies in the U.S. as victims, including airlines, manufacturers, retailers, five tech companies, three financial services firms, and dozens of others. The U.S. federal court system was also allegedly targeted in the scheme, the complaint states. 

The operation was multi-faceted, according to law enforcement. Jubair and other unnamed conspirators allegedly contacted company help desks and convinced representatives to reset other users’ passwords multiple times in addition to allegedly running password cracking software. Once successfully inside the company networks, the alleged hackers were able to encrypt or steal data and threaten to delete or publish it unless executives agreed to pay ransom. Prosecutors claim portions of payments from the victim companies were traced to a server allegedly controlled by Jubair. The financial services firms allegedly each paid $25 million and $36.2 million in Bitcoin in 2023—the highest payments listed in the complaint. 

On Jan. 8, 2025, Jubair allegedly contacted the U.S. Courts network help desk and tricked a representative into resetting another person’s password, and then used it to take over two other accounts, including one belonging to a federal magistrate judge. Once Jubair and others allegedly gained access to the judge’s email, they searched the inbox for the terms “subpoena,” “scattered spider,” and the name of another alleged hacker facing charges. A second judge who had presided over a case involving an alleged conspirator in the Scattered Spider scheme was also targeted, the complaint states. Jubair and others allegedly stole 18 megabytes of data including thousands of names of Court employees, job titles, work locations, and usernames, and cellphone numbers. 

Jubair could not be reached for comment. 

“Jubair is alleged to have participated in a sweeping cyber extortion scheme carried out by a group known as Scattered Spider, which committed at least 120 attacks worldwide and resulted in over $115 million in ransom payments from victims,” said acting Assistant Attorney General Matthew R. Galeotti of the Department of Justice. “These malicious attacks caused widespread disruption to U.S. businesses and organizations, including critical infrastructure and the federal court system, highlighting the significant and growing threat posed by brazen cybercriminals.”

The U.K.’s National Crime Agency (NCA) and City of London Police arrested Jubair at his home address in East London this week, according to the NCA. A second teen, Owen Flowers, 18, of West Midlands in the U.K., was also arrested at home, the NCA announced. The two teenagers were separately charged for an August 2024 attack on Transport for London, a government agency that oversees trains, buses, taxis, and the London Underground. 

According to the NCA, Jubair and Flowers appeared in Westminster Magistrates Court this week, where Flowers was separately charged with conspiring to damage SSM Health Care Corporation and Sutter Health, which are U.S. companies. Jubair was charged for failing to disclose pins or passwords for his seized devices. Both were remanded into custody in the UK. SSM and Sutter Health did not immediately respond to a request for comment. 

“The arrest of Thalha Jubair underscores an undeniable truth: no matter how elusive or destructive these cyber-criminal syndicates are, we will continue to pursue those who allegedly extort our businesses and ensure they are held accountable,” said FBI Special Agent in Charge Stefanie Roddy in a statement. “[C]harges in both the U.S. and U.K. reflect extraordinary coordination with our foreign and industry partners and mark a decisive victory against cybercriminal gangs who thought they could cripple American industries, inflict hundreds of millions in losses, and hide behind a screen without consequence. The FBI remains relentless in protecting Americans and American businesses—detecting, deterring and diminishing the impact of cyber-criminal gangs.”

Fortune Global Forum

returns Oct. 26–27, 2025 in Riyadh. CEOs and global leaders will gather for a dynamic, invitation-only event shaping the future of business.

Apply for an invitation.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

Thalha Jubair Scattered Spider 网络犯罪 电脑欺诈 共谋 网络勒索 美国法院系统 国际合作 网络安全 Cybercrime Computer Fraud Conspiracy Cyber Extortion US Court System International Cooperation Cybersecurity
相关文章