Executive Summary
In September 2024, UK authorities arrested two teenagers, Thalha Jubair and Owen Flowers, for their significant roles in numerous cyberattacks attributed to the Scattered Spider gang—a notorious offshoot of The Com collective. Operating since at least May 2022, the pair leveraged social engineering techniques to infiltrate a range of organizations, including Transport for London, U.S. critical infrastructure, healthcare providers, and the federal court system. They stole and encrypted sensitive data, then demanded ransom payments, netting at least $115 million from 47 U.S. victims alone. Cryptocurrency wallets tied to the suspects were seized, totaling over $36 million, and both face serious charges on both sides of the Atlantic.
This incident illustrates the growing threat from young, highly skilled ransomware groups utilizing sophisticated extortion tactics. As extortion and identity-driven ransomware evolve, organizations—especially those in critical industries—face increasing pressure to bolster defenses against lateral movement and social engineering-based breaches.
Why This Matters Now
The arrest underscores an urgent need for organizations to address rising social engineering and ransomware threats, which are increasingly driven by young actors leveraging multi-vector attacks. With critical national infrastructure now routinely targeted, businesses face escalating regulatory scrutiny and operational risks—making modern Zero Trust policies and advanced threat detection essential.
Attack Path Analysis
The attackers initiated compromise through social engineering targeting user accounts, leading to unauthorized access. They then escalated privileges within cloud and enterprise environments, leveraging stolen credentials or misconfigured IAM roles. Once inside, the adversaries moved laterally, accessing additional services and workloads, including healthcare and critical infrastructure targets. Establishing command and control channels, they maintained persistent remote access while evading detection. Large volumes of sensitive data were exfiltrated, often encrypted in transit to external locations for extortion. Finally, ransomware was deployed, data encrypted, and victims extorted for ransom payments, causing widespread impact and disruptions.
Kill Chain Progression
Initial Compromise
Description
Attackers used social engineering techniques, such as phishing, to obtain valid credentials or impersonate authorized users, enabling unauthorized cloud and network access.
Related CVEs
CVE-2023-20867
CVSS 9.8An authentication bypass vulnerability in VMware ESXi allows a remote attacker to execute arbitrary code.
Affected Products:
VMware ESXi – 7.0, 8.0
Exploit Status:
exploited in the wildCVE-2023-23397
CVSS 9.8A privilege escalation vulnerability in Microsoft Outlook allows an attacker to execute arbitrary code.
Affected Products:
Microsoft Outlook – 2013, 2016, 2019, Office 365
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing
Valid Accounts
Resource Hijacking
Data Encrypted for Impact
Data Manipulation: Stored Data Manipulation
Exfiltration Over C2 Channel
Process Injection
Create Account
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Strong Authentication for Users and Administrators
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Article 10
CISA ZTMM 2.0 – Identify, Authenticate, and Authorize Identity
Control ID: Identity Pillar Level 3
NIS2 Directive – Risk Management Measures
Control ID: Article 21.2(a)
HIPAA Security Rule – Risk Analysis
Control ID: 164.308(a)(1)(ii)(A)
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Health Care / Life Sciences
Ransomware attacks targeting healthcare companies like SSM Health and Sutter Health demonstrate critical vulnerability to data encryption, patient record theft, and regulatory compliance violations.
Transportation
Transport for London attack showcases ransomware threats to critical transportation infrastructure, highlighting east-west traffic security gaps and potential for widespread operational disruption.
Government Administration
U.S. federal court system intrusion reveals ransomware vulnerability in government networks, emphasizing need for zero trust segmentation and enhanced threat detection capabilities.
Financial Services
Scattered Spider's $115 million ransom collection through cryptocurrency laundering exposes financial sector to money laundering schemes and encrypted traffic exploitation for illicit transfers.
Sources
- UK arrests two teens accused of heavy involvement in yearslong Scattered Spider attack spreehttps://cyberscoop.com/scattered-spider-teenagers-arrested-uk/Verified
- CISA and Partners Release Updated Advisory on Scattered Spider Grouphttps://www.cisa.gov/news-events/alerts/2025/07/29/cisa-and-partners-release-updated-advisory-scattered-spider-groupVerified
- Scattered Spider Threat Actor Profile: TTPs, IOCs & Attacks | Huntresshttps://www.huntress.com/threat-library/threat-actors/scattered-spiderVerified
- HC3: Threat Actor Profilehttps://www.aha.org/system/files/media/file/2024/10/hc3%20tlp%20clear%20threat%20actor%20profile%20scattered%20spider-10-24-2024.pdfVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, network and workload isolation, and egress controls available via CNSF capabilities would have significantly constrained the attack progression by limiting lateral movement, detecting anomalies, and restricting data exfiltration. Early detection, robust policy enforcement, and inline controls inhibit adversary movement and ransomware effectiveness within multi-cloud environments.
Control: Threat Detection & Anomaly Response
Mitigation: Detection of suspicious logins and rapid alerting on anomalous access.
Control: Zero Trust Segmentation
Mitigation: Limits risk from elevated permissions via least privilege and workload isolation.
Control: East-West Traffic Security
Mitigation: Blocks unauthorized service-to-service and internal lateral movement.
Control: Inline IPS (Suricata)
Mitigation: Detects and blocks known C2 signatures and malicious traffic.
Control: Egress Security & Policy Enforcement
Mitigation: Prevents data exfiltration to unauthorized destinations via FQDN and policy-based egress controls.
Limits attacker reach, enabling rapid containment and minimizing business impact.
Impact at a Glance
Affected Business Functions
- Operations
- Customer Service
- Financial Transactions
Estimated downtime: 14 days
Estimated loss: $115,000,000
Personal identifiable information (PII) of customers and employees, including financial records and sensitive communications, were exfiltrated and potentially exposed.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust segmentation and microsegmentation to strictly limit lateral movement across cloud workloads and environments.
- • Enforce strong egress filtering policies and encrypted traffic inspection to block unauthorized data exfiltration and C2 traffic.
- • Integrate anomaly-based threat detection and real-time incident response capabilities for rapid identification of credential abuse and abnormal behaviors.
- • Centralize multicloud visibility and control to uniformly apply policy and monitor traffic across all regions and platforms.
- • Regularly validate and test IAM configurations, permission boundaries, and network zones to ensure least privilege and compliance with Zero Trust principles.



