Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
    • Site Check
  • Data
    • Ransomware statistics
    • Ransom payment rate
  • Newsletter
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Security

Scattered Spider in 2026: still the SIM-swap kings

Ransomnews Research TeamBy Ransomnews Research TeamMay 3, 2026No Comments3 Mins Read892 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
A spider silhouette spread over a network diagram with telecom and SIM-card icons connected by red threads
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Scattered Spider, also tracked as UNC3944, Octo Tempest, and 0ktapus, has been one of the most operationally aggressive English-speaking threat groups since 2022. The 2024 arrests of several alleged members and the disruption of their RaaS partner ALPHV did not break the group. They are still landing major incidents in 2026, with a playbook that combines social engineering, SIM-swap attacks, and extortion partnerships across multiple ransomware brands.

The signature TTP: voice-based help-desk social engineering

The thing Scattered Spider is best at, and the reason their attacks keep landing, is voice-based social engineering against IT help desks. They call in pretending to be an employee, claim a lost device, and convince the help desk to reset the user’s MFA. From there it’s a normal Active Directory escalation. The conversation is cordial, professional, and convincing enough that experienced help desk agents fall for it.

The defense against this is straightforward in concept: out-of-band verification before any MFA reset. The defense is hard in practice because the help desk’s KPI is “time to resolution” and the procedure that catches Scattered Spider also slows down legitimate users. The organisations that have done it well treat MFA reset as an authorisation event, not a service event.

SIM-swap as the second leg

Where the help-desk approach fails, SIM-swap fills the gap. Scattered Spider operators have ongoing relationships with insiders at the major US carriers and with SIM-swap-as-a-service providers operating from Telegram. The operational pattern: identify the target, port the target’s number to a SIM the attacker controls, intercept the SMS-based MFA codes, take over the account.

The mitigation here is removing SMS as an MFA factor anywhere it still exists. SMS is dead as authentication; carriers cannot reliably protect their own port-out flows; the only sustainable solution is to not depend on the phone number at all.

// Free tool

How does your own site score?

Run the same forty passive checks against your own domain — TLS and certificates, security headers, SPF and DMARC, cookies before consent, and what your stack quietly reveals. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

Targeting that hasn’t changed

The group’s targeting in 2026 looks structurally similar to 2023. Hospitality, gaming, and telecom remain disproportionately represented. SaaS companies whose customer-data is valuable for downstream attacks are a steady target. The 2025-2026 incidents we’ve reviewed include several casino properties, a multi-brand restaurant chain, and three different US-listed retailers.

The post-ALPHV arrangement

After ALPHV’s exit, Scattered Spider partnered with whichever ransomware brand had the right combination of payout structure and infrastructure. They’ve been linked to RansomHub deployments, Akira deployments, and at least one custom-tooling operation that didn’t carry a public brand at all. The group is best understood as a stable team of intrusion specialists who attach to whichever ransomware program is paying.

Detection priorities for 2026

Three things to watch. Help-desk audit logs for MFA reset events that don’t have corresponding ticket numbers in your ITSM tool. Identity logs for impossible-travel after MFA reset (the attacker’s location is rarely the user’s location). VPN logs for unusual ASN combinations in newly-authorised devices, especially residential proxy ranges Scattered Spider routinely uses.

The arrests didn’t end them

The 2024 indictments and the 2025 follow-up arrests removed several alleged operators. The group’s TTPs persisted. The English-speaking threat actor pool that supplies Scattered Spider operatives, gaming-adjacent communities, SIM-swap subcultures, COM-tagged Telegram groups, remains active and recruits new participants faster than law enforcement removes them. Expect Scattered Spider, or its successors operating under different names, to remain prominent through 2026 and beyond.

The Ransomnews Monthly

One email a month. Original leak-site data, victim census updates, and the findings that did not make the articles. No spam, unsubscribe any time.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleWhy double extortion isn’t enough anymore: the rise of triple and quadruple extortion
Next Article RansomHub explained: the post-LockBit consolidator
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Best VirusTotal alternatives 2026: what threat hunters run

August 9, 2026

SOAR vs SIEM 2026: tune before you automate

August 6, 2026

SIEM vs XDR 2026: retention is the deciding factor

August 6, 2026

Comments are closed.

// The Ransomnews Monthly

What leaked, what held up

One email a month: the datasets we verified, and the ones that fell apart under scrutiny.

Double opt-in. We store your email, signup time, and IP for consent records (GDPR Art. 7). See our privacy policy.

// Free tool

How does your own site score?

Forty passive checks on TLS, security headers, email spoofing and privacy. A grade out of 100 in about fifteen seconds.

No signup. Nothing installed. We only request what your site already serves publicly.

// Free tool

Were you in a leak?

Check whether an email address has surfaced in infostealer logs. No signup, no data stored.

Run StealerCheck

// Live data

Ransomtracker

Victims as they are posted to ransomware leak sites, tracked continuously and checked against the claims.

Open the tracker

9,520 confirmed attacks tracked

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker
  • Site Check

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.