Scattered Spider: Understanding the Hacking Group Behind 2025's Biggest Cyberattacks Cybersecurity has become one of the most talked-about subjects in boardrooms and classrooms alike, and one name keeps surfacing in almost every major breach headline this year. Scattered Spider is a hacking collective that has managed to bring airlines, casinos, and retail giants to a standstill using nothing more than a phone call and a convincing voice. This article breaks down who they are, how they operate, and what businesses can do to protect themselves, written in a simple, classroom-style explanation so that even beginners can follow along. What Is Scattered Spider? Scattered Spider is the name given to a loosely organized group of young hackers who rely on social engineering rather than complex malware to break into networks. The group is also tracked under aliases like UNC3944, Muddled Libra, and 0ktapus by different security vendors. Unlike traditional hacking gangs that write custom code, this collective prefers manipulating human trust, tricking help desk staff into resetting passwords or multi-factor authentication devices. Their approach proves that even the strongest firewall cannot stop a well-told lie. Also Known As UNC3944 and Muddled Libra Security researchers at different firms gave the group different code names before realizing they were tracking the same actors. Google's Mandiant calls them UNC3944, while Palo Alto Networks refers to the cluster as Muddled Libra. These overlapping names sometimes confuse readers, but they all point to one highly active threat group. Members and Origins Investigators believe the group formed in May 2022, initially focusing on telecom firms using SIM swap fraud. Many alleged members are teenagers or young adults based in the United States and United Kingdom. They are considered part of a wider underground network known informally as "the Com." The Rise of Scattered Spider: A Timeline of Attacks The group's reputation grew rapidly after a string of headline-making breaches that disrupted household-name companies. What started as telecom-focused SIM swapping evolved into full-scale ransomware extortion campaigns across multiple industries. Each new wave of attacks has followed a similar playbook, targeting one sector intensely before pivoting to another. This pattern makes their movements somewhat predictable for analysts who study threat intelligence closely. The 2023 Casino Breaches In 2023, the group breached MGM Resorts and Caesars Entertainment, causing slot machines, hotel key cards, and reservation systems to fail for days. The MGM breach brought the Las Vegas hotels to a standstill. This incident remains one of the clearest real-world examples of how social engineering can paralyze an entire physical business. pymnts The 2025 Retail and Insurance Wave Early in 2025, the group shifted focus to British retailers. Their attack on Marks & Spencer reportedly wiped out more than $807 million of the company's market value. Insurance companies in the United States, including major carriers, were targeted soon afterward. pymnts How Scattered Spider Hackers Operate Understanding the methodology behind these intrusions helps organizations build better defenses against similar social engineering campaigns. The Scattered Spider hackers typically begin by researching an employee's public information before calling a company help desk. They impersonate that employee convincingly enough to request a password reset or a new multi-factor authentication device. Once inside, they move laterally through cloud platforms like Microsoft Azure, Google Workspace, and AWS to locate valuable data. Their most common tactics include: ● Impersonating IT staff or employees during help desk phone calls ● Exploiting SIM swapping to intercept one-time passcodes ● Triggering MFA fatigue by bombarding victims with approval requests ● Using legitimate remote-access tools to avoid detection by antivirus software ● Deploying ransomware after data theft to pressure victims into paying Social Engineering and Help Desk Exploitation Help desks are often the weakest link because staff are trained to be helpful rather than suspicious. Attackers exploit this by sounding urgent, distressed, or authoritative on the phone. Mandiant's CTO has recommended that companies tighten identity verification steps immediately. SIM Swapping and MFA Fatigue By convincing telecom providers to transfer a victim's phone number to a new SIM card, attackers intercept verification codes sent by text message. Combined with repeated MFA push notifications, exhausted employees sometimes approve a login just to stop the alerts. This single mistake can open the door to an entire corporate network. Scattered Spider Airlines Attacks: A Case Study Aviation became the group's newest target starting in June 2025, alarming regulators worldwide almost overnight. The FBI publicly warned that anyone connected to the airline ecosystem, including vendors and contractors, faced potential risk. Analysts at Unit 42 and Mandiant both confirmed active incidents across the transportation sector during this period. The pattern shows how quickly a Scattered Spider airlines campaign can spread once one carrier's third-party vendor is compromised. Hawaiian Airlines and WestJet Incidents Hawaiian Airlines disclosed a cyberattack while securing its systems, and WestJet confirmed an ongoing breach first reported in mid-June 2025. Several media outlets linked both incidents to the same threat cluster. These were among the earliest signals that aviation had become the group's next area of interest. beinsure The Qantas Data Breach Qantas suffered a breach detected on June 30, 2025, compromising data belonging to up to six million passengers. Customers later reported receiving scam calls referencing personal details that were not part of the original leak, showing how stolen data gets combined from multiple sources for further fraud. adminbyrequestadminbyrequest Recent Scattered Spider News and Industry Response Staying updated on Scattered Spider news has become essential for IT security teams across every major industry, not just aviation. Microsoft confirmed in mid-July 2025 that the group's activity aligned with its known pattern of concentrating on one sector for weeks before moving elsewhere. Security firm Halcyon warned that the group had begun broadening its reach into food and manufacturing companies as well. Constant monitoring of threat intelligence feeds is now considered a basic requirement for any large enterprise. FBI and Mandiant Warnings Mandiant recommended that the aviation industry immediately tighten its help desk identity verification processes following multiple confirmed incidents. The FBI echoed similar advice, urging companies to report suspected activity early so intelligence could be shared industry-wide. computing Arrests and Ongoing Investigations Despite multiple arrests of alleged members throughout 2024, the group has continued operating into 2025. This resilience demonstrates how decentralized and loosely structured the collective truly is, making it difficult to dismantle entirely through arrests alone. adminbyrequest Digital Risk Protection: How Organizations Can Defend Against Scattered Spider Preventing an incident from this notorious threat group requires more than just antivirus software and a firewall. Digital risk protection strategies combine identity verification, employee awareness training, and continuous monitoring of the dark web for leaked credentials. Companies that invest early in these layered defenses tend to recover faster and lose far less data during an attempted breach. Because Scattered Spider relies heavily on human error, protecting people is just as important as protecting servers. Effective defensive measures include: ● Verifying employee identity through video calls before password resets ● Enforcing phishing-resistant MFA methods like hardware security keys ● Monitoring for unusual login locations or repeated MFA prompts ● Segmenting networks so one compromised account cannot reach everything ● Running regular social engineering awareness drills for help desk staff Employee Training and Verification Protocols Regular simulated phishing and vishing drills help staff recognize manipulation tactics before damage occurs. Many breaches trace back to a single untrained employee who trusted a convincing phone call. Building a culture of healthy skepticism at the help desk closes this gap significantly. Zero Trust and Continuous Monitoring A zero trust architecture assumes no user or device is automatically trustworthy, even inside the network. Continuous monitoring tools flag unusual behavior, such as a login from an unexpected country. Together, these measures shrink the window of opportunity attackers rely on. Frequently Asked Questions What industries have been affected by this hacking group? Casinos, retailers, insurance firms, airlines, and now manufacturing and food companies have all reported incidents linked to this collective. Is this threat group financially motivated? Yes, most incidents end with a ransom demand or extortion attempt after sensitive data is stolen. How can employees protect themselves from social engineering calls? Always verify a caller's identity through an official channel before resetting passwords or approving access requests. Are these hackers based in one country? Members are believed to be spread across the United States and United Kingdom, working as part of a broader online community. What should a company do if it suspects a breach? Report the incident to law enforcement early and isolate affected systems immediately to limit further damage. Conclusion The rapid rise of this social-engineering-driven hacking group proves that cybersecurity is no longer just a technical problem, it is a human one. From casinos to airlines, the pattern remains the same: convincing a person is often easier than breaking encryption. Organizations that combine strong verification protocols, employee training, and continuous monitoring stand the best chance of staying off the next headline.