logo

Despite Arrests, Scattered Spider Continues High-Profile Hacking

ID: d9fc4418-7c51-5632-ba44-b1a81313b4f3

STIX ID: report--d9fc4418-7c51-5632-ba44-b1a81313b4f3

Feed Name: Dark Reading

Threat Score
75/100

Date Published: 2025-05-02

Date Updated: 2026-04-21

Author: Rob Wright

...
...

The report details ongoing activity by the Scattered Spider cybercriminal group that leverages advanced social-engineering techniques (SIM swapping, MFA bombing) to steal credentials and gain privileged access, deploying ransomware and data-extortion (notably ALPHV/BlackCat and DragonForce) against high-value targets such as casino operators and major retailers; it also covers recent arrests, the group’s resilience and shift to distributed affiliate models, and defensive recommendations like non-SMS MFA and domain blocking.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.