The cyber threat group Scattered Spider (or a group using its tactics) appears to be behind new cyberattackstargeting insurance companies in the United States.

Researchers at the Google Threat Intelligence Group (GTIG) recently identified multiple breaches bearing the “stamp” of this group, known for its use of sophisticated social engineering techniques.
The group is known for targeting a specific sector at a time. It previously attacked retail businesses in the UK, before shifting its focus to similar organizations in the US. Now, it appears to be targeting the insurance industry in the US.
Particular attention is recommended to help desks and call centers, which are often entry points for social engineering attacks.
See also: FIN6 hackers target recruiters
Who are the Scattered Spiders?
Scattered Spider, also known by the aliases 0ktapus, UNC3944, Starfraud, Muddled Libra and others, is not a single entity, but a flexible coalition of hackers that uses techniques such as phishing, SIM swapping and MFA fatigue attacks to gain access to high-profile organizations.
In more advanced stages of their attacks, they have been observed using ransomware such as RansomHub, Qilin, and DragonForce.
Why hackers target insurance companies?
Insurance companies are significant targets for several reasons:
- Valuable personal data: They handle vast volumes of sensitive information — from medical records and financial data to customer identification data.
- Relatively lower cyber maturity: Many insurers have not reached the same level of cyber defense as technology or financial services organizations, making them easier targets.
- Strong incentive to pay ransom: The need for business continuity and maintaining customer trust leads many companies to quickly comply with ransom demands — especially if the attacks threaten confidentiality or functionality.
Cyberspace is no longer «IT problem». It is an existential risk for every business. Organizations that do not recognize this in time will become the next front pages.
See also: Marks & Spencer: Hackers sent threatening email to CEO

Defense proposals
GTIG recommends that companies adopt security practices, starting with full visibility across their entire infrastructure. Particular emphasis is placed on identity management, the use of multi-factor authentication (MFA) and tightening processes such as password resets.
Privilege separation and the implementation of strong authentication controls are considered critical steps to protect against the increasingly sophisticated methods of Scattered Spider.
As we mentioned earlier, hackers heavily use social engineering techniques, so organizations are urged to invest in training employees and security teamsto recognize impersonation attempts that appear via SMS, phone calls, or popular messaging apps. Often, attackers use an aggressive tone to exert psychological pressure on the victim and ensure cooperation.
The UK has already been targeted by the Scattered Spider group, with recent breaches targeting major retailers such as Marks & Spencer, Co-op and Harrods. In all incidents, the attackers followed the same social engineering tactic and, in the final stage, activated the DragonForce.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Hackers exploit old AT&T data breach
In response, the United Kingdom's National Cyber Security Centre (NCSC) issued guidance to businesses to strengthen their defensive mechanisms. Among the proposals are:
- Enable two- or multi-factor authentication (2FA/MFA)
- Detection of unauthorized connections
- Strict access control to high-privilege accounts such as Domain Admin, Enterprise Admin, and Cloud Admin
The NCSC also highlights the importance of securely handling password reset from help desks, especially when they involve users with elevated privileges. Additionally, organizations are urged to monitor for suspicious activity, such as connections from VPN services that appear to originate from homes or other unusual locations, to quickly identify potential intrusions.
Source: www.bleepingcomputer.com
