DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Scattered Spider Hacking Gang Arrests Mount With Teen

Posted on December 5, 2024December 5, 2024 by Dissent
Bloomberg Law reports that an accused teenage hacker who was arrested last month in California is suspected of being a member of Scattered Spider, according to several people familiar with the matter.

Remington Goy Ogletree (“remi”) was arrested in California on November 4 on a warrant from New Jersey. He was released on an unsecured bond of $50,000 with conditions (see below).

The complaint, filed in federal court in New Jersey (Case 2:24-mj-12280-JBC-1) charges Ogletree with wire fraud and aggravated identity theft for crimes allegedly committed between October 2023 and May 2024:

The investigation into the Cyber Threat Group has revealed that from at least October 2023 through at least May 2024, OGLETREE perpetuated a scheme to defraud in which he called and sent phishing messages to U.S.- and foreign-based company employees to gain unauthorized access to the companies’ computer networks. Once OGLETREE had access to the victim companies’ networks, OGLETREE accessed and stole confidential data, including data that was later posted for sale on the dark web, and, at times, used the companies’ services to facilitate the theft of cryptocurrency from unwitting victims. As a result of OGLETREE’s scheme, victims have suffered over $4 million in losses.

The complaint identifies three victims: one is a financial institution (a U.S. national bank) and the other two are telecoms (one is U.S., the other is EU).

Ogletree’s operational security was not impressive.  As one example:

According to Apple records, the OGLETREE iCloud Account was subscribed to by “Steven Durango” at a Key Largo, Florida address (the “Key Largo Address”) and phone number ending in 7923 (the “7923 Phone Number”). As described in more detail below, the Key Largo Address was an Airbnb where OGLETREE and his father stayed in late 2023. A public record check revealed that no person by the name of Steven Durango lives in Key Largo, Florida. Further, the 7923 Phone Number is registered to OGLETREE’s father, and OGLETREE later admitted in an interview with the FBI that it was his own number. Evidence within the OGLETREE iCloud Account, including photos of OGLETREE and emails to OGLETREE, further shows that the account was used by OGLETREE during the relevant period. Finally, OGLETREE is listed as a billing· contact for the OGLETREE iCloud Account.

The FBI reportedly raided Ogletree’s Texas residence on February 23, 2024 and seized his iPhone. The complaint notes:

On February 23, 2024, the FBI conducted a search of OGLETREE’s residence in Fort Worth, Texas (“the Fort Worth Residence”) pursuant to a court­ authorized search vrnrrant. As explained above, during the search, the FBI seized the OGLETREE A search of the OGLETREE iPhone -in addition to the evidence described above – further revealed photos of OGLETREE as well as evidence of criminal conduct, including: (a) a screenshot of a phishing text impersonating a technology company; and (b) a screenshot of a credential harvesting phishing page impersonating a personal information manager software system. The OGLETREE iPhone also contained screenshots of cryptocurrency accounts showing tens of thousands of dollars in cryptocurrency.

Two days later:

Two days after the FBI searched OGLETREE’s residence, a Telegram user (“User-1”) later identified as OGLETREE contacted the provider of a cash for cryptocurrency money laundering service (the “Cash Service”). On February 25, 2024, OGLETREE stated, “I need $50k cash.” OGLETREE then increased his request to “$75k” and asked that the cash be sent in OGLETREE’s father’s name to the Fort Worth Residence. At the time, OGLETREE was apparently unaware that the Cash Service was part of an undercover FBI operation.

Ogletree seems to have helped the FBI tie him to Scattered Spider in his interview with them while they were executing the search and seizure:

During this interview, OGLETREE demonstrated a knowledge of cybercrime and cybercrime techniques. OGLETREE told the FBI, “I talk to a large variety of people on [the] internet … I know people who commit all sorts of crimes.” OGLETREE then specifically provided information on the hacking group known as “Scattered Spider.” OGLETREE explained, “I know key Scattered Spider members.” OGLETREE further explained, “any company getting ransom … that’s not crypto-related, it’s gonna be them … they target BPOs … because outsourcing companies they have less security.” He further explained that Scattered Spider has hacked at least five of the top “BPO” companies.

Read the full complaint.

Read the conditions of his release, below:

ogletree_nj_conditionsofrelease

No related posts.

Category: HackOf Note

Post navigation

← Germany arrests suspected admin of country’s largest criminal marketplace
Deloitte Hacked – Brain Cipher Ransomware Group Allegedly Stole 1 TB of Data (1-DISPUTED) →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Integrated Oncology Network victim of phishing attack; multiple locations affected
  • HHS’ Office for Civil Rights Settles HIPAA Privacy and Security Rule Investigation with Deer Oaks Behavioral Health for $225k and a Corrective Action Plan
  • HB1127 Explained: North Dakota’s New InfoSec Requirements for Financial Corporations
  • Credit reports among personal data of 190,000 breached, put for sale on Dark Web; IT vendor fined
  • Five youths arrested on suspicion of phishing
  • Russia Jailed Hacker Who Worked for Ukrainian Intelligence to Launch Cyberattacks on Critical Infrastructure
  • Kentfield Hospital victim of cyberattack by World Leaks, patient data involved
  • India’s Max Financial says hacker accessed customer data from its insurance unit
  • Brazil’s central bank service provider hacked, $140M stolen
  • Iranian and Pro-Regime Cyberattacks Against Americans (2011-Present)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • On July 7, Gemini AI will access your WhatsApp and more. Learn how to disable it on Android.
  • German court awards Facebook user €5,000 for data protection violations
  • Record-Breaking $1.55M CCPA Settlement Against Health Information Website Publisher
  • Ninth Circuit Reviews Website Tracking Class Actions and the Reach of California’s Privacy Law
  • US healthcare offshoring: Navigating patient data privacy laws and regulations
  • Data breach reveals Catwatchful ‘stalkerware’ is spying on thousands of phones
  • Google Trackers: What You Can Actually Escape And What You Can’t

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.