Scattered Spider Hackers Get Busy

Hackers associated with the group known as Scattered Spider are currently engaged in a wave of cyber-attacks that have affected some of the UK’s most prominent retailers, including Marks & Spencer, the Co-op, and Harrods. Cybersecurity experts warn that the same threat is now extending across the Atlantic, targeting retailers in the United States as well.

Google’s cybersecurity division, Mandiant, has confirmed that this pattern of attacks has shifted seamlessly from the UK into the US, consistent with the modus operandi of Scattered Spider assailants.

The group is believed to be behind the recent breaches, which have seen personal data stolen from affected organisations.

Data Breaches & Personal Information Compromised

Mark & Spencer (M&S) recently notified staff that some personal information may have been compromised during the attack, with email addresses and full names believed to be amongst the data stolen. Later disclosures revealed that thousands of customers’ personal information had also been accessed by the hackers, further underscoring the scope and severity of these breaches.

The Tactics Of Scattered Spider

The National Cyber Security Centre (NCSC) issued an advisory warning businesses across the UK to remain vigilant. The agency highlighted specific tactics employed by Scattered Spider, notably an approach where attackers call IT help desks pretending to be employees or contractors to obtain system access.

“These cyber threats, including extortion and ransomware, are among the most prevalent risks facing UK organisations today,” the NCSC warned. Their guidance urges companies to scrutinise how their help desks manage password resets, as this remains a common entry point exploited by cybercriminals.

About Scattered Spider

Unlike many ransomware groups traditionally linked to Russian and former Soviet states, Scattered Spider is characterised by its composition of native English speakers from countries such as the UK, US, and Canada. The gang uses a variety of hacking techniques rather than operating as a formal, homogenous group.

The primary goal of ransomware gangs like Scattered Spider is to infect organisations' systems with malicious software that encrypts files. The attackers then demand payment in exchange for the decryption keys, often leading to significant data loss and operational disruption.

Challenges For Law Enforcement

Law enforcement agencies have found it difficult to track down and combat Scattered Spider. The group's amorphous structure, youthful membership, and the lack of cooperation from victims have hampered efforts to curtail their activities. 

Given their sophisticated social engineering tactics and dispersed structure, analysts warn that these cyber-attacks could continue to grow in frequency and intensity, especially with the increasing value of retail and consumer data.

The Growing Threat

With the retail sector increasingly targeted by cybercriminals, the importance of robust security measures becomes evident. The NCSC emphasises that cyber threats are opportunistic and indiscriminate, affecting businesses of all sizes - no organisation is immune to the risks posed by groups like Scattered Spider.

As these attacks expand into the US market, both UK and international companies are advised to reinforce their cybersecurity protocols to prevent becoming the next victim of this rising threat.

Google   |   NCSC  |   TechDigest  |   The Record  |   Guardian  |   MSN  

Image: Ideogram

You Might Also Read: 

The Future Of Passwords In Retail:


If you like this website and use the comprehensive 7,000-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« New Law Bans Intimate Deepfake Images
US Confirms Pause In Cyber Operations Against Russia »

Infosecurity Europe
CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity

Resecurity

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

MIRACL

MIRACL

MIRACL provides the world’s only single step Multi-Factor Authentication (MFA) which can replace passwords on 100% of mobiles, desktops or even Smart TVs.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

Alvacomm

Alvacomm

Alvacomm offers holistic VIP cybersecurity services, providing comprehensive protection against cyber threats. Our solutions include risk assessment, threat detection, incident response.

QASymphony

QASymphony

QASymphony software testing and QA tools help companies create better software by improving speed, efficiency and collaboration during the testing lifecycle.

Phoenix Contact Cyber Security

Phoenix Contact Cyber Security

Phoenix Contact Cyber Security is a leading manufacturer of network security appliances for use in industrial environments.

Tessian

Tessian

Tessian (formerly CheckRecipient) is a next-generation email security platform that helps enterprises counteract human error and significantly reduce the risk of data loss.

Chainalysis

Chainalysis

Chainalysis provides blockchain analysis software to prevent, detect and investigate cryptocurrency money laundering, fraud and compliance violations.

Arsenal Recon

Arsenal Recon

Arsenal Recon are digital forensics experts, providing consultancy services and powerful software tools to improve the analysis of electronic evidence.

StormWall

StormWall

StormWall is an Anti-DDoS protection service for websites and networks. We offer 100% protection from all types of DDoS attacks and 24/7 technical support.

Forgepoint Capital

Forgepoint Capital

ForgePoint Capital is a premier venture investor for early stage cybersecurity companies.

Black Hills Information Security (BHIS)

Black Hills Information Security (BHIS)

Black Hills Information Security provide security testing and vulnerability assessment services.

Information & Communications Technology Association of Jordan (int@j)

Information & Communications Technology Association of Jordan (int@j)

The Information & Communications Technology Association of Jordan is a membership based ICT and IT Enabled Services (ITES) industry advocacy, support and networking association.

Cyber Security Works (CSW)

Cyber Security Works (CSW)

Cyber Security Works is your organization’s early cybersecurity warning system to help prevent attacks before they happen.

eCloudvalley Digital Technology

eCloudvalley Digital Technology

eCloudvalley Digital Technology is a born-in-the-cloud partner focused entirely on AWS services across APAC region.

CloudGuard

CloudGuard

CloudGuard is an AI-driven XDR platform that helps organisations to proactively detect and automatically remediate threats in real-time.

ARGOS Cloud Security

ARGOS Cloud Security

ARGOS aims to simplify and strengthen cloud security, by creating a visual map of security vulnerabilities, to your priceless information stored in any cloud provider environment.

Viatel Technology Group

Viatel Technology Group

Viatel Technology Group is a complete digital services provider. We have over 26 years’ experience delivering fully managed security, networking, cloud and communications services.

Fernao Group

Fernao Group

Fernao offer you all solutions from a single source - from cyber security, business resilience and digital infrastructure to cloud technologies and pentesting.

Nyx Security Solutions

Nyx Security Solutions

Nyx is committed to excellence in embedded cybersecurity, delivering top-tier secure design, development, and penetration testing services that meet and exceed industry standards.