?Widely attributedActiveMITRE G1015

Scattered Spider

Scattered Spider is a native English-speaking cybercriminal group active since at least 2022. The group initially targeted customer relationship management (CRM) providers, business process outsourcing (BPO) firms, and telecommunications and technology companies before expanding in 2023 to gaming, hospitality, retail, managed service provider (MSP), manufacturing, and financial sectors. Scattered Spider relies heavily on social engineering, including impersonating IT and help-desk staff, to gain initial access, bypass multi-factor authentication (MFA), and compromise enterprise networks. The group has adapted its tooling to evade endpoint detection and response (EDR) defenses and used ransomware for financial gain. Scattered Spider had expanded into hybrid cloud and identity environments, using help-desk impersonation and MFA bypass to obtain administrator access in Okta, AWS, and Office 365.

Attribution signal

?Score = mentions × confidence weight, summed across all attributed sources. Higher source diversity increases the score.≥ 10 High≥ 3 Moderate< 3 Low
13.6
High signal strength
Mentions20
Sources7
High conf.12
Last seenMay 2026
First observed
2023-07-05
Last active
Active
Origin
Western — English-speaking members primarily from US and UK
Aliases
9
Techniques
64
Campaigns
0
Western — English-speaking members primarily from US and UKmedium confidence
TargetsHospitalityTelecommunicationsTechnologyFinancial
RegionsUsEu

Attribution signals

20 mentions · 7 sources
#1attributed tohigh
VictimologyTTP match
socradar
May 2026

"The breach was attributed to Scattered Spider, a group known for its social engineering expertise."

#2trackinghigh
TTP matchVictimology
mandiant
May 2026

"tracking how groups like UNC3944 target IT help desks to bypass multifactor authentication (MFA)"

#3pleaded guiltyhigh
HUMINT
wechat-qax-ti
May 2026

"Scottish threat actor Tyler Robert Buchanan was arrested in Spain and formally charged by the United States in November 2024. In 2025, the U.S. Department of Justice formally announced that this member pleaded guilty to charges related to participation in the Scattered Spider cybercriminal organization."

#4responsible forhigh
Unspecified
dark-reading
May 2026

"Scattered Lapsus$ Hunters has been responsible for some of the most significant, costly cyberattacks across the US economy lately."

#5confirmshigh
Unspecified
dark-reading
May 2026

"An analysis this week from Flashpoint of the disturbing cybercriminal group known as The Com confirms that as major Russian groups have splintered and withered away in recent years, the new class of predominantly North American cybercriminal groups that has emerged all trace back in one way or another to the same source."

#6separated from the pack by effectively targetinghigh
TTP match
dark-reading
May 2026

"They've separated from the pack by effectively targeting the cloud and SaaS platforms organizations across the Western world rely on most, like Okta, Salesforce, and Microsoft365."

#7were behindhigh
Unspecified
eset
May 2026

"cybercrime groups like Scattered Spider, which were behind both JLR and Marks & Spencer breaches"

#8were behindhigh
Unspecified
eset
May 2026

"The loose grouping of English-speaking criminals known as Scattered Spider, who were behind the Marks and Spencer (M&S) breach in the UK"

#9pleaded guiltyhigh
HUMINT
krebs
May 2026

"A 24-year-old British national and senior member of the cybercrime group "Scattered Spider" has pleaded guilty to wire fraud conspiracy and aggravated identity theft."

#10admittedhigh
HUMINT
krebs
May 2026

"admitted his role in a series of text-message phishing attacks in the summer of 2022 that allowed the group to hack into at least a dozen major technology companies and steal tens of millions of dollars worth of cryptocurrency from investors."

#11admittedhigh
HUMINT
krebs
May 2026

"Buchanan admitted conspiring with other Scattered Spider members to launch tens of thousands of SMS-based phishing attacks in 2022 that led to intrusions at a number of technology companies, including Twilio, LastPass, DoorDash, and Mailchimp."

#12usedhigh
TTP match
wiz-research
May 2026

"0ktapus used spoofed SSO portals to harvest credentials."

Hedge terms observed

admittedaligns withattackersattributed toblamed forconfirmsis thought to be behindmirrorspleaded guiltyresponsible forseparated from the pack by effectively targetingshowstrackingunspecifiedusedwere behind