Threat Intelligence • Threat Actor Profile
The Scattered Spider Profile
Last Updated: July 2026
Scattered Spider is a cybercriminal actor known for identity-focused attacks, social engineering, help desk impersonation, SIM swapping, and MFA fatigue techniques.
Studying Scattered Spider is a reminder that attackers do not always need advanced malware to create serious impact. Sometimes the intrusion path begins with convincing the right person to trust the wrong request.
Analyst Snapshot // Intelligence Brief
Financially Motivated Threat Group
Financial extortion, ransomware deployment, and data theft
Social engineering, SIM swapping, MFA fatigue attacks, help desk impersonation, credential theft, and lateral movement
Telecommunications providers, casinos, cloud service providers, retail organizations, and large enterprises
Intermediate–Advanced
Background
Scattered Spider has been associated with financially motivated intrusions that rely heavily on social engineering and identity abuse. Their activity often focuses on gaining access by manipulating people, processes, and authentication workflows.
Common tactics
- Help desk impersonation
- MFA fatigue attacks
- SIM swapping
- Credential theft
- Social engineering through phone calls and messaging platforms
Why identity is central
Scattered Spider shows why identity security is one of the most important parts of modern defense. If attackers can convince a help desk to reset credentials, approve access, or bypass normal procedures, technical controls can be weakened by process failures.
This makes training, verification procedures, conditional access, monitoring, and strong escalation processes critical.
Defensive lessons
- Train help desk teams to verify identity before resetting access.
- Monitor repeated MFA prompts and suspicious authentication patterns.
- Use phishing-resistant MFA where possible.
- Limit access based on role and least privilege.
- Document escalation paths for suspicious access requests.
Why this matters for CTI
Scattered Spider is important for CTI because it highlights the overlap between technical intrusion, identity abuse, and human manipulation.
This actor shows that cyber defense cannot focus only on tools. It also has to account for people, policies, help desk workflows, and attacker behavior.
Millie's Perspective
Scattered Spider is one of the strongest examples of how social engineering can bypass strong technical controls. I recommend studying the human side of the intrusion path.
Key Takeaways
- Identity-focused attacks can be highly effective.
- Help desk impersonation remains a serious attack path.
- MFA fatigue exploits human behavior.
- Verification procedures matter.
- Security teams must protect both systems and processes.
Project Repository
Interested in the complete project, lab documentation, or research notes? Explore the full repository on GitHub.
View on GitHub →