Executive Summary
In 2025, the cybercriminal group Scattered Spider executed a series of sophisticated voice phishing attacks targeting major corporations, including technology firms and critical infrastructure providers. By impersonating employees and IT staff over the phone, they manipulated help desks into resetting credentials, granting them unauthorized access to sensitive systems. This method led to significant data breaches, operational disruptions, and financial losses for the affected organizations. The rise of such interactive phishing techniques underscores a shift in cyberattack strategies, emphasizing the exploitation of human vulnerabilities over technical exploits. As traditional phishing methods decline, the increasing prevalence of voice-based social engineering attacks highlights the need for enhanced security awareness and robust verification processes within organizations.
Why This Matters Now
The surge in voice phishing attacks by groups like Scattered Spider in 2025 highlights the urgent need for organizations to strengthen their defenses against sophisticated social engineering tactics. As attackers increasingly exploit human vulnerabilities, it's imperative to implement comprehensive security awareness training and robust verification processes to mitigate these evolving threats.
Attack Path Analysis
The adversary initiated the attack by conducting voice-based phishing (vishing) to deceive employees into divulging credentials. Using the obtained credentials, the attacker escalated privileges to gain higher-level access within the network. Subsequently, the adversary moved laterally across the network to identify and access sensitive data. They established command and control channels to maintain persistent access and exfiltrated sensitive data to external servers. Finally, the attacker leveraged the exfiltrated data for financial gain, such as extortion or sale on dark web marketplaces.
Kill Chain Progression
Initial Compromise
Description
The adversary conducted voice-based phishing (vishing) to deceive employees into divulging credentials.
Related CVEs
CVE-2025-31324
CVSS 9.8An unrestricted file upload vulnerability in SAP NetWeaver allows authenticated remote attackers to execute arbitrary code.
Affected Products:
SAP NetWeaver – 7.5
Exploit Status:
exploited in the wildCVE-2025-61882
CVSS 9.8A vulnerability in Oracle E-Business Suite allows unauthenticated attackers to compromise Oracle Configurator, leading to unauthorized access to critical data.
Affected Products:
Oracle E-Business Suite – 12.2.3, 12.2.4, 12.2.5, 12.2.6, 12.2.7, 12.2.8, 12.2.9, 12.2.10, 12.2.11, 12.2.12, 12.2.13, 12.2.14
Exploit Status:
exploited in the wildCVE-2025-53770
CVSS 9.8A deserialization of untrusted data vulnerability in Microsoft SharePoint allows remote attackers to execute arbitrary code.
Affected Products:
Microsoft SharePoint Server – 2013, 2016, 2019
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Spearphishing Voice
Spearphishing Voice
Valid Accounts
Valid Accounts
Valid Accounts
Valid Accounts
Valid Accounts
Valid Accounts
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Security Awareness Training
Control ID: 6.4.3
NYDFS 23 NYCRR 500 – Cybersecurity Awareness Training
Control ID: 500.14(b)
DORA – ICT Risk Management Framework
Control ID: Article 13
CISA ZTMM 2.0 – User Training and Awareness
Control ID: Pillar 1: Identity
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Information Technology/IT
Voice phishing targeting IT help desks exploits social engineering vulnerabilities, bypassing traditional email security controls and compromising privileged access credentials.
Financial Services
Second-most targeted sector faces elevated voice phishing risks targeting customer service representatives, potentially compromising sensitive financial data and payment systems.
Health Care / Life Sciences
Fourth-most attacked industry vulnerable to voice-based social engineering targeting medical staff, risking HIPAA violations and patient data exposure through compromised systems.
Computer Software/Engineering
Most frequently attacked sector experiencing 17% of incidents, with voice phishing exploiting developer environments and compromising software supply chain security.
Sources
- The phone call is the new phishing emailhttps://cyberscoop.com/social-engineering-surge-intrusion-vector-mandiant-m-trends/Verified
- M-Trends 2025 Reporthttps://www.mandiant.com/resources/reports/m-trends-2025Verified
- CISA Known Exploited Vulnerabilities Cataloghttps://www.cisa.gov/known-exploited-vulnerabilities-catalogVerified
- Oracle Security Alert for CVE-2025-61882https://www.oracle.com/security-alerts/alert-cve-2025-61882.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust Cloud Native Security Fabric (CNSF) is pertinent to this incident as it could have constrained the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-aware access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not prevent credential disclosure via phishing, it could limit the attacker's subsequent network access, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could limit the attacker's ability to escalate privileges by enforcing strict access controls, reducing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could restrict lateral movement by controlling and monitoring internal traffic, thereby limiting the attacker's ability to traverse the network.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could detect and limit unauthorized command and control communications, reducing the attacker's ability to maintain persistent access.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could limit data exfiltration by controlling and monitoring outbound traffic, reducing the risk of unauthorized data transfer.
With Aviatrix controls in place, the attacker's ability to exfiltrate data would likely be constrained, reducing the potential for financial exploitation.
Impact at a Glance
Affected Business Functions
- Enterprise Resource Planning (ERP)
- Customer Relationship Management (CRM)
- Document Management
Estimated downtime: 14 days
Estimated loss: $5,000,000
Confidential business data, customer information, and internal communications.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within the network.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic, preventing unauthorized access between workloads.
- • Utilize Multicloud Visibility & Control solutions to gain comprehensive insights into network activities and detect anomalies.
- • Enforce Egress Security & Policy Enforcement to control outbound traffic and prevent data exfiltration to unauthorized destinations.
- • Conduct regular user training on recognizing and reporting social engineering attempts, including voice-based phishing attacks.



