Executive Summary
In 2025, U.K. and U.S. law enforcement charged members of the cybercrime group Scattered Spider, including Thalha Jubair and Owen Flowers, with a $115 million ransomware and extortion campaign targeting sectors such as retail, transportation, hospitality, and healthcare. The group, also known as 0ktapus and UNC3944, leveraged advanced social engineering, SIM-swapping, phishing, and remote access tactics to breach hundreds of organizations—including notorious attacks on MGM Resorts, Caesars Entertainment, Transport for London, and major U.K. retailers. Law enforcement tracked cryptocurrency ransoms to the group, seizing millions in illicit funds and identifying extensive operational overlap with LAPSUS$ and other threat collectives.
This incident highlights the escalating threat posed by young, identity-driven ransomware affiliates employing blended TTPs, exploiting cloud and hybrid infrastructures, and leveraging insider access. Their success in spanning critical infrastructure and commercial targets underscores the urgent need for multilayered defenses, compliance vigilance, and aggressive regulatory and incident response readiness.
Why This Matters Now
The Scattered Spider story exemplifies the convergence of ransomware, social engineering, and identity abuse in targeting critical infrastructure and cross-border victims. As regulatory requirements tighten in both the U.K. and U.S., organizations must rapidly mature network segmentation, credential controls, and threat detection capabilities to combat increasingly agile, well-funded threat actor collectives.
Attack Path Analysis
Scattered Spider initiated their attack through SMS phishing and SIM-swapping to compromise employee credentials and bypass MFA, giving initial network access. Leveraging compromised accounts, they escalated privileges via internal tools and gained administrative access. The attackers then moved laterally across cloud and corporate environments, exploiting remote access tooling and lack of east-west controls. They established command & control using covert channels and remote access tools. Sensitive data was exfiltrated through outbound channels, often hidden in legitimate traffic, before deploying ransomware to disrupt operations and extort ransom.
Kill Chain Progression
Initial Compromise
Description
The attackers used targeted SMS phishing (smishing) and SIM-swapping techniques to steal employee credentials and bypass multi-factor authentication for accessing cloud environments.
Related CVEs
CVE-2015-2291
CVSS 7.8A vulnerability in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service (system crash) via a crafted application.
Affected Products:
Intel Ethernet diagnostics driver for Windows – before 1.3.1.0
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Phishing: Spearphishing Attachment
Spearphishing Link
Brute Force: Credential Stuffing
Scheduled Task/Job: Scheduled Task
Valid Accounts
Exploitation for Credentials
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Multi-Factor Authentication (MFA) for All Access to the CDE
Control ID: 8.3.4
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA (EU Digital Operational Resilience Act) – ICT Risk Management Framework
Control ID: Chapter II, Article 8
CISA Zero Trust Maturity Model (ZTMM) 2.0 – Continuous Policy Enforcement and Adaptive Authentication
Control ID: Identity Pillar – Policy Enforcement
NIS2 Directive – Cybersecurity Risk-management Measures
Control ID: Article 21
ISO/IEC 27001:2022 – Access Rights
Control ID: A.5.18
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Telecommunications
Direct targeting of T-Mobile and AT&T systems via SIM-swapping and phishing attacks, compromising encrypted traffic and east-west security controls.
Hospitality
MGM Resorts and Caesars Entertainment ransomware attacks demonstrate vulnerability to social engineering and lateral movement within hospitality infrastructure systems.
Health Care / Life Sciences
Healthcare providers targeted by Scattered Spider face HIPAA compliance violations through compromised encrypted traffic and failed egress security controls.
Financial Services
SIM-swapping attacks targeting Chase Bank authentication and cryptocurrency theft totaling $115M expose critical vulnerabilities in zero trust segmentation.
Sources
- Feds Tie ‘Scattered Spider’ Duo to $115M in Ransomshttps://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/Verified
- Scattered Spider: A Threat Profilehttps://www.flashpoint.io/blog/scattered-spider-threat-profile/Verified
- HC3 Issues Warning About Scattered Spider Threat Actorhttps://www.hipaajournal.com/hc3-issues-warning-about-scattered-spider-threat-actor/Verified
- Scattered Spider: Threat Actor Profile - Cyblehttps://cyble.com/threat-actor-profiles/scattered-spider/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust network segmentation, east-west traffic security, and robust egress and anomaly controls would have significantly disrupted attacker lateral movement, command and control, and data exfiltration, limiting blast radius even after initial credential compromise.
Control: Multicloud Visibility & Control
Mitigation: Centralized visibility accelerates detection of abnormal login sources and credential use.
Control: Zero Trust Segmentation
Mitigation: Identity- and role-based isolation hampers privilege elevation paths.
Control: East-West Traffic Security
Mitigation: Lateral movement is blocked between critical workloads and segments.
Control: Threat Detection & Anomaly Response
Mitigation: Suspicious remote connections and beaconing behavior are rapidly detected and alerted.
Control: Egress Security & Policy Enforcement
Mitigation: Unapproved outbound flows and large data movements are detected and blocked.
Inline policies and real-time inspection limit ransomware's reach and effectiveness.
Impact at a Glance
Affected Business Functions
- Customer Service
- Payment Processing
- Online Reservations
Estimated downtime: 14 days
Estimated loss: $100,000,000
Personal data of loyalty program members, including Social Security and driver's license numbers, were compromised.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust segmentation and microsegmentation to restrict lateral movement and contain breaches.
- • Enable continuous multicloud and hybrid environment visibility to rapidly identify anomalous user and service behavior.
- • Enforce robust east-west traffic security controls to block unauthorized internal pivots and workload-to-workload communications.
- • Implement comprehensive egress filtering and outbound policy enforcement to prevent data exfiltration and detect malicious C2 patterns.
- • Integrate real-time threat detection and anomaly response capabilities to identify remote access tools and unusual privileged activity early.



