Cyber‑threat actors known as Scattered Spider (also tracked as UNC3944, Scatter Swine, Starfraud) are being attributed to a wave of high-impact cyberattacks targeting major UK retailers and U.S. financial and insurance firms, according to recent intelligence briefings.


🕷️ Who is Scattered Spider?

Scattered Spider is a loosely affiliated hacking collective primarily composed of tech-savvy teens and young adults operating across the U.K., U.S., Canada, and other Western countries Unlike more technically advanced ransomware syndicates, the group relies heavily on social engineering, including impersonating IT support, MFA fatigue (“MFA bombing”), SIM-swapping, and phishing calls to help desks

They first surfaced in high-profile attacks on MGM Resorts and Caesars Entertainment in Las Vegas (2023), where help-desk impersonation enabled them to deploy ransomware and disrupt operations


📉 UK Retail Meltdown: M&S & Co-op Hit Hard

In April 2025, UK retail giants Marks & Spencer and Co-op were struck in what security analysts classified as a single, coordinated cyber incident. The Cyber Monitoring Centre estimated combined damages between £270 million ($363 million) and £440 million ($592 million)

Investigators linked the breaches via similar timelines, tactics, and Scattered Spider activity . The hackers gained initial entry by targeting IT help desks and using phishing to extract credentials.


↗️ New Focus: U.S. Insurance Industry

Following UK attacks, Google’s Threat Intelligence Group (GTIG) reported that Scattered Spider has begun targeting U.S. insurance firms. According to GTIG chief analyst John Hultquist, the group follows a pattern of concentrating on a specific sector at once—now, their sights are on insurers

GTIG has detected “multiple intrusions in the U.S. which bear all the hallmarks of Scattered Spider activity” . Their methods include sophisticated social engineering tactics against help desks and managed service providers (MSPs)


🛡️ Aflac Breach Highlights Real-world Impact

The Aflac attack, disclosed June 12 and halted within hours, demonstrates the gravity of the threat. Intruders accessed sensitive records—Social Security numbers, claim details, and health data—via social engineering, though ransomware was not deployed

Sources indicate the attack aligns with Scattered Spider’s MO, part of a broader spree also affecting Erie Insurance and Philadelphia Insurance firms . Aflac engaged cybersecurity experts and followed SEC reporting guidelines, but the full extent of the breach is still under investigation


💥 Tactics & Trends: Why This Threat Matters

Scattered Spider operates as a fluid coalition within “The Community” of cybercriminals, sometimes linked to ransomware groups like DragonForce or ALPHVTheir primary TTPs include fake vendor domains, MFA bypass, fraudulent password resets, and calls to help-desks—95% via social engineering, not code exploits

By targeting MSPs and vendor supply chains, they’ve gained a wider sphere to infiltrate major organizations . Security analysts warn that they adapt quickly—focusing on whichever sector offers the most entry points and low resistance .


🚨 Takeaways: How Organizations Should Respond

1. Harden help desks & identity channels – Use strong caller verification, limit MFA resets via phone.
2. Monitor authentication – Watch for MFA fatigue tactics and unauthorized device registrations.
3. Segregate MSP/vendor access – Enforce strict least-privilege policies on third-party accounts.
4. Conduct social-engineering drills – Regular simulated phishing and help-desk training.
5. Enforce MFA everywhere – Particularly for access to email, admin portals, and systems management.

Given Scattered Spider’s ongoing evolution, organizations must prioritize both identity security and employee training.


🧭 Conclusion

Scattered Spider is proving to be a disruptive force in both retail and financial sectors, moving from major UK retailers to U.S. insurers through refined social engineering. Their youth-driven, agile approach complicates attribution and enforcement, particularly across jurisdictions. As attacks continue, cybersecurity leaders must harden identity systems and help-desk protocols while treating social engineering as a top-tier threat.

Please subscribe to the Newsletter so that you do not miss any critical update

Leave a Reply

Your email address will not be published. Required fields are marked *