Scattered Spider is a loosely organized cybercrime collective known for breaking into major companies through social engineering rather than malware, tricking help desks and employees into handing over access instead of hacking their way in. Active since at least 2022, the group has been linked to attacks on MGM Resorts, Caesars Entertainment, Marks & Spencer, and a growing list of airlines, insurers, and retailers, often deploying DragonForce or ALPHV ransomware once inside a victim’s network.
Despite a string of arrests across the US, the UK, and Spain since 2024, the group’s activity hasn’t stopped; it’s shifted, moving sector by sector as new members adopt the same playbook. US federal prosecutors have tied Scattered Spider to more than 100 network intrusions and over $100 million in ransom payments as of mid-2026, making it one of the most financially damaging threat groups currently active.
This guide breaks down who’s behind Scattered Spider, exactly how their attacks unfold, which organizations they’ve targeted, and, most importantly, the specific defenses that actually stop their methods.
What Is Scattered Spider?
Scattered Spider is a cybercriminal collective that specializes in social engineering, impersonating employees to trick help desks and IT support into resetting passwords or multifactor authentication, rather than exploiting software vulnerabilities. First identified in 2022, the group is composed largely of English-speaking teenagers and young adults, many recruited from online gaming and Discord communities, which has made attribution and takedown efforts unusually difficult for law enforcement.
Aliases, UNC3944, Octo Tempest, 0ktapus, “The Com”
Scattered Spider isn’t a fixed name so much as a label different security vendors gave the same activity. Mandiant tracks the group as UNC3944, Microsoft calls it Octo Tempest, and early researchers used 0ktapus after a 2022 wave of Okta-themed phishing campaigns. All three names point to the same core cluster of actors operating within “The Com,” a much larger, loosely affiliated network of English-speaking cybercriminals who trade access, tools, and stolen data across Telegram and Discord. Because membership in The Com overlaps with other named groups, security teams often see Scattered Spider’s tactics appear under different labels depending on which vendor reports them.
Is Scattered Spider an APT or a Cybercrime Gang?
Scattered Spider is not a nation-state advanced persistent threat (APT); it’s a financially motivated cybercrime gang, despite tactics sophisticated enough that some researchers initially assumed it was state-backed. The group’s goal is extortion and ransom, not espionage or geopolitical disruption, and its members have been prosecuted through ordinary criminal courts in the US and UK rather than treated as state actors. US federal prosecutors have linked the group to more than 100 network intrusions and over $100 million in ransom payments, a scale that reflects an organized criminal enterprise rather than a single-purpose intelligence operation.
Who’s Behind Scattered Spider
A single leader or nation-state doesn’t run Scattered Spider; it’s a shifting collective of mostly young, English-speaking hackers, many still in their teens or early twenties, who found each other through gaming and Discord communities before turning to cybercrime. That loose, decentralized structure is part of why the group has been so hard to shut down: arresting one member rarely stops the next attack.

Origin and Nationality, Where Are They Based?
Most identified Scattered Spider members are based in the United States and the United Kingdom, rather than in Russia or another state actor’s territory, which sets the group apart from many ransomware crews tied to Eastern Europe. Investigators have traced arrests to Florida, Scotland, and England, and the group draws its membership from “The Com,” a broader English-speaking cybercrime network rather than any single country’s criminal underworld.
Known Members and Arrests (Tyler Buchanan, Noah Urban, Thalha Jubair)
Law enforcement has steadily attached real names to the group once known only by online handles. Tyler Buchanan, a Scottish national once described as a ringleader, was extradited from Spain and pleaded guilty to conspiring in SMS phishing attacks that led to breaches at Twilio, LastPass, and DoorDash. Noah Urban, a 20-year-old from Florida who went by aliases including “Sosa” and “King Bob,” was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution for SIM-swapping attacks that drained cryptocurrency from dozens of victims. Thalha Jubair, an 18-year-old from the UK, was charged alongside co-defendant Owen Flowers over the 2024 attack on Transport for London and hacks against US healthcare systems, arrests that, according to researchers, briefly slowed the group’s activity without stopping it.
Links to LAPSUS$, ShinyHunters, ALPHV and DragonForce
Scattered Spider doesn’t operate in isolation; it borrows people, tools, and ransomware payloads from other crews within The Com. The group has reportedly joined forces with ShinyHunters and LAPSUS$ in a broader cybercrime alliance, and it typically doesn’t build its own ransomware, instead deploying ALPHV/BlackCat or DragonForce encryptors once it has gained access to a victim’s network. That division of labor- Scattered Spider handles the social engineering and initial breach, partner groups supply the ransomware- is a big reason its attacks move so fast once inside.
How Scattered Spider Attacks: Tactics and Techniques
Scattered Spider’s attacks succeed because they target people and processes rather than software flaws; the group would rather talk its way past a help desk than find a zero-day exploit. That approach lets it move from first contact to full network access in hours, not weeks, which is part of what makes the group so disruptive once it’s inside.

Social Engineering and Vishing
The group’s signature move is voice phishing, or vishing: calling an employee or IT help desk while impersonating a staff member, often using details scraped from LinkedIn or previous breaches to sound convincing. These calls are frequently used to request a password reset or to register a new MFA device, giving the attacker a legitimate-looking way into the network without ever touching malware.
Help Desk and MFA Bypass Tactics
Because Scattered Spider’s entry point is almost always a human decision, the help desk has become its most reliable target. Attackers pressure support staff into resetting credentials or enrolling a new multifactor authentication device under their control, sidestepping MFA entirely rather than trying to break it. Security researchers have pointed to this as the core weakness the group exploits; stricter identity verification before any reset, not stronger firewalls, is what actually closes the gap.
SIM Swapping and Phishing Infrastructure
Alongside vishing, the group runs large-scale SMS phishing campaigns, sending employees fake account-deactivation texts that lead to convincing fake login pages. Stolen credentials are then sometimes paired with SIM-swapping, which hijacks a victim’s phone number to intercept one-time passcodes, a tactic tied to more than $800,000 in cryptocurrency theft from just five victims in a single prosecuted case. This combination of phishing kits and telecom fraud gives the group multiple paths around traditional two-factor authentication.
VMware ESXi and Active Directory Exploitation
Once inside a network, Scattered Spider moves quickly to the systems that let it cause the most damage: Active Directory, for broader credential access, and VMware ESXi servers, which host the virtual machines many companies rely on to run their operations. Targeting ESXi directly allows the group to encrypt or turn off dozens of virtual servers at once, which is why victims like MGM Resorts experienced widespread, simultaneous outages rather than isolated system failures.
Ransomware Deployment (DragonForce, RansomHub, ALPHV)
Scattered Spider typically doesn’t build its own ransomware; it deploys payloads from partner operations after establishing access. CISA has confirmed the group is using DragonForce ransomware to encrypt victims’ ESXi environments, alongside past use of ALPHV/BlackCat and RansomHub, and custom tools like the RattyRAT remote access trojan to maintain stealthy, persistent footholds. This “access-for-hire” model, pairing Scattered Spider’s social engineering with another group’s encryption tools, is what turns a single successful phone call into a full ransomware incident.
MITRE ATT&CK Mapping and Known IOCs
Security teams track Scattered Spider’s activity using the MITRE ATT&CK framework, a shared vocabulary of technique IDs that lets analysts recognize the group’s behavior even as its tools and infrastructure change. Because Scattered Spider relies so heavily on social engineering rather than custom malware, its ATT&CK profile looks different from that of a typical ransomware gang, weighted toward identity and human-layer techniques rather than exploit code.

Key TTP IDs and Indicators of Compromise
A joint advisory from CISA, the FBI, and international partners maps Scattered Spider’s core playbook to specific ATT&CK techniques: phishing for information over the phone (T1598, including the voice-call variant T1598.004), impersonation of employees or IT staff (T1656), and use of legitimate remote access software like AnyDesk or ScreenConnect to maintain a foothold (T1219) after tricking a user into running it (T1204). Once inside, the group is known for MFA fatigue attacks, bombarding a user with authentication prompts until one is accepted out of frustration (T1621), and for convincing help desks to transfer a victim’s MFA enrollment to a device the attacker controls, a technique mapped to valid account abuse (T1078.002) and trusted relationship exploitation (T1199). Earlier reconnaissance typically draws on personal details gathered from social media (T1593.001) and other identity information (T1589), which is what makes the group’s phone-based pretexting so convincing in the first place. For defenders, matching real-time help desk activity against these specific technique IDs, rather than relying on antivirus or malware signatures, is what actually catches a Scattered Spider intrusion before it reaches Active Directory or ESXi.
Scattered Spider Attack Timeline (2023–2026)
Scattered Spider’s activity has moved in waves, hitting one industry hard before shifting to the next as law enforcement catches up. Tracing that timeline shows a group that adapts faster than most defenders expect, cycling through casinos, cloud platforms, retailers, and airlines over roughly three years.

MGM and Caesars (2023)
Scattered Spider’s breakout moment came in September 2023, when the group breached MGM Resorts and Caesars Entertainment within days of each other, shutting down MGM’s slot machines, hotel keycards, and reservation systems for over a week. Caesars reportedly paid around $15 million to restore its network. In comparison, MGM refused to pay and absorbed an estimated $100 million in losses from the outage, a split outcome that’s since become a reference point in debates over whether paying ransom is ever the safer bet.
Snowflake and Okta Incidents
Before the casino attacks, Scattered Spider (then better known as “0ktapus”) ran a large 2022 phishing campaign built around fake Okta login pages, compromising Twilio, Cloudflare, and dozens of other companies that relied on Okta for single sign-on. In mid-2024, researchers also flagged a possible connection between the group and the Snowflake customer-data theft campaign. However, that intrusion has been attributed primarily to a separate threat actor, UNC5537, a reminder that Scattered Spider’s tactics are widely copied within its broader Com network, which can blur attribution even for experienced investigators.
2025–2026 Airline, Insurance, and Retail Wave
Through 2025 and into 2026, the group’s focus shifted to UK retail and then US insurance and aviation, hitting Marks & Spencer, Co-op, and Harrods in the spring of 2025 before moving on to insurers including Aflac and Erie, and airlines such as Hawaiian, Qantas, and WestJet. Security researchers describe this as a deliberate pattern: Scattered Spider works through one sector at a time, exhausting a wave of similarly structured targets before pivoting, which makes an active wave in one industry a reasonable early warning for others in the same sector.
Who Has Scattered Spider Targeted?
Scattered Spider’s victim list reads like a cross-section of consumer-facing industries rather than any single sector; the group tends to work through one industry at a time, using the same playbook of help-desk deception before moving to the next. That pattern makes its target history useful for predicting where the next wave is likely to land.

Airlines and Transportation (Hawaiian, Qantas, WestJet)
In mid-2025, the group turned its attention to aviation, with Hawaiian Airlines, Qantas, and WestJet all disclosing cybersecurity incidents linked to Scattered Spider’s tactics within a short window of each other. The FBI issued a specific warning about the group targeting the airline industry, noting its pattern of using help desk social engineering to bypass identity verification at large transportation companies. In this sector, operational disruption carries outsized real-world stakes.
Insurance (Aflac, Erie, Allianz)
Scattered Spider’s insurance-sector wave hit Aflac, Erie Insurance, and Allianz Life within weeks of each other in 2025, each disclosing unauthorized access consistent with the group’s social engineering approach. Insurers are attractive targets because they hold large volumes of sensitive personal and financial data on policyholders, giving attackers leverage for extortion even without ransomware.
Retail (M&S, Clorox, Victoria’s Secret, Harrods)
UK retail bore some of the group’s most damaging attacks: Marks & Spencer, Co-op, and Harrods were all breached in the spring of 2025, with M&S alone estimating the disruption cost it more than £300 million in lost sales. Clorox hit back in 2023, later filing a $380 million lawsuit alleging its IT vendor handed over employee credentials to attackers without properly verifying their identities, underscoring how much of Scattered Spider’s damage traces back to a single unauthenticated phone call.
Automotive and Enterprise (Jaguar Land Rover, TCS)
Jaguar Land Rover’s September 2025 breach was initially claimed by “Scattered Lapsus$ Hunters,” a collective claiming ties to Scattered Spider, LAPSUS$, and ShinyHunters. It forced a five-week production shutdown that a later New York Times investigation suggested may actually trace back to a separate Russian operation, a reminder that attribution in these cases isn’t always settled even months later. IT services giant TCS, which counted JLR among its clients, was also drawn into scrutiny during the incident’s aftermath, illustrating how an attack on one company’s supply chain can implicate its vendors as well.
How Scattered Spider Compares to Other Threat Groups
Scattered Spider is often mentioned alongside other cybercrime groups it collaborates with, but each has a distinct role and history worth separating. Understanding those differences matters for defenders, since the warning signs and motivations aren’t identical across groups even when their attacks overlap.
Scattered Spider vs. LAPSUS$
LAPSUS$ and Scattered Spider share a similar playbook; both rely on social engineering and SIM swapping rather than malware, but their goals diverge. LAPSUS$, which first drew attention in 2021 for breaches at Microsoft, Okta, and Nvidia, is driven largely by notoriety and public extortion, often leaking stolen data on Telegram for attention as much as profit. Scattered Spider has historically been more financially disciplined, monetizing access through ransomware deployment and direct cryptocurrency theft. The two groups now overlap significantly through the “Scattered Lapsus$ Hunters” alliance, which also includes ShinyHunters, blurring a distinction that used to be clearer.
Scattered Spider vs. ALPHV/BlackCat
ALPHV, also known as BlackCat, is a ransomware-as-a-service operation, a business that builds and licenses encryption malware to affiliates, rather than a group that breaches networks itself. Scattered Spider is one of the affiliates known to have used ALPHV’s ransomware after gaining access through its own social engineering attacks, most notably in the 2023 MGM Resorts breach. That distinction matters operationally: taking down ALPHV’s infrastructure, as law enforcement attempted in 2023 and 2024, doesn’t stop Scattered Spider, since the group can simply switch to a different ransomware partner like DragonForce, which is exactly what it has done since.
How to Detect and Defend Against Scattered Spider
Defending against Scattered Spider means hardening the human aspects of a security program, not just the technical ones; the group has consistently proven that a convincing phone call can bypass defenses that stop most malware cold. The two most effective controls both target the same weak point: how easily an attacker can pass as someone they’re not.

Help Desk Verification Hardening
Because Scattered Spider’s primary entry point is a help desk conversation, the single most effective defense is requiring verification that can’t be talked around over the phone, a callback to a pre-registered number, a supervisor sign-off, or an in-person check for high-risk actions like password resets and MFA re-enrollment. Security researchers who studied the group’s tactics have noted that stricter identity checks before any reset, rather than stronger firewalls, are what actually close this gap. Organizations should also move away from push-based MFA toward phishing-resistant options like hardware security keys, since push notifications are exactly what the group’s MFA fatigue attacks exploit.
Monitoring for Leaked Credentials and Dark Web Exposure
Scattered Spider’s social engineering works best when attackers already have real personal details about an employee, names, roles, phone numbers, and prior breach data scraped from the open and dark web, so cutting off that raw material is a meaningful layer of defense. Continuous dark web monitoring that flags employee credentials, corporate email addresses, or internal documents appearing in breach dumps and criminal marketplaces gives security teams a chance to force password resets and alert help desks before that exposed data gets weaponized in a vishing call. Given that federal prosecutors have tied the group to over 100 intrusions and $100 million in ransom payments, closing this early-warning gap is one of the more cost-effective controls available, since it catches exposure long before an attacker ever picks up the phone.
Frequently Asked Questions (FAQ’s)
What does Scattered Spider want?
Money. The group monetizes network access through ransomware extortion and direct cryptocurrency theft rather than espionage or political disruption.
Is Scattered Spider Russian?
No. Most identified members are based in the United States and United Kingdom, unlike many ransomware crews tied to Eastern Europe.
What is “The Com”?
A large, loosely organized network of English-speaking cybercriminals on Telegram and Discord. Scattered Spider is one cluster operating within it, alongside groups like LAPSUS$ and ShinyHunters.
Is Scattered Spider still active in 2026?
Yes, though arrests have periodically slowed it. New members keep reusing the same playbook even as earlier ones face prosecution.
How does Scattered Spider get initial access?
Almost always through phone-based social engineering, impersonating an employee to convince IT help desks to reset a password or transfer MFA to an attacker-controlled device.



