Scattered Spider is a financially motivated, English-speaking group known for aggressive social engineering, SIM-swapping and high-profile extortion attacks.
Key facts
- Specialises in social engineering of help desks and employees to bypass MFA.
- Uses SIM-swapping to hijack accounts and reset credentials.
- Linked to major attacks on large enterprises, including in retail and hospitality.
- Has partnered with ransomware operations to monetise access.
Why it matters
Scattered Spider proves that people and process, not just technology, are the attack surface. Monitoring for leaked employee credentials supports identity defence.
How DarkThreatX helps
DarkThreatX tracks threat-actor activity, leaked credentials and exposed data across the dark web so security teams can act on early warning. Run a free dark web scan or explore the platform.