Tyler Buchanan Sentencing: Inside the $8 Million Phishing and SIM-Swap Operation

Tyler Buchanan Sentencing: Inside the $8 Million Phishing and SIM-Swap Operation
Haseeb Awan
calender icon
August 18, 2026
Tyler Buchanan Sentencing: Inside the $8 Million SIM-Swap Operation, title graphic with a photo of Buchanan being escorted by Spanish police at his arrest.

Introduction

24-year-old Tyler Robert Buchanan of Dundee, Scotland, is scheduled to be sentenced on August 21, 2026, in federal court in California after pleading guilty to conspiracy to commit wire fraud and aggravated identity theft. He faces a statutory maximum of 22 years in prison but after reviewing the public record, I think the more important story is how the underlying operation worked.

Buchanan admitted participating in a conspiracy that began with phishing employees at companies, moved through stolen corporate credentials, and reached individual cryptocurrency holders through SIM swapping taking control of phone numbers, bypassing authentication, and stealing digital assets. According to the U.S. Department of Justice, the conspiracy stole at least $8 million in virtual currency from victims across the United States.

For executives, cryptocurrency investors and other high-value targets, the case shows how an account takeover can begin far from the eventual victim: an employee becomes the entry point, stolen data helps identify wealthy targets, and a weak mobile account becomes the bridge into email, exchange or financial accounts.

Efani reviewed the Justice Department's description of Buchanan's guilty plea, the original FBI criminal complaint and related prosecution records separating what Buchanan admitted from what investigators alleged and what researchers have attributed to the wider Scattered Spider ecosystem. That distinction matters: Buchanan's case is already significant without stretching the evidence.

Is your cellphone vulnerable to SIM Swap? Get a FREE scan now!

Scan Now

Please ensure your number is in the correct format.
Valid for US numbers only!

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

SIM Swap Protection

Get our SAFE plan for guaranteed SIM swap protection.

Protect Your Phone Now

Tyler Buchanan Case Timeline

For readers who want the case in chronological form, these are the key milestones:

  • September 2021 to April 2023: Buchanan admitted participating in a conspiracy involving corporate phishing, unauthorized access, stolen personal information, SIM swapping and cryptocurrency theft.
  • Summer 2022: A large SMS phishing campaign targeted employees at technology, communications and other companies. Researchers associated the broader activity with the campaign known as 0ktapus and later with the Scattered Spider ecosystem.
  • October 2022 to February 2023: The FBI later alleged that approximately 391 BTC moved through a cryptocurrency address investigators linked to Buchanan. That figure is separate from the $8 million in cryptocurrency theft Buchanan ultimately admitted.
  • April 2023: Police Scotland searched Buchanan's residence and seized digital devices. Investigators later said one device contained victim information, cryptocurrency seed phrases and account credentials.
  • May 31, 2024: Spanish police arrested Buchanan at Palma de Mallorca airport as he was preparing to travel to Naples, Italy.
  • April 2025: Buchanan was extradited from Spain to the United States and entered federal custody.
  • April 17, 2026: Buchanan pleaded guilty in the Central District of California to conspiracy to commit wire fraud and aggravated identity theft.
  • August 21, 2026: Buchanan is scheduled to be sentenced by U.S. District Judge John W. Holcomb.
Timeline graphic showing key dates in the Tyler Buchanan case, from the September 2021 to April 2023 conspiracy period through the scheduled August 21, 2026 sentencing.

The chronology is worth keeping in mind because Buchanan's admitted conduct covers the period from 2021 through April 2023. Later attacks attributed in public reporting to Scattered Spider should not automatically be added to his personal record.

What Buchanan Actually Admitted

Buchanan's guilty plea covers conduct from approximately September 2021 through April 2023.

According to the Justice Department, the conspiracy targeted employees and at least a dozen companies operating in sectors including telecommunications, technology, interactive entertainment, IT and business-process outsourcing, cloud communications and cryptocurrency.

The initial access technique was often SMS phishing.

Employees received text messages that appeared to come from their employer or from an IT-related service provider. Some warned that an account was about to be deactivated and directed the recipient to a fraudulent website designed to resemble a legitimate corporate login page.

Employees who entered their credentials supplied the attackers with valid usernames and passwords. In some instances, victims also completed authentication requests delivered to their devices. The attackers therefore did not always need to exploit a vulnerability in corporate software. They could persuade a legitimate employee to complete the authentication process for them.

The FBI complaint describes phishing domains designed to imitate Okta login pages and infrastructure used to collect employee credentials. Investigators also identified evidence they said connected Buchanan with the administration and use of that infrastructure.

According to the complaint, phishing domains were registered through an account that had been accessed from a British IP address associated with Buchanan. Browser history recovered from one of his devices also showed access to management systems connected with phishing infrastructure.

Investigators additionally found a phishing kit on one of Buchanan's devices. The software was designed to capture information entered into fraudulent login pages and transmit the stolen data through Telegram.

The Justice Department's account of Buchanan's guilty plea later said stolen credentials were forwarded into a Telegram channel administered by Buchanan and another conspirator.

Taken together, those details describe a role that went beyond simply receiving credentials stolen by somebody else. The public record connects Buchanan with infrastructure used to collect and distribute compromised authentication data.

The Corporate Breach Was Only the Beginning

One of the most revealing parts of Buchanan's case is what happened after a company was compromised.

Prosecutors say the conspirators obtained confidential company information, credentials and personal information including names, email addresses and telephone numbers. Information gathered through company intrusions could then be combined with leaked datasets and other sources to identify individuals worth targeting directly.

In my view, this is one of the most important lessons in the entire case.

Corporate data breaches are often measured by the number of records exposed or the immediate cost to the company. That framing can miss what happens later. For a determined attacker, stolen corporate data can become intelligence for identifying and profiling specific people.

A phone number by itself may not reveal much. The same is true of an email address or an employer name. When those details are combined with breached databases, public records, social media, cryptocurrency communities and other information, the picture becomes more useful to an attacker.

That information can help answer questions such as: Who appears to control substantial assets? Which exchange might that person use? Which phone number protects the account? Which email address handles recovery? What details could make a fraudulent support request appear convincing?

The Buchanan prosecution is particularly valuable because the government connects corporate information gathering with later attacks against cryptocurrency holders. The eventual financial victim did not necessarily need to fall for the original phishing message. Someone else could provide the first opening.

For high-value individuals, this is where privacy becomes part of security. Information gathered elsewhere can eventually be turned against you.

SIM Swapping Became a Route Into Financial Accounts

Buchanan admitted that members of the conspiracy used SIM swapping to gain unauthorized control over victims' telephone numbers.

In a successful SIM swap, a carrier associates the victim's number with a SIM or device controlled by the attacker. Calls and text messages can then be redirected, potentially including one-time authentication codes and account-recovery messages.

For a cryptocurrency holder, the consequences can extend well beyond the temporary loss of mobile service.

If an exchange, email provider or financial platform trusts the phone number as evidence of identity, control of that number may help an attacker reset passwords, intercept authentication codes or complete an account-recovery process.

The FBI complaint also describes Telegram conversations concerning the division of proceeds from SIM swapping and communications containing information about potential cryptocurrency victims. Investigators believed SIM swapping and social engineering were among the methods used to gain access to victims' cryptocurrency accounts.

What stood out to me is that the phone number was not necessarily the first target. It became valuable after the attackers had already gathered enough information to know whose number was worth taking and what that number might unlock.

That is a more accurate way to understand the risk.

SMS-based authentication can be weak against a targeted adversary, but the deeper issue is the amount of authority that outside services assign to a telephone number. If a compromised number can reset an email account, restore an exchange login and approve other recovery processes, one successful carrier-side attack can affect several independent systems.

For high-value users, a telephone number should not function as a master key to financial identity.

Investigators Found Victim Data and Cryptocurrency Seed Phrases

The evidence recovered from Buchanan's devices created another connection between the corporate phishing operation and individual cryptocurrency victims.

Police Scotland searched Buchanan's residence in April 2023 and seized approximately 20 digital devices, according to the FBI complaint. The Justice Department says one device contained names and addresses belonging to individual victims.

Investigators also found a text file containing cryptocurrency seed phrases and login information relating to one victim's account.

The FBI complaint describes additional cryptocurrency evidence. In one instance, investigators said they recovered a seed phrase from one of Buchanan's devices, reconstructed the associated wallet and identified a transaction involving more than nine bitcoin that the FBI alleged had been transferred without the victim's authorization.

Other evidence described by investigators included Telegram communications, browser history, phishing infrastructure, information associated with victim companies and cryptocurrency wallet records.

There is still an important evidentiary distinction here.

The FBI complaint contains investigative allegations presented during an earlier stage of the prosecution. Buchanan's guilty plea provides a firmer basis for describing the core conspiracy because he admitted participating in it. We should therefore avoid treating every individual allegation in the complaint as though Buchanan separately admitted each one.

That discipline becomes particularly important when looking at the amount of cryptocurrency associated with the case.

The $8 Million and $27 Million Figures Measure Different Things

Two financial figures appear repeatedly in coverage of Buchanan.

The strongest is at least $8 million.

According to the Justice Department, Buchanan admitted that the conspiracy stole at least that amount in virtual currency from victims across the United States.

The larger figure comes from the investigation.

The FBI described a cryptocurrency address it believed was linked to Buchanan and said approximately 391 BTC moved through that address between October 2022 and February 2023. Spanish police separately said around the time of his arrest that Buchanan controlled bitcoin worth more than $27 million.

Those figures should not be collapsed into a claim that Buchanan personally stole $27 million.

A cryptocurrency address processing 391 BTC does not automatically tell us how much was stolen from victims, how much belonged to one conspirator, how much passed through on behalf of others or how much Buchanan personally retained.

From my perspective, this distinction is particularly important because cryptocurrency numbers can become misleading very quickly once they are converted into headline dollar values.

The public evidence supports a narrower conclusion: Buchanan admitted participating in a conspiracy responsible for at least $8 million in cryptocurrency theft. Investigators separately alleged connections between him and cryptocurrency activity worth substantially more.

Both claims can be true while measuring different things.

SIM Swap Protection

Get our SAFE plan for guaranteed SIM swap protection.

Protect Your Phone Now

How Strong Is the Scattered Spider Connection?

Buchanan is widely described by cybersecurity researchers and media reports as a significant member of Scattered Spider, a loosely organized cybercriminal ecosystem tracked under several names by different security companies.

Reporting has connected Buchanan with the alias "Tylerb," and researchers who followed the group have described him as an important participant.

That attribution is relevant, but the legal distinction remains important.

Buchanan was not convicted of an offense called membership in Scattered Spider. His guilty plea concerns conspiracy to commit wire fraud and aggravated identity theft.

The difference matters because Scattered Spider is not comparable to a conventional company with a fixed organizational chart and documented membership list. Researchers have described a fluid network of mostly young, English-speaking cybercriminals who collaborate through online communities, move between campaigns and sometimes operate under several overlapping labels.

Calling Buchanan a Scattered Spider figure is therefore reasonable when properly attributed to researchers and reporting. Using the group name to assign every attack associated with that ecosystem to Buchanan personally is not.

The Case Does Not Establish That Buchanan Hacked MGM or Caesars

Scattered Spider became internationally known after the 2023 attacks against MGM Resorts and Caesars Entertainment.

Those incidents frequently appear in articles discussing Buchanan, but his guilty plea does not establish that he personally participated in them.

The conspiracy Buchanan admitted ran through April 2023. The MGM and Caesars attacks happened months later.

KrebsOnSecurity has also reported that the federal complaint against Buchanan did not connect him to the MGM intrusion and that his involvement in that operation remained unclear.

That is enough reason to keep the cases separate unless stronger evidence appears.

The same principle should apply to later incidents associated with Scattered Spider or related criminal communities. Threat-group names can survive even as the people operating around them change. New participants can join, arrested participants can disappear, and researchers may use broader clustering labels than prosecutors use when charging particular defendants.

There is no analytical benefit in inflating Buchanan's record with attacks the court case does not establish. His admitted conduct already provides more than enough material to understand the threat.

Monthly

$99.00
Per Month
Unlimited talk, text, and data across North America.
Global High-Speed Data
Unlimited texting to 200+ countries
Hotspot & Wi-Fi calling
No Contract
SIM Security backed $5M Insurance Coverage
60-Days 100% Money Back Guarantee
No Activation or Shipping Fee.

Yearly

$999.00
Per Year
Unlimited talk, text, and data across North America.
Global High-Speed Data
Unlimited texting to 200+ countries
Hotspot & Wi-Fi calling
No Contract
SIM Security backed $5M Insurance Coverage
60-Days 100% Money Back Guarantee
No Activation or Shipping Fee.

Why "Up to 22 Years" Is Not a Sentencing Prediction

Buchanan faces a statutory maximum sentence of 22 years.

That does not mean prosecutors are necessarily asking U.S. District Judge John W. Holcomb to impose 22 years, and it does not mean the maximum is the most likely outcome.

Buchanan pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. The aggravated identity-theft offense carries a mandatory consecutive prison component under federal law, while the fraud conspiracy carries its own potential punishment.

Federal sentencing can also be affected by the U.S. Sentencing Guidelines and factors including the financial loss attributed to the defendant, his role in the offense, relevant conduct, criminal history, acceptance of responsibility and other considerations the court is permitted to evaluate.

Without the final sentencing materials and the judge's findings, assigning Buchanan a precise likely sentence would be speculation.

The careful formulation is therefore simple: Buchanan faces up to 22 years in federal prison, but 22 years is the statutory maximum, not a known prosecution recommendation.

Noah Urban's 10-Year Sentence Provides Context

Buchanan is not the first person connected to this conspiracy to reach federal sentencing.

Noah Michael Urban, identified by the Justice Department as one of Buchanan's co-conspirators, was sentenced in August 2025 to 10 years in federal prison.

Urban was also ordered to pay $13 million in restitution and forfeit approximately $4.8 million in assets. According to the Justice Department, he participated in cryptocurrency theft involving dozens of victims and in related conduct involving phishing and identity theft.

Urban's sentence provides useful context because it shows that substantial prison terms are already being imposed for criminal activity connected with this broader operation.

It does not give us a formula for Buchanan's sentence.

The defendants have different personal circumstances, records and factual findings. They are also being sentenced through different proceedings before different judges. Federal sentencing remains individualized.

Urban's outcome is useful mainly as a guardrail against two extremes. Buchanan's 22-year statutory maximum should not be treated as an expected sentence, but the possibility of a lengthy prison term is not merely theoretical either.

The Real Security Story Is the Sequence of Compromises

Cyber incidents are often categorized according to whichever failure becomes visible at the end.

If cryptocurrency disappears after a phone-number takeover, the event is called a SIM-swap attack. If an employee entered credentials into a fake website, it becomes phishing. If confidential information was stolen from a company, it becomes a data breach.

Buchanan's case shows how incomplete those categories can be when the attacks are examined separately.

The operation described by prosecutors moved through several security layers:

  1. Employees received phishing messages.
  2. Attackers obtained legitimate corporate credentials.
  3. Those credentials opened access to company systems and information.
  4. Stolen information helped identify and profile individual targets.
  5. Attackers used social engineering and SIM swapping against those individuals.
  6. Control of the telephone number weakened authentication and recovery mechanisms.
  7. Cryptocurrency accounts and assets became accessible.
Diagram showing how the Tyler Buchanan attack chain worked, from phishing SMS and stolen employee credentials through corporate access, victim targeting, SIM swap takeover, weakened authentication, and cryptocurrency theft.

No single security product addresses that entire sequence.

Strong enterprise authentication cannot automatically protect a customer's mobile number. Carrier security cannot prevent an employee from submitting credentials to a convincing phishing site. A hardware wallet protects assets held in that wallet, but it does not automatically secure funds stored on an exchange account recoverable through email or SMS.

My view is that this is the most useful way to read Buchanan's case. The attackers did not rely on one extraordinary weakness. They connected several ordinary weaknesses that belonged to different organizations.

That is exactly why high-value security has to be designed as a stack.

What High-Value Targets Should Take From the Case

The practical response is to reduce the number of situations in which compromising one identity component can unlock several others.

Where important accounts support phishing-resistant authentication, hardware security keys and properly implemented passkeys can reduce reliance on SMS. Email accounts used for financial recovery deserve especially strong protection because control of email can become a bridge into unrelated systems.

The mobile account requires its own controls.

An attacker who already knows a person's name, phone number, email address and other identifying information should still encounter meaningful resistance before that number can be transferred or reassigned. Strong port-out protections, restricted account changes and careful human verification can make the carrier layer harder to exploit.

This is the specific part of the attack chain where Efani operates.

It would be inaccurate to suggest that secure mobile service could have prevented the corporate phishing campaign described in Buchanan's case. That belongs to a different security layer. Carrier security also cannot replace strong cryptocurrency custody.

What it can do is make the phone-number takeover stage harder, especially when an attacker has already accumulated enough information to attempt social engineering against a carrier.

Cryptocurrency holders with substantial assets should apply the same principle to custody. If compromising one device, one email account, one telephone number or one recovery phrase can authorize a catastrophic transfer, too much authority may be concentrated in one place.

Large holdings can justify structural protections such as separating authorization across independent credentials, devices or people. Those controls do more than make an account slightly harder to access. They change what an attacker must compromise before money can move.

Privacy belongs in the same conversation.

Public information about holdings, employment, telephone numbers, addresses, travel and family relationships can help criminals decide who is worth targeting and which social-engineering approach is most likely to succeed. Buchanan's case demonstrates how identity data can become useful long before the final account takeover begins.

The Investigation Also Shows How Cybercriminals Get Identified

Scattered Spider has been associated with attacks against extremely large organizations, but much of the evidence described against Buchanan involves conventional attribution mechanisms.

Investigators connected phishing infrastructure with domain-registration records, accounts and IP activity. Browser history allegedly linked Buchanan's devices with phishing domains. A phishing kit recovered from one device matched software located on servers used in the campaign.

Telegram records connected harvested credentials with the operation. Cryptocurrency transactions could be traced on public blockchains. Police searches produced victim information, account data and other digital evidence.

No individual artifact necessarily explains the entire investigation.

Together, however, those records can create a chain of attribution that becomes increasingly difficult to explain away.

Collaborative cybercrime creates its own operational-security problem. Participants may need to protect their identities across devices, hosting providers, domain registrars, messaging platforms, cryptocurrency wallets and multiple co-conspirators for years.

Investigators need only enough durable links to begin joining those systems together.

What to Watch at the August 21 Sentencing

The sentencing hearing should answer the most obvious outstanding question: how much prison time Judge Holcomb believes Buchanan's admitted conduct warrants.

Other findings could ultimately be just as important.

The proceeding may clarify the financial loss formally attributed to Buchanan, restitution, forfeiture, the court's assessment of his role in the conspiracy and any aggravating or mitigating arguments raised by prosecutors and the defense.

Those findings may also help explain how the $8 million admitted loss relates to the much larger cryptocurrency activity described earlier in the investigation.

Whatever sentence Buchanan receives, the broader security lesson is already visible.

The conspiracy succeeded by moving across boundaries that defenders often treat separately: employee security, corporate access, personal information, telecommunications, authentication and financial custody.

Each system placed trust in another system. The company trusted an authenticated employee. A financial platform could trust an email account. An account-recovery flow could trust an SMS code. A carrier could trust information presented during an account change.

Attackers look for the weakest trust decision connecting those systems.

For defenders, the goal should be the opposite. A single phone number, email account, employee credential, device or recovery mechanism should not carry enough authority to compromise everything else.

What stood out to me most after reviewing Buchanan's case is how little of the operation depended on one spectacular technical breakthrough. According to the federal record, the conspiracy produced millions of dollars in theft by connecting smaller compromises that became far more powerful when used together.

The sentence imposed on August 21 will determine Buchanan's punishment.

The attack model exposed by the case will remain relevant long after that number disappears from the headlines.

I founded Efani after being Sim Swapped 4 times. I am an experienced CEO with a demonstrated history of working in the crypto and cybersecurity industry. I provide Secure Mobile Service for influential people to protect them against SIM Swaps, eavesdropping, location tracking, and other mobile security threats. I've been covered in New York Times, The Wall Street Journal, Mashable, Hulu, Nasdaq, Netflix, Techcrunch, Coindesk, etc. Contact me at 855-55-EFANI or [email protected] for a confidential assessment to see if we're the right fit!

Related Articles

SIM SWAP Protection

Get our SAFE plan for guaranteed SIM swap protection.