← Back to Intelligence Library

Threat Intelligence • Threat Actor Profile

The Scattered Spider Profile

A cybercriminal actor known for social engineering, SIM swapping, help desk impersonation, and MFA fatigue attacks.

CTI FocusSocial EngineeringIdentity AbuseMFA Fatigue

Last Updated: July 2026

Scattered Spider is a cybercriminal actor known for identity-focused attacks, social engineering, help desk impersonation, SIM swapping, and MFA fatigue techniques.

Studying Scattered Spider is a reminder that attackers do not always need advanced malware to create serious impact. Sometimes the intrusion path begins with convincing the right person to trust the wrong request.

Analyst Snapshot // Intelligence Brief

Threat Type

Financially Motivated Threat Group

Primary Motivation

Financial extortion, ransomware deployment, and data theft

Primary Tactics

Social engineering, SIM swapping, MFA fatigue attacks, help desk impersonation, credential theft, and lateral movement

Primary Targets

Telecommunications providers, casinos, cloud service providers, retail organizations, and large enterprises

Analyst Level

Intermediate–Advanced

Background

Scattered Spider has been associated with financially motivated intrusions that rely heavily on social engineering and identity abuse. Their activity often focuses on gaining access by manipulating people, processes, and authentication workflows.

Common tactics

  • Help desk impersonation
  • MFA fatigue attacks
  • SIM swapping
  • Credential theft
  • Social engineering through phone calls and messaging platforms

Why identity is central

Scattered Spider shows why identity security is one of the most important parts of modern defense. If attackers can convince a help desk to reset credentials, approve access, or bypass normal procedures, technical controls can be weakened by process failures.

This makes training, verification procedures, conditional access, monitoring, and strong escalation processes critical.

Defensive lessons

  • Train help desk teams to verify identity before resetting access.
  • Monitor repeated MFA prompts and suspicious authentication patterns.
  • Use phishing-resistant MFA where possible.
  • Limit access based on role and least privilege.
  • Document escalation paths for suspicious access requests.

Why this matters for CTI

Scattered Spider is important for CTI because it highlights the overlap between technical intrusion, identity abuse, and human manipulation.

This actor shows that cyber defense cannot focus only on tools. It also has to account for people, policies, help desk workflows, and attacker behavior.

Millie's Perspective

Scattered Spider is one of the strongest examples of how social engineering can bypass strong technical controls. I recommend studying the human side of the intrusion path.

Key Takeaways

  • Identity-focused attacks can be highly effective.
  • Help desk impersonation remains a serious attack path.
  • MFA fatigue exploits human behavior.
  • Verification procedures matter.
  • Security teams must protect both systems and processes.

Project Repository

Interested in the complete project, lab documentation, or research notes? Explore the full repository on GitHub.

View on GitHub →