The Boy Who Topped the Leaderboard: How 'Tylerb' Became a Cooperating Witness
Tyler Buchanan, the Scottish core of Scattered Spider's 2022 phishing spree, pleaded guilty in U.S. federal court. His path there ran through a blowtorch, a Barcelona departure gate, and a Telegram scoreboard.

The blowtorch was the part that stuck with people.
In February 2023, a rival crew kicked in the door of a quiet house in Dundee, Scotland, beat the mother of a 22-year-old hacker, and threatened to set her son on fire unless he handed over the keys to his cryptocurrency wallet. He fled the U.K. within days. Sixteen months later, Spanish police arrested him at a Barcelona departure gate as he tried to board a flight to Italy.
That hacker, Tyler Robert Buchanan, now 24, pleaded guilty this month in a U.S. federal court to wire fraud conspiracy and aggravated identity theft, admitting his role as a senior operator inside Scattered Spider. The Justice Department said Buchanan personally took at least $8 million in cryptocurrency from individual victims, and helped run the SMS phishing campaign that punched holes in Twilio, LastPass, DoorDash, and Mailchimp in the summer of 2022.
His handle was Tylerb. On one long-running SIM-swapping leaderboard pinned in a Telegram channel — a kind of dark mirror of a gamer ranking board — he sat at number 65 out of 100. Noah Michael Urban, the Palm Coast, Florida co-conspirator who went by Sosa and was sentenced last year to ten years and $13 million in restitution, ranked 24th.
The FBI's case against Buchanan reads like a tutorial in operational hygiene failures. The same username and email address that registered dozens of phishing domains used in the 2022 campaign were tied back to a NameCheap account. Less than a month before the spree began, that account logged in from a U.K. residential IP. Scottish police told American investigators the address was leased to Buchanan for the whole of 2022. When officers searched the Dundee house in 2023, they found a device holding SMS phishing victim data and seed phrases lifted from drained wallets.
The phishing lures themselves were the cheapest part. A text purporting to be from corporate IT. A spoofed Okta page. A help-desk call placed in a soft English accent, convincing enough to talk an overworked support agent into resetting MFA. From there, the group pivoted into customer databases at the breached companies and used the leaked phone numbers to run SIM swaps against high-value crypto holders.
Buchanan is the second Scattered Spider member to fold. Three alleged co-conspirators in Texas, Dallas, and Jacksonville still face charges. Two more — Owen Flowers, 18, and Thalha Jubair, 20 — are due to stand trial in the U.K. in June on charges tied to the Marks & Spencer ransomware attack, intrusions at the London transit system, and breaches of U.S. healthcare providers. Both pleaded not guilty.
Buchanan's sentencing is scheduled for August 21, 2026. The statutory maximum is 22 years. Federal sentencing math being what it is, the actual number will depend heavily on one variable the filings carefully do not address: how much of The Com he is willing to name.



