Target Industry

Scattered Spider have been seen targeting these sectors: 

  • Financial  
  • Gaming 
  • Hospitality 
  • Insurance 
  • Managed Service Providers (MSPs) 
  • Manufacturing 
  • Retail 
  • Transportation 

Overview

The FBI has issued a warning about the Scattered Spider cybercriminal group, which is now targeting the transportation sector, including airlines. The warning highlights the group’s use of social engineering to impersonate employees or contractors, allowing them to bypass multi-factor authentication (MFA). The FBI is collaborating with aviation and industry partners to address this activity and assist victims. 

Impact

The impact of these cybersecurity threats on the insurance industry can be profound. Ransomware attacks can lead to significant operational disruptions due to network outages. The financial implications can be severe, including potential ransom payments, legal fees, and costs associated with recovery efforts. 

Exploitation

Scattered Spider often starts the ransomware attack with fake helpdesk calls to gain access to devices. For this they use social engineering or SIM-swapping, to gain unauthorised access to personal accounts and sensitive information. The group move on to deploy DragonForce ransomware, adding a ransom note into the affected directories.  

The data is exfiltrated and threaten to be released publicly if the ransom is not paid. Access to the compromised systems is maintained, allowing them to return even if the initial attack is mitigated. The group attempt to move laterally within the network to infect other devices and systems, increasing the scope of the attack. 

Indicators of Compromise

Here are some indicators of compromise associated with Scattered Spider. For a more in-depth listing, please refer to the Quorum Cyber ransomware report on the group. 

Indicator  Type  Description  
README.txt Ransom note  Name of ransom note left in the directories of encrypted file  
..df File extension  File extension used by DragonForce  
9a218d69ecafe65eae264d2fdb52f1aa md5  File hashes used by DragonForce ransomware  
d44071f255785c73909d64f824331ebf md5  File hashes used by DragonForce ransomware  
b97812a2e6be54e725defbab88357fa2 md5  File hashes used by DragonForce ransomware  

 

Containment, Mitigations & Remediations

To improve cybersecurity, organisations should consider the following recommendations: 

  • Enhance employee training on recognising phishing attempts and social engineering tactics. 
  • Implement strong authentication by utilising multi-factor authentication (MFA) and ensuring robust identity verification processes. 
  • Conduct regular security audits of security protocols and systems. 
  • Develop incident response plans, by having a well-defined incident response strategy can minimise the impact of a cyberattack and ensure a swift recovery 

Threat Landscape

Cybersecurity threats in the transportation industry are evolving rapidly. The frequency of attacks has increased, with threat groups like Scattered Spider shifting their focus to new sectors, including transportation, as they exhaust previous targets. The speed at which new tactics are developed and deployed is alarming, with reports indicating that attacks are becoming more sophisticated and harder to detect. This trend necessitates constant vigilance and adaptation from insurance companies to keep pace with emerging threats.

Threat Group

Scattered Spider, also known as UNC3944, is a prominent threat group that has recently pivoted its focus to the insurance sector. This group is known for its high-impact campaigns that often involve social engineering, phishing, and ransomware attacks. Their tactics include impersonating IT staff to manipulate help desk personnel into granting access to sensitive systems.  

The group has a history of targeting specific sectors sequentially, which raises concerns about their potential to cause widespread disruption in the insurance industry. Scattered Spider collaborates with major ransomware operators and has ties with Russia-aligned threat groups, enhancing their impersonation tactics. 

Access our Scattered Spider Ransomware report here: Scattered Spider Report 

Further Information

https://www.forbes.com/sites/daveywinder/2025/06/30/fbi-warning-issued-as-2fa-bypass-attacks-surge—act-now/

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content