The Attack Surface in Your Pocketâand How Scattered Spider Socially Engineers Their Way Inside
ID: 89b8e18d-6c46-5800-a54a-d60674b94fb2
STIX ID: report--89b8e18d-6c46-5800-a54a-d60674b94fb2
Feed Name: iVerify Blog
Threat Score
This advisory warns financial institutions that mobile devices and social-engineering campaigns led by groups such as Scattered Spider (in collaboration with LAPSUS$ and ShinyHunters) are primary attack vectors—exploiting SIM swaps, SMS/MFA, help-desk flows, and OAuth integrations—and recommends concrete mitigations including FIDO2/passkeys, cryptographic device binding, OAuth hygiene, stricter help-desk controls, and mobile-focused awareness and incident playbooks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
