Skip to main content
2 Minute Drill

175 Bitcoin, 150 Shoes, and a Muhammad Ali Painting | 2 Minute Drill with Drex DeFord

4:15

hosted by Drex DeFord

Watch

Questions answered in this episode

  1. Could someone talk your help desk into a password reset just by sounding like a doctor in a hurry?
  2. What proof does your team demand before they hand over access?
  3. Do they do that check every single time?

About this episode

Prosecutors filed a forfeiture list for a 24-year-old from College Station, Texas, named Ahmed Hossam Eldin Elbadawy: 175 Bitcoin, 1,300 Ethereum, gold jewelry, luxury watches, designer handbags, 150 pairs of shoes, and a painting of Muhammad Ali. Drex DeFord says Elbadawy was an early member of Scattered Spider, a crew whose best weapon was a phone call. They rang a company's IT desk, sounded like a stressed-out employee locked out of an account, and talked a real person into resetting a password or waving through a multi-factor prompt. Prosecutors say he and his co-conspirators hit at least a dozen companies and 29 victims across entertainment, telecom, cloud, and healthcare, including $6.3 million in crypto one morning in September 2021 and $1.7 million on another hit. He pled guilty about a year ago. The plea stayed fairly quiet until this month, when prosecutors moved to seize the pile. Drex puts that pile at around $17.6 million.

Scattered Spider members pointed the same phone-call playbook at hospitals, including some of the largest health systems, as far back as 2024. Same move: call the help desk, sound like staff, get in. In this Two Minute Drill, Drex asks whether someone could talk your help desk into a password reset just by sounding like a doctor in a hurry, what proof the team demands, and whether they do that check every time.

Remember, Stay a Little Paranoid.

Watch

Transcript

[00:00:01] Drex: Hey everyone, I'm Drex, and this is the Two-Minute Drill, thanks to Fortified Health Security for sponsoring today's podcast. It's great to see you today. Here's some stuff you might want to know about.

[00:00:09] Drex: Let me tell you about a court document. It's not exactly gripping material, I know, but, you know, stay with me. This court document is a forfeiture list, and that's when the government convicts someone and wants to take back what they bought with stolen money. Prosecutors file an itemized inventory, and this one reads like an estate sale for an old MTV Cribs video. 175 Bitcoin, 1300 Ethereum, gold jewelry, luxury watches, designer handbags, and 150 pairs of shoes. And I promise I'm not making this up. A painting of Muhammad Ali.

[00:00:55] Drex: It all belongs to a 24-year-old named Ahmed Elbadawy. He's from College Station, Texas, the face behind one of the most feared hacking crews in the country. It turns out to be a young guy in a college town who got very good at lying on the phone. Ahmed was one of the early members of a group that's become the boogeyman of corporate security. They call themselves Scattered Spider, and the best weapon they had was a phone call. They'd ring up a company's IT desk, and they'd sound like a stressed-out employee, locked out of an account, and talk to a real person, talk that real person into resetting a password or waving through a multi-factor prompt. And that was the whole trick. That was it. Be convincing and be patient.

[00:01:41] Drex: What made them scary was that they were young, English-speaking, and they understood people. They knew help desk workers at 2 a.m., and they knew that those help desk workers wanted to solve your problem and get you off the line. And they knew how to sound like they belonged. And it worked over and over. Prosecutors say Ahmed and his co-conspirators hit at least a dozen companies and ran through 29 victims across entertainment and telecom and cloud and healthcare. One morning in September 2021, they walked off with $6.3 million in crypto, and in another hit, $1.7 million. They got stinking rich.

[00:02:25] Drex: And the part that snuck up on me about this story was that Ahmed pled guilty about a year ago, and it stayed fairly quiet. We only found out about it this month when prosecutors moved to seize that pile of Bitcoin and shoes and other stuff. Around $17.6 million worth of other stuff. Now, if you're a healthcare leader, why should you care about a kid in Texas and his Muhammad Ali painting? Well, because the crew didn't stop at telecom and crypto. Scattered Spider members pointed their same phone call playbook at hospitals, including some of the largest health systems in the country as far back as 2024. Same move, call the help desk, sound like staff, get in.

[00:03:10] Drex: So think about your own front line. And I know you're doing this. Always worth saying again, here's a brand new story, a brand new update. Use this to help reinforce it to your team. Your help desk resets passwords all day for real clinicians who are locked out mid shift with patients waiting and that pressure is real. And these cyber thugs know it. They're counting on your people to be extra helpful. So here's the question for today. Could someone talk your help desk into a password reset right now, just by sounding like a doctor in a hurry? What proof does your team demand before they hand over access? And do they really do that check every single time? Are you sure? And how do you know?

[00:03:53] Drex: That's it for today's two minute drill. Thanks to Fortified Health Security for sponsoring today's show. Drop me a note. Let me know what you're working on. I'm always happy to hear from you. I'm Drex at 229project.com. Thanks for being here. Stay a little paranoid and I'll see you around campus.