/
Contención de ransomware

Scattered Spider: What Its Attacks Reveal About Network Posture

Scattered Spider shut down casino floors, froze hotel room keys, and stalled a major retailer for weeks. The people now being arrested for those attacks are teenagers and young adults.

The arrests close one chapter. But they don’t change what made the attacks work. Scattered Spider got in through people: a phone call, a help desk, and one employee identity were often enough. From there, the damage came down to one question: how far could that identity reach? That’s a network posture question, and the answer is set long before an attacker calls.

Hackers who grew up online

Scattered Spider has an unusual origin story. CrowdStrike researchers trace parts of its ecosystem to “the Com,” a sprawling online community that grew out of Minecraft and Roblox circles. Some moved from gaming into “griefing” — harassing other players and hacking one another.

The ecosystem grew darker from there. What began as online harassment grew into a marketplace where people could pay to have others harassed. CrowdStrike describes it as “violence as a service,” and it included swatting, bomb threats, and even in-person intimidation.

Others turned to cryptocurrency theft, where their skills in stolen access could quickly become stolen money. To reach crypto accounts, they became advanced in social engineering, identity theft, credential compromise, MFA bypass, and SIM swapping. Those same skills would later become central to Scattered Spider’s attacks on large companies.

“These are young threat actors who started out as teenagers, not necessarily wanting to be criminals,” said Christer Swartz, industry solutions director at Illumio. “They just sort of drifted into it because they could.”

Some of the same people later took part in the biggest ransomware attacks in years. One alleged member, a dual U.S.-Estonian citizen known as “Bouquet,” posted Snapchat photos of his cash, luxury watches, and a diamond “Hack the Planet” chain. The FBI later traced a Windows device ID that prosecutors say belongs to 19-year-old Peter Stokes. Stokes has been charged with conspiracy, computer intrusion, and fraud.

From SIM swapping to social engineering

By 2022, Scattered Spider’s hacking skills were aimed at businesses. They targeted telecom companies and business-process outsourcers with access to mobile carrier systems. A successful SIM swap could move a victim’s phone number to an attacker-controlled device, redirecting all the victim’s calls, texts, and SMS-based MFA.

That business model didn’t last. Telecom providers and call centers hardened their systems and access became more difficult to get. Scattered Spider then turned to video-game companies. The scheme was to steal source code and extort the owner: pay us, or we release your code to underground markets.

One attempt involved extorting a gaming company for its stolen anti-cheating source code. The gaming company wouldn’t pay, and underground buyers weren’t interested in the code. The scheme fizzled. In 2023 the group turned to ransomware. That’s where the money was.

From the help desk to the heart of the network

SIM swapping was an important step in Scattered Spider’s evolution. From it, the group became skilled at impersonating employees and manipulating IT help desks. CrowdStrike found attackers who researched victims in detail. They used local-looking phone numbers, adopted accents, and stayed on calls for 45 minutes or longer. Across hundreds of recorded vishing calls, researchers identified seven recurring voices that used different names and personas.

The 2023 MGM attack showed how far that kind of access could go. Scattered Spider used social engineering to get into the network, then moved deeper into the environment. The attack ultimately disrupted slot machines, ATMs, digital room keys, and payment systems. MGM told the SEC the incident would cut about $100 million from third-quarter earnings.

The M&S breach showed the same pattern with even greater depth. Attackers reportedly impersonated employees and convinced the IT help desk to reset passwords, giving the attackers a foothold inside the network. From there, they worked their way to Active Directory and stole the NTDS.dit. It stores all the domain information, including user accounts, group memberships, computer objects, and critical password hashes.

The attackers used DragonForce, a ransomware-as-a-service operation. It gives affiliates the tools to encrypt systems and extort victims. That access became a wide outage. M&S stopped taking online clothing and home orders for nearly seven weeks.

Scattered Spider: A timeline of changing tactics

  • 2022 — SIM swapping at scale
    Scattered Spider hijacked phone numbers at telecom providers and call centers, which let it intercept MFA codes.
  • August 2023 — The help desk becomes the front door
    Social engineering against an outsourced IT vendor got attackers into Caesars Entertainment. It reportedly paid about $15 million.
  • September 2023 — One identity, the whole floor
    The same approach at MGM Resorts reached slot machines, ATMs, and room keys. MGM told the SEC it expected a $100 million hit to third-quarter earnings.
  • 2024 — The move to cloud and SaaS
    Stolen credentials replaced malware. Attackers took data from online business applications and demanded payment, often without ransomware.
  • April 2025 — Ransomware as the finish
    At Marks & Spencer, help desk social engineering reached Active Directory, and DragonForce did the rest. M&S said it expected the attack to cut operating profit by about £300 million before mitigation.
  • Mid-2025 — The playbook goes portable
    Insurance and aviation followed in turn. The entry point stayed the same: a call to the help desk.

Each new business model made them more dangerous

Scattered Spider’s tactics kept changing, but each pivot added new skills. Social engineering led to identity compromise. Identity compromise opened paths into cloud, SaaS, and critical infrastructure. Ransomware became a way to monetize their access.

AI may be making that adaptation even faster. CrowdStrike researchers say they have seen Scattered Spider deploy scripts with signs of LLM generation. AI could help the group work more quickly through unfamiliar systems.

Recent arrests may disrupt the people behind some of these attacks. But the playbook remains.

Find the paths that should not exist

Network posture matters. Defenders need to know which systems can communicate and which ones actually should. A user device may technically be able to reach Active Directory, a database, or a hypervisor. That doesn’t mean it needs to.

“The important distinction is between what can communicate and what should communicate,” Swartz said.

Those unnecessary paths are what attackers can turn into lateral movement. Visibility exposes them. Some lead somewhere that matters more than others.

Swartz points to Active Directory and hypervisors. “Hypervisors are probably as important as Active Directory,” he said. “If you compromise that foundation, you can do enormous damage.”

Active Directory, hypervisors, key DNS systems, and backups should be tightly controlled. Only the users and workloads that genuinely need access should reach them. Segmentation closes the rest.

Contain first, investigate second

Scattered Spider has shown how quickly an intrusion can become ransomware. That means containment can’t depend entirely on a person seeing an alert and deciding what to do next.

“You have to remove the human from the loop as much as possible,” Swartz said.

Teams should prepare quarantine policies and automate containment for high-confidence threats. If a workload starts behaving dangerously, isolate it first. Investigate once the spread has been stopped.

Swartz compares it to pulling a fire alarm: you may not know exactly what caused the smoke yet, but you don’t wait to stop the fire.

Test how far an attacker can go

The final lesson is to test the network from the attacker’s point of view.

Assume an identity has already been compromised. Then ask how far it can move. Can it reach Active Directory? VMware? Backups? Sensitive databases? Can defenders see that movement and stop it without disrupting the rest of the business?

“Assume that somebody can take over identity; look and see how much damage they can do,” Swartz said. “Think like the attacker. Break into your own environment and find those paths before somebody else does.”

The people and tactics may change. What changes the outcome is the answer to the question: how far can one stolen identity reach?

Ready to take the next step? See how Illumio Insights uses AI-powered Cloud Detection and Response to uncover lateral movement, risky traffic, AI-driven threats, and compliance gaps. Analyze your network posture score and prioritize what to segment next.

Watch the Illumio Insights demo.

,

Artículos relacionados

Experimente Illumio Insights hoy

Vea cómo la observabilidad impulsada por IA le ayuda a detectar, comprender y contener amenazas más rápido.