The Containment Era is here. →Explore

Executive Summary

In September 2024, UK authorities arrested two teenagers, Thalha Jubair and Owen Flowers, for their significant roles in numerous cyberattacks attributed to the Scattered Spider gang—a notorious offshoot of The Com collective. Operating since at least May 2022, the pair leveraged social engineering techniques to infiltrate a range of organizations, including Transport for London, U.S. critical infrastructure, healthcare providers, and the federal court system. They stole and encrypted sensitive data, then demanded ransom payments, netting at least $115 million from 47 U.S. victims alone. Cryptocurrency wallets tied to the suspects were seized, totaling over $36 million, and both face serious charges on both sides of the Atlantic.

This incident illustrates the growing threat from young, highly skilled ransomware groups utilizing sophisticated extortion tactics. As extortion and identity-driven ransomware evolve, organizations—especially those in critical industries—face increasing pressure to bolster defenses against lateral movement and social engineering-based breaches.

Why This Matters Now

The arrest underscores an urgent need for organizations to address rising social engineering and ransomware threats, which are increasingly driven by young actors leveraging multi-vector attacks. With critical national infrastructure now routinely targeted, businesses face escalating regulatory scrutiny and operational risks—making modern Zero Trust policies and advanced threat detection essential.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

These attacks highlighted insufficient lateral movement controls, lack of end-to-end encryption, and inadequate enforcement of Zero Trust principles, undermining compliance with HIPAA, PCI DSS, and NIST cybersecurity standards.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, network and workload isolation, and egress controls available via CNSF capabilities would have significantly constrained the attack progression by limiting lateral movement, detecting anomalies, and restricting data exfiltration. Early detection, robust policy enforcement, and inline controls inhibit adversary movement and ransomware effectiveness within multi-cloud environments.

Initial Compromise

Control: Threat Detection & Anomaly Response

Mitigation: Detection of suspicious logins and rapid alerting on anomalous access.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Limits risk from elevated permissions via least privilege and workload isolation.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Blocks unauthorized service-to-service and internal lateral movement.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Detects and blocks known C2 signatures and malicious traffic.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Prevents data exfiltration to unauthorized destinations via FQDN and policy-based egress controls.

Impact (Mitigations)

Limits attacker reach, enabling rapid containment and minimizing business impact.

Impact at a Glance

Affected Business Functions

  • Operations
  • Customer Service
  • Financial Transactions
Operational Disruption

Estimated downtime: 14 days

Financial Impact

Estimated loss: $115,000,000

Data Exposure

Personal identifiable information (PII) of customers and employees, including financial records and sensitive communications, were exfiltrated and potentially exposed.

Recommended Actions

  • Deploy Zero Trust segmentation and microsegmentation to strictly limit lateral movement across cloud workloads and environments.
  • Enforce strong egress filtering policies and encrypted traffic inspection to block unauthorized data exfiltration and C2 traffic.
  • Integrate anomaly-based threat detection and real-time incident response capabilities for rapid identification of credential abuse and abnormal behaviors.
  • Centralize multicloud visibility and control to uniformly apply policy and monitor traffic across all regions and platforms.
  • Regularly validate and test IAM configurations, permission boundaries, and network zones to ensure least privilege and compliance with Zero Trust principles.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image