Target Industry

Scattered Spider has been seen targeting these sectors: 

  • Financial  
  • Gaming 
  • Hospitality 
  • Insurance 
  • Managed Service Providers (MSPs) 
  • Manufacturing 
  • Retail. 

Overview

The cybercrime gang Scattered Spider has shifted its focus from high-end retailers to insurance companies in the United States. Google Threat Intelligence Group (GTIG) has observed multiple ransomware attacks in the US insurance sector which can be attributed to Scattered Spider.  

Impact

The impact of these cyber security threats on the insurance industry can be profound. Ransomware attacks can lead to significant operational disruptions due to a network outage. The financial implications can be severe, with potential ransom payments, legal fees, and costs associated with recovery efforts. 

Recent Attacks

The Scattered Spider cyberattack on Erie Insurance was identified on 7th June 2025, with a significant network outage affecting all of Erie Insurance’s systems on 8th June 2025. The Philadelphia Insurance Companies (PHLY) had reported on 9th June that their IT team were dealing with suspicious activity on their network. 

Exploitation

Scattered Spider often starts the ransomware attack with fake helpdesk calls to gain access to devices. For this they use social engineering or SIM-swapping to gain unauthorised access to personal accounts and sensitive information. The group moves on to deploy DragonForce ransomware, adding a ransom note into the affected directories.  

The data is exfiltrated and Scattered Spider threatens to release it publicly if the ransom is not paid. Access to the compromised systems is maintained, allowing them to return even if the initial attack is mitigated. The group attempts to move laterally within the network to infect other devices and systems, increasing the scope of the attack. 

Indicators of Compromise

Here are some indicators of compromise associated with Scattered Spider. For more in-depth analysis, please refer to Quorum Cyber’s Scattered Spider Threat Actor Profile. 

Indicator  Type  Description  
README.txt Ransom note  Name of ransom note left in the directories of encrypted file  
..df File extension  File extension used by DragonForce  
9a218d69ecafe65eae264d2fdb52f1aa md5  File hashes used by DragonForce ransomware  
d44071f255785c73909d64f824331ebf md5  File hashes used by DragonForce ransomware  
b97812a2e6be54e725defbab88357fa2 md5  File hashes used by DragonForce ransomware  

Containment, Mitigations & Remediations

To improve cyber security, organisations should consider the following recommendations: 

  • Enhance employee training on recognising phishing attempts and social engineering tactics 
  • Implement strong authentication by utilising multi-factor authentication (MFA) and ensuring robust identity verification processes 
  • Conduct regular security audits of security protocols and systems 
  • Develop incident response plans; a well-defined incident response strategy can minimise the impact of a cyber-attack and ensure a swift recovery. 

Threat Landscape

Cyber security threats in the insurance industry are evolving rapidly. The frequency of attacks has increased, with threat groups like Scattered Spider shifting their focus to new sectors, including insurance, as they exhaust previous targets. The speed at which new tactics are developed and deployed is alarming, with reports indicating that attacks are becoming more sophisticated and harder to detect. This trend necessitates constant vigilance and adaptation from insurance companies to keep pace with emerging threats. 

Threat Group

Scattered Spider, also known as UNC3944, is a prominent threat group that has recently pivoted its focus to the insurance sector. This group is known for its high-impact campaigns that often involve social engineering, phishing, and ransomware attacks. Its tactics include impersonating IT staff to manipulate help desk personnel into granting access to sensitive systems. The group has a history of targeting specific sectors sequentially, which raises concerns about their potential to cause widespread disruption in the insurance industry. 

Further Information

 

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content