Updated Advisory: Mitigating Scattered Spider❗️
International law enforcement and cyber agencies have issued a have issued an urgent Joint Cybersecurity Advisory in response to recent activity by the threat actor and cybercriminal group known as Scattered Spider.
These threat actors have been actively targeting the commercial facilities sector, its subsectors, and other critical industries. The advisory includes tactics, techniques, and procedures (TTPs) identified through FBI investigations as recent as June 2025.
Scattered Spider—also known as Starfraud, UNC3944, Scatter Swine, Oktapus, Octo Tempest, Storm-0875, and Muddled Libra— is still using social engineering techniques like phishing, push bombing & SIM swap attacks to target CriticalInfrastructure organizations & commercial facilities.
Network defenders should implement the mitigations outlined in the advisory to improve your organization’s cybersecurity posture.
These include the following:
Advisory Updates
Note: This advisory was originally published on November 16, 2023, and has undergone multiple updates:
Scattered Spider is known for targeting large organizations and their third-party IT help desks.
Update – July 29, 2025: According to reliable third-party sources, Scattered Spider primarily conducts data theft for extortion purposes and has recently been observed deploying DragonForce ransomware alongside its standard methods. Although some TTPs have remained unchanged, the group frequently evolves its techniques to avoid detection.
Authoring Agencies
The authoring agencies include: the Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), Royal Canadian Mounted Police (RCMP), Australian Signals Directorate’s Australian Cyber Security Centre (ACSC), Australian Federal Police (AFP), Canadian Centre for Cyber Security (CCCS), and the United Kingdom’s National Cyber Security Centre (NCSC-UK)
Call To Immediate Action❗️
The authoring organizations strongly urge commercial facilities and critical infrastructure entities to review and apply the guidance in the Mitigations section of this advisory to minimize the risk and potential impact of Scattered Spider activities.
Download the original November 2023 version of this report HERE
Download the updated July 2025 version HERE
A Closer Look At Scattered Spider
Scattered Spider, also known as UNC3944, is a cybercriminal group primarily composed of teenagers and young adults, believed to reside in the United States and the United Kingdom.
The group rose to prominence following high-profile cyberattacks and extortion attempts targeting major casino operators Caesars Entertainment and MGM Resorts International. Beyond these, they have also reportedly targeted companies such as Visa, PNC Financial, Transamerica, New York Life, Synchrony Financial, Truist Bank, Twilio, and, more recently, Snowflake customers.
Scattered Spider typically relies on sophisticated social engineering tactics and deception to gain initial access to an organization. Common entry points include SMS-based phishing (smishing) and voice phishing (vishing). The group is also known to contact external-facing help desks, impersonating legitimate users in an effort to reset passwords or bypass multi-factor authentication (MFA), thereby gaining unauthorized account access.
Their operations often escalate to large-scale data theft and ransomware deployment. This leads to double extortion scenarios, where victims are coerced into paying both to recover their encrypted data and to prevent the public release of stolen information.
Known tactics include:
Alternate Names and Affiliations
While most commonly referred to as Scattered Spider in media and press releases, the group has also been labeled Star Fraud, Octo Tempest, Scatter Swine, and Muddled Libra. They are considered part of a broader cybercriminal ecosystem known as "the Community" or "the Com", which includes individuals responsible for breaches of major U.S. tech firms.
Origins and Early Tactics
Formed around May 2022, Scattered Spider initially focused on attacks against telecommunications companies. Their methods included SIM swapping, MFA fatigue attacks, and phishing via SMS and Telegram. They exploited vulnerabilities like CVE-2015-2291, a Windows anti-DoS flaw, to disable security software and evade detection. The group is known for its technical sophistication, particularly in cloud platforms like Microsoft Azure, Google Workspace, and AWS, often leveraging legitimate remote-access tools.
Transition to Critical Infrastructure & Casinos
After targeting infrastructure sectors, the group shifted focus to casinos in 2023.
MGM Resorts Hack
On September 11, 2023, Scattered Spider infiltrated MGM Resorts by impersonating an employee during a call to the company's help desk, using LinkedIn for social engineering. The next day, MGM reported the breach in a Form 8-K filing with the SEC. The attack disabled hotel systems, including ATMs, room keys, food and beverage credits, and parking charges. Scattered Spider partnered with ALPHV, a ransomware-as-a-service (RaaS) provider.
In July 2024, a 17-year-old from the UK was arrested in connection to the hack. He was released on bail pending trial.
Caesars Entertainment Hack
Scattered Spider reportedly extorted Caesars Entertainment by demanding a $30 million ransom, of which the company paid $15 million. The breach compromised personal data including driver's license and potentially Social Security numbers. Caesars admitted it could not guarantee the deletion of the stolen data.
There is some dispute over whether Scattered Spider was solely responsible for the Caesars attack, with conflicting reports suggesting involvement from another group.
Aftermath and Lawsuits
Both companies experienced stock drops following the attacks. MGM's CEO admitted the company was “completely in the dark” during the incident. The FTC and FBI launched investigations, and Moody's warned of potential credit rating downgrades due to MGM’s operational disruption.
Class-action lawsuits were filed against both MGM and Caesars, alleging negligence in securing customer data. In January 2025, MGM settled for $45 million.
Snowflake Data Breaches
Scattered Spider members were later tied to breaches involving Snowflake customers, where they stole large volumes of data and demanded ransoms. Victims included AT&T, Ticketmaster, Advance Auto Parts, LendingTree, and Neiman Marcus, among nearly 100 organizations.
Mitigate The Threat: Defensive Security Recommendations
To safeguard against threats such as Scattered Spider, implement the following security measures:
Administrative Assistant at Cisco
1wDark matter Quantum ai digital infrastructure cybersecurity
IT Infrastructure Manager | Info Sec & Cloud Security | Cybersecurity | Program/Project Management
2wCritical component to improving an organization’s security posture is timely awareness—training of employees. Scattered Spider are notoriously known for social engineering; therefore, employees must be informed of this group’s current—prior attack tactics.
Timely and relevant update—thanks for sharing this advisory. The evolving tactics of groups like Scattered Spider highlight the critical need for continuous awareness and proactive defence strategies. It's also a reminder of how vital it is to invest in cyber resilience through ongoing #training and #upskill initiatives, especially for teams managing complex digital environments. Looking forward to more insights that support stronger #leadership in navigating today’s #techinnovation landscape.
Inventor, Author, Speaker, Privacy & Security Advocate
2wUnfortunately, the one mitigation they missed was filtering voice traffic. These are socially engineered voice phishing calls for the most part. Why wouldn’t you want to mitigate the risk by filtering out calls from Spoofed numbers, recently ported numbers, and calls that have red flags in the metadata, indicating the caller is impersonating someone else? Shouldn’t a defense in depth be used? Firewalls and spam filters are used routinely for email. Why wouldn’t you use the same techniques for voice traffic?
Security Manager @ BT Group | Governance, Risk and Compliance (GRC) | Cyber Threat Intelligence (CTI) CISM, CRISC, CCSP NIST CSF, CIS, NIS, DORA, ISO27001, MITRE ATT&CK
2wScattered Spider are skilled social engineers. To help protect against them: Focus on reinforcing awareness in your helpdesk, Fatigue resistant MFA, (no SMS/Email if possible) And separation of duties for privileged account resets. These will pay dividends.