Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
  • Reviews
    • Best antivirus software for 2026: independent picks from Ransomnews
    • Best ransomware-resistant backup for 2026: cloud, hybrid, and immutable picks reviewed
    • Best ransomware protection for business 2026: ESET PROTECT and 5 alternatives reviewed
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
  • Reviews
    • Best antivirus software for 2026: independent picks from Ransomnews
    • Best ransomware-resistant backup for 2026: cloud, hybrid, and immutable picks reviewed
    • Best ransomware protection for business 2026: ESET PROTECT and 5 alternatives reviewed
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Security

Scattered Spider in 2026: still the SIM-swap kings

Ransomnews Research TeamBy Ransomnews Research TeamMay 3, 2026No Comments3 Mins Read42 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
A spider silhouette spread over a network diagram with telecom and SIM-card icons connected by red threads
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Scattered Spider, also tracked as UNC3944, Octo Tempest, and 0ktapus, has been one of the most operationally aggressive English-speaking threat groups since 2022. The 2024 arrests of several alleged members and the disruption of their RaaS partner ALPHV did not break the group. They are still landing major incidents in 2026, with a playbook that combines social engineering, SIM-swap attacks, and extortion partnerships across multiple ransomware brands.

The signature TTP: voice-based help-desk social engineering

The thing Scattered Spider is best at, and the reason their attacks keep landing, is voice-based social engineering against IT help desks. They call in pretending to be an employee, claim a lost device, and convince the help desk to reset the user’s MFA. From there it’s a normal Active Directory escalation. The conversation is cordial, professional, and convincing enough that experienced help desk agents fall for it.

The defense against this is straightforward in concept: out-of-band verification before any MFA reset. The defense is hard in practice because the help desk’s KPI is “time to resolution” and the procedure that catches Scattered Spider also slows down legitimate users. The organisations that have done it well treat MFA reset as an authorisation event, not a service event.

SIM-swap as the second leg

Where the help-desk approach fails, SIM-swap fills the gap. Scattered Spider operators have ongoing relationships with insiders at the major US carriers and with SIM-swap-as-a-service providers operating from Telegram. The operational pattern: identify the target, port the target’s number to a SIM the attacker controls, intercept the SMS-based MFA codes, take over the account.

The mitigation here is removing SMS as an MFA factor anywhere it still exists. SMS is dead as authentication; carriers cannot reliably protect their own port-out flows; the only sustainable solution is to not depend on the phone number at all.

Targeting that hasn’t changed

The group’s targeting in 2026 looks structurally similar to 2023. Hospitality, gaming, and telecom remain disproportionately represented. SaaS companies whose customer-data is valuable for downstream attacks are a steady target. The 2025-2026 incidents we’ve reviewed include several casino properties, a multi-brand restaurant chain, and three different US-listed retailers.

The post-ALPHV arrangement

After ALPHV’s exit, Scattered Spider partnered with whichever ransomware brand had the right combination of payout structure and infrastructure. They’ve been linked to RansomHub deployments, Akira deployments, and at least one custom-tooling operation that didn’t carry a public brand at all. The group is best understood as a stable team of intrusion specialists who attach to whichever ransomware program is paying.

Detection priorities for 2026

Three things to watch. Help-desk audit logs for MFA reset events that don’t have corresponding ticket numbers in your ITSM tool. Identity logs for impossible-travel after MFA reset (the attacker’s location is rarely the user’s location). VPN logs for unusual ASN combinations in newly-authorised devices, especially residential proxy ranges Scattered Spider routinely uses.

The arrests didn’t end them

The 2024 indictments and the 2025 follow-up arrests removed several alleged operators. The group’s TTPs persisted. The English-speaking threat actor pool that supplies Scattered Spider operatives, gaming-adjacent communities, SIM-swap subcultures, COM-tagged Telegram groups, remains active and recruits new participants faster than law enforcement removes them. Expect Scattered Spider, or its successors operating under different names, to remain prominent through 2026 and beyond.

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleWhy double extortion isn’t enough anymore: the rise of triple and quadruple extortion
Next Article RansomHub explained: the post-LockBit consolidator
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Registrų centras breach: 600,000 records exposed

May 27, 2026

RDP attacks 2026: ransomware’s #1 entry vector

May 16, 2026

Alerts.bar review 2026: dark-web monitoring tested

May 12, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Reviews
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Affiliate Disclosure
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.