The Rise of Scattered Spider: What Every Organisation Needs to Know

Written by: Lisa Forte

Categorised: Cyber Resilience, Ransomware, Social Engineering

Who are Scattered Spider?

Scattered Spider is a fast-rising, English-speaking group of cybercriminals that’s making waves for all the wrong reasons. Operating as a decentralised and elusive coalition, they’ve become infamous for targeting large enterprises with alarming precision, both on-premises and in the cloud. Their technical skill and ability to evade law enforcement make them one of the most formidable threats in today’s digital landscape. In this article, we break down who they are, how they operate, and most importantly, what you can do to protect your organisation from becoming their next target.

 Scattered Spider’s Ruthless Playbook: How They Break In and Stay In

Unlike many traditional ransomware groups, Scattered Spider doesn’t rely on a single tactic. They use a broad and aggressive toolkit to breach organisations. Their attacks often begin with phishing campaigns, help desk impersonation, and MFA fatigue, combined with fake domains and social media profiles to trick employees into handing over credentials.

Once inside, they follow the familiar double extortion model: encrypting data while also exfiltrating it to pressure victims into paying up. But what sets them apart is their ability to maintain persistent access. They use legitimate remote administration tools to stay hidden, conduct deep reconnaissance, and move laterally across networks. Their skill in exploiting cloud management platforms makes them especially dangerous in hybrid environments.

Scattered Spider also employs advanced evasion techniques, such as Bring Your Own Vulnerable Driver (BYOVD), to disable security software and avoid detection. Their targets span industries, including casinos, luxury hotels, retailers, and, most recently, airlines. This shows a clear pattern of evolving focus and adaptability.

 

How to Prepare Your Organisation for a Scattered Spider Attack

There are plenty of blogs talking more specifically about the TTPs and IOCs being observed from Scattered Spider attacks and how to defend against them but we also have to consider what we do if we end being a victim of such a group.

Key things to prepare:

1. Develop your IRP for identity breaches

Scattered Spider attacks move extremely fast from that initial account compromise to full domain or domain admin compromise. This documentation should include elements such as forcing enterprise-wide password resets, invalidating active sessions, locking down accounts, stopping help desk password resets and system isolation considerations.

2. Ensure you have double extortion ransomware attack playbooks for GSB teams

Each level of your crisis management structure (Gold, Silver, Bronze for example) should have playbooks created to help guide their decision making in those crucial early hours/days. These should include key things they need to ask / consider regarding containment decisions, how to validate stolen data, who to tell and when, SLAs from suppliers and what external third party support they can expect.

3. Consider GSB escalations and delegated authority for faster decision making

Due to the speed these attacks evolve at, waiting to make critical decisions can prove costly. A common decision that may need to be made early on and could into and of itself yield disruption is that of aggressive containment. Also referred to as a “Killswitch” it could involve pulling the organisation offline. Some attacks don’t afford you the time to wait for the Gold team to discuss and decide whether or not to take this course of action. Consider having it delegated to the CISO or other appropriate role.

4. Comms plans, playbooks and templates

Comms are the second most important team in a ransomware attack. Bandwidth becomes increasing precious quickly. Pre-planning and getting advance sign off for communications can pay dividends in a crisis. Have ransomware specific templates, plans and playbooks developed so your comms team need to tailor what they put out but crucially don’t have large delays in the comms and ensure that the information contained therein is accurate and well articulated.

5. Important business service disruption

Ensure you know what your important business services are, what technology they rely on and manual workarounds are considered and tested. Consider how you could keep as many important business services up and running if the worst happened and you had no systems operational. Test those workarounds because everything works well on paper. Consider what additional resources would be needed to keep these workarounds going after a few days, weeks and months. Disruption from ransomware attacks is rarely weeks, it is usually much longer so how will that impact things?

6. Run exercises and simulations

Ensure that you are running exercises (and if you are more mature in your resilience journey then simulations) for all your crisis management teams and the deputies to ensure that any gaps in these plans are identified, all team members are aware of the business impact a ransomware attack from a group like Scattered Spider could cause and any solutions that need to be implemented or improved are understood and stood up.

 

Scattered Spider represents a new breed of cyber threat. They are technically skilled, fast-moving, and relentless. Their ability to exploit both human and technical vulnerabilities makes them a serious risk to organisations across industries. Preparing for an attack isn’t just about prevention, it’s about readiness. By building robust incident response plans, training crisis teams, and running realistic simulations, organisations can strengthen their resilience and respond decisively when it matters most. The threat is real, but with the right preparation, it doesn’t have to be devastating.

Related Content

Menu