logo

Report Finds 50% of Scattered Spider Phishing Domains Targeted Finance & Insurance

ID: 4e0495a7-e424-57c5-abf2-84aefd623ca0

STIX ID: report--4e0495a7-e424-57c5-abf2-84aefd623ca0

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2025-01-22

Date Updated: 2026-04-29

...
...

This threat landscape briefing for the finance and insurance sector highlights that phishing (including Microsoft Teams abuse) drove the majority of incidents in H2 2024, impersonating domains and subdomains remain a persistent risk, and ransomware group “RansomHub” became the most active ransomware actor targeting the sector—using remote-access tools and data exfiltration for double-extortion with average demands of $6–9M; the report details observed TTPs, tooling, victim impact, and recommends defensive measures such as monitoring, MFA, DLP, segmentation, and domain/DMARC protections while forecasting increased social engineering, state-sponsored activity, and AI model-poisoning risks in 2025.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.