HomeSecurityScattered Spider hackers target US retail

Scattered Spider hackers target US retail

A new wave of cyberattacks appears to be hitting the United States retail sector, according to a new warning from Google. As reported by John Hultquist, head of threat analysis at Google Threat Intelligence Group, the attacks are attributed to the hacking group Scattered Spider (also known as UNC3944 and Octo Tempest), which is also responsible for recent attacks in the United Kingdom (Marks & Spencer, Co-Op, Harrods).

 hackers Scattered Spider retail in the US

The group appears to have shifted its focus to the US market, focusing on ransomware attacks and extortion campaigns. Their strategy involves targeting a single industry at a time , and all indications are that US retail is now in the crosshairs.

The Scattered Spider group has recently been linked to major attacks in the UK. Among the targets was Marks & Spencer (M&S), which was attacked with the DragonForce ransomware, which targeted virtual machines on VMware ESXi hosts.

See also: MirrorFace hackers target Japan with ROAMINGMOUSE and ANEL

The group Co-op, confirming that cybercriminals had gained access to the data of former and current members. Finally, Harrods announced that on May 1 it had restricted internet access to prevent a possible intrusion into its network – an action considered an immediate response to a cyber threat, although a breach has not been officially confirmed.

The ongoing attacks indicate an organized and targeted campaign, with a clear intent to target leading retail chains. Experts say that organizations in the industry must strengthen their protection measures against one of the most persistent and technologically advanced cybercrime networks in recent years.

DragonForce Ransomware

All three attacks in the UK appear to have involved DragonForce. As BleepingComputer reveals, the hackers adopted social engineering methods similar to those used by the infamous Scattered Spider.

See also: Hackers hide ransomware in JPG images

DragonForce, which first emerged in late 2023, appears to be evolving rapidly, now expanding its “services” to a white-label ransomware-as-a-service (RaaS). This allows other criminal groups to leverage DragonForce’s infrastructure for their own attacks, further complicating accountability.

Following the attacks in the UK, the country's National Cyber ​​Security Council (NCSC) issued protection guidance for businesses, calling the attacks a "wake-up call" for the industry. It noted that no business is immune.

However, the NCSC has not yet confirmed whether the attacks are linked or if they are independent incidents (although the same methods were used at least at M&S ​​and Co-op).

The NCSC proposals are summarized in the following key points:

  • Strengthen connection monitoring with an emphasis on suspicious sources, such as home VPNs or unidentified endpoints, to detect and isolate potential threats.
  • Adopting multi-factor authentication (MFA) across all systems, without exceptions, to increase the difficulty of access by unauthorized users.
  • Continuous monitoring for suspicious activity, such as unrecognized logins or account breaches, especially those detected through Microsoft Entra ID Protection.
  • Regular auditing of administrative accounts (Domain, Enterprise and Cloud Admin), with the aim of confirming that they are only used by authorized personnel.
  • Review support procedures regarding password resets, ensuring strong authentication protocols are in place before access is granted.
Scattered Spider hackers target US retail

Who are the Scattered Spiders?

The Scattered Spider group , also known as 0ktapus, UNC3944, Scatter Swine, Starfraud , and Muddled Libra , is a coalition of attackers known for their highly sophisticated social engineering campaigns . Their arsenal includes techniques such as SMS phishing , SIM swapping , and multi-factor authentication (MFA) bombing attacks. The group has been linked to numerous attacks on large organizations worldwide.

See also: Turkish hackers exploited Output Messenger vulnerability

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Despite the widespread use of the term “Scattered Spider,” experts point out that this is a loose alliance of threat actors, united mainly by the common techniques they use.

John Hultquist highlights the threat: "These are particularly aggressive, inventive and effective hackers, who manage to bypass even mature security structures. Social engineering remains their most effective weapon.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS