Back Issues/Search Home → Calendar → Archive → Current Issue → Popular →

All issuesVolume 328, Issue 1IT Vendor NewsCyberArk

Scattered Spider Unmasked: How An Identity-Focused APT Is Redefining Cyber Threats

CyberArk, July 3,2025

Scattered Spider has emerged as one of the most disruptive advanced persistent threats in recent years, breaching major organizations across telecom, gaming, transportation, and retail. In the last few months, the group has escalated its activity-targeting financial services and launching coordinated ransomware campaigns that have crippled operations and exposed sensitive data.

By exploiting identity systems and human workflows rather than software flaws, Scattered Spider is forcing security teams to rethink how they protect access and privilege. What follows is a breakdown of the group's high-profile campaigns, evolving tactics, and the controls organizations can implement to help defend against identity-centric attacks.

Who (or what) is Scattered Spider?

Since at least mid-2022, Scattered Spider (also tracked as UNC3944, Storm-0875, Oktapus, among other aliases) has been a financially motivated advanced persistent threat (APT) that combines native-English social engineering with precise technical know-how. Its operators are predominantly young adults based in Western countries fluent in local dialects, enabling them to impersonate employees, support staff, and executives convincingly.

more →  ·  More from CyberArk →