#Scattered Spider
9 stories taggedScattered Spider.

Ransomware Gangs Are Now Paying Insiders to Unlock the Front Door
Criminal groups are bribing employees to hand over company access rather than hacking their way in. It is cheaper, faster, and harder to detect, and the insider threat problem is getting worse.

ShinyHunters Are Phoning Hospital Help Desks: Health-ISAC Sounds the Alarm
A wave of voice-phishing calls is tricking healthcare staff into handing over single sign-on access, and the data theft is following fast.

Two Scattered Spider Members Jailed in UK's Largest Ever Cybercrime Prosecution
Thalha Jubair and Owen Flowers each received five and a half years in prison for a 2024 attack on Transport for London that cost the city £29 million.

A Windows Device ID Helped Trace an Alleged Scattered Spider Hacker to a Jewelry Heist
Federal prosecutors say a single hardware identifier tied a May 2025 intrusion at a luxury retailer to the online accounts of a 19-year-old.

Scattered Spider Suspect, 19, Extradited From Finland to Chicago
Peter Stokes, a dual U.S.-Estonian citizen, faces conspiracy, intrusion and fraud charges tied to the loose-knit crew behind a string of high-profile enterprise breaches.

Week in Brief: Russia's Cellebrite Use, Five Eyes AI Warning, macOS Backdoor, Scattered Spider Pleas
State-backed mobile forensics against an activist, an intelligence alliance's AI advisory, a new Mac implant, and a cybercrime case moving toward sentencing.

Account Takeovers Still Outrunning Detection, Vendors Push Behavioral AI as Answer
Compromised credentials remain the cheapest entry point on criminal marketplaces. A new webinar argues behavioral models, not static rules, are the only way to close the gap.

The Service Desk Is the New Phishing Inbox
Help desks keep getting talked out of MFA resets. The fix is less about training and more about treating identity verification like an auth protocol.

Two Scattered Spider Members Plead Guilty as London Trial Opens
Thalha Jubair and Owen Flowers admitted roles in the TfL intrusion and a SIM-swap and SMS-phishing operation that turned harvested SSO credentials into nine-figure ransom payouts.