logo

Suspected Scattered Spider domains target everyone from manufacturers to Chipotle

ID: 5e5c7f28-184a-521d-b494-20fe68ab0f1b

STIX ID: report--5e5c7f28-184a-521d-b494-20fe68ab0f1b

Feed Name: The Register (Security)

Threat Score
72/100

Date Published: 2025-07-08

Date Updated: 2026-04-26

Author: Jessica Lyons

...
...

Check Point researchers disclosed roughly 500 domains that imitate corporate login portals and follow Scattered Spider naming patterns, indicating prepared or active phishing infrastructure used to harvest credentials; targets span aviation, retail, manufacturing, medical technology and enterprise platforms, with examples including chipotle-sso.com and gemini-servicedesk.com. The report links this activity to a broader wave of social-engineering-driven intrusions and recent airline data incidents (e.g., Qantas), underscoring an opportunistic criminal group using fake helpdesk calls and credential phishing at scale.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.