PC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchNoah Michael Urban, a Florida man prosecutors linked to Scattered Spider, pleaded guilty to federal cybercrime charges in April 2025 and was sentenced four months later to 10 years in prison. The court also ordered him to pay $13 million in restitution and forfeit approximately $4.8 million in assets, according to the U.S. Department of Justice.
Who is Noah Urban?
Urban, a Palm Coast, Florida, resident, was 20 when he was sentenced. Prosecutors and news coverage have associated him with the loosely organized cybercriminal collective known as Scattered Spider. His reported online aliases included “King Bob,” “Sosa,” “Elijah” and “Gustavo Fring.” The public record described in the sentencing announcement establishes his responsibility for the offenses to which he pleaded guilty; it does not make him the adjudicated leader of the broader group.
Urban pleaded guilty on April 4, 2025. In the Florida case, he admitted to conspiracy to commit wire fraud, wire fraud and aggravated identity theft. He also pleaded guilty in a separate California federal matter to a fraud-related conspiracy count, as reported by The Record. Those were proceedings in different jurisdictions, not a single set of charges.
What conduct did the case involve?
The Justice Department said the criminal activity ran from about August 2022 through March 2023 and involved cryptocurrency theft from at least 59 victims, with losses exceeding $13 million. Prosecutors described a mix of identity theft, SIM swapping, phishing and account compromise.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
How SIM swapping and phishing fit together
In a SIM swap, an attacker gets a victim’s phone number transferred to a device under the attacker’s control. If an account relies on text messages for password resets or one-time codes, control of that number can help an attacker take over the account. It does not mean every form of multifactor authentication is defeated: the exposure is particularly relevant to SMS-based codes and account-recovery processes that depend on the phone number.
In the corporate part of the scheme, prosecutors said conspirators sent phishing texts while impersonating colleagues or suppliers, sought employee credentials, and used access to company systems to steal confidential information, intellectual property and personal data. Information obtained from compromised systems or leaked datasets could then be reused in attempts to access cryptocurrency accounts. The Justice Department’s 2024 announcement of charges against five defendants describes the alleged phishing scheme.
What sentence and financial orders did Urban receive?
On August 21, 2025, a federal court in Florida sentenced Urban to 120 months—10 years—in prison, followed by three years of supervised release. The court ordered $13 million in restitution and approximately $4.8 million in forfeiture. Restitution is intended to compensate victims; forfeiture is the surrender of property or proceeds to the government. These final sentencing figures are distinct from earlier reported estimates and seizure figures.
Investigators found approximately $4.8 million in cryptocurrency and other assets linked to victims on Urban’s devices, according to the Justice Department. That amount is the basis for the reported forfeiture order; it should not be confused with the larger restitution obligation or total losses.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteRank #3
What evidence did prosecutors describe?
The government said an FBI search of Urban’s residence found evidence connecting his computer to victims’ email accounts and cryptocurrency wallets. Prosecutors also cited browser history showing access to victim accounts and cryptocurrency on his devices that they linked to stolen funds. The guilty plea and sentence resolve Urban’s liability for his pleaded offenses; these details describe the evidence the government presented, rather than a basis for attributing every Scattered Spider incident to him.
How does the case fit into Scattered Spider prosecutions?
Scattered Spider is commonly described as a loose collective, not a conventional organization with a clearly established hierarchy. Public reporting and authorities have associated the group with social engineering, SMS and voice phishing, SIM swapping, credential theft and cloud-account compromise. Those group-level descriptions should be kept separate from Urban’s specific convictions: other attacks attributed publicly to Scattered Spider were not thereby proven against him.
Rank #4
A November 2024 federal announcement named five defendants in connection with the phishing and cryptocurrency-theft scheme:
- Ahmed Hossam Eldin Elbadawy
- Noah Michael Urban
- Evans Onyeaka Osiebo
- Joel Martin Evans
- Tyler Robert Buchanan
The Justice Department reported on April 17, 2026, that Buchanan had pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. At that time, the other three defendants charged alongside him in the California case still faced charges. Buchanan’s plea is a separate development, not part of Urban’s April 2025 plea. The same Justice Department update said Urban was serving his 10-year sentence.
Best Value
What the case means for cryptocurrency users and organizations
The methods described in the case show why account security is not only about choosing a strong password. A stolen identity or employee credential can become an entry point to financial accounts or business systems, while weak recovery procedures can undermine otherwise sound protections.
- For cryptocurrency and other high-value accounts, avoid relying on SMS alone for authentication or recovery where stronger options are available.
- Organizations can reduce exposure by using phishing-resistant authentication for privileged accounts and by applying careful identity verification to help-desk requests and account changes.
- Monitor for unusual login activity, password resets and phone-number or SIM changes, and limit employee access to the systems and data needed for their roles.
- Protecting credentials and checking for reuse matters because information stolen in one compromise may be used in later attempts against other accounts.
These are defensive lessons drawn from the documented attack methods, not a claim that any single safeguard would have prevented every incident in the case.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




