Suspected Scattered Spider domains target everyone from manufacturers to Chipotle
ID: 5e5c7f28-184a-521d-b494-20fe68ab0f1b
STIX ID: report--5e5c7f28-184a-521d-b494-20fe68ab0f1b
Feed Name: The Register (Security)
Check Point researchers disclosed roughly 500 domains that imitate corporate login portals and follow Scattered Spider naming patterns, indicating prepared or active phishing infrastructure used to harvest credentials; targets span aviation, retail, manufacturing, medical technology and enterprise platforms, with examples including chipotle-sso.com and gemini-servicedesk.com. The report links this activity to a broader wave of social-engineering-driven intrusions and recent airline data incidents (e.g., Qantas), underscoring an opportunistic criminal group using fake helpdesk calls and credential phishing at scale.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
