logo

Scattered Spider and Other Criminal Compromise of Outsourcing Providers Increases Victim Attacks

ID: d2e767ce-018c-5a0c-bf15-2b8bacc185a4

STIX ID: report--d2e767ce-018c-5a0c-bf15-2b8bacc185a4

Feed Name: Halcyon Blog

Threat Score
85/100

Date Published: 2026-03-02

Date Updated: 2026-04-28

...
...

This Halcyon intelligence brief details Scattered Spider (UNC3944) leveraging compromises of BPO/MSP providers to gain broad lateral access to client environments, execute large-scale data exfiltration, and deploy ransomware across sectors (retail, insurance, aviation, etc.). The report maps the group’s lifecycle to MITRE ATT&CK—highlighting social engineering and insider recruitment, MFA and Intune abuse, BYOVD/EDR evasion, and use of cloud/file hosts for covert exfiltration—and issues prioritized mitigations such as enforcing phishing-resistant MFA, auditing third‑party access and logs, monitoring for cloned authentication flows, hardening identity infrastructure, and preparing tenant-lockout recovery playbooks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.