Threat Intelligence
scattered-spider
unc3944
ingenieria-social

Scattered Spider: Help Desk Social Engineering and Account Takeover

Who Scattered Spider (UNC3944) is, how it uses help desk social engineering, MFA resets and SIM swapping, and how to defend your organisation identity.

Secra Solutions teamJuly 26, 202612 min read

Scattered Spider is a financially motivated threat group that has turned the telephone into its primary intrusion tool. Instead of exploiting a technical vulnerability, they call the help desk posing as employees and convince an agent to reset the victim's password or MFA. That access to identity opens the door to the corporate network, data theft and, frequently, ransomware deployment. Understanding how they operate is the first step to hardening your IT support.

This article explains who Scattered Spider (tracked as UNC3944) is, what techniques it uses to deceive IT support and compromise accounts, why its approach is so effective even against organisations with MFA in place, and what concrete defences you can apply to your identity verification process, phishing-resistant authentication and identity threat detection.

Key takeaways

  • It is a financially motivated group known for aggressive social engineering and for including native English speakers who converse naturally with support staff.
  • Its signature technique is help desk social engineering: they call posing as employees to force a password or MFA reset.
  • They complement that vector with MFA fatigue (push bombing), SIM swapping and phishing, including AiTM.
  • After initial access they escalate privileges rapidly, steal data and deploy ransomware, collaborating with Ransomware-as-a-Service operations.
  • They have been linked to high-profile breaches in casinos and hospitality, retail, airlines and insurers.
  • Defence rests on hardening identity verification, adopting phishing-resistant MFA and deploying ITDR.

Who Scattered Spider (UNC3944) is

Scattered Spider is a financially motivated cybercriminal collective. Different intelligence vendors track it under aliases such as UNC3944, Octo Tempest, Muddled Libra and Scatter Swine. What sets this group apart from many traditional threat actors is not an exotic technical arsenal but its mastery of human manipulation and the fact that it includes native English speakers able to hold a credible conversation with a support agent without raising suspicion through accent or language errors.

That fluency is a weapon. An attacker who calls the help desk and sounds like just another employee, who knows the internal jargon and answers with ease, has a much higher chance of convincing the person on the other end of the line. Scattered Spider has industrialised that model: instead of investing weeks looking for a flaw in the perimeter, they invest minutes in a well-prepared phone call.

Why the human factor works so well for them

Most organisations have hardened their technical defences: they patch, segment and deploy MFA. But the account recovery process usually remains the weak link. When an employee says they have lost their phone or cannot log in, the support agent wants to help and unblock the situation as quickly as possible. Scattered Spider exploits precisely that goodwill. To understand the underlying mechanics, it helps to review what social engineering is and how deception targets people, not machines.

The signature technique: help desk social engineering

Scattered Spider's characteristic vector is the call to the help desk or IT support. The attacker poses as a legitimate employee, often after gathering prior information about the victim (name, role, email, perhaps part of the employee identifier) from open sources or previous leaks. With that context, they contact support and present an urgent problem: they cannot log in, they have lost their MFA device or they need to restore access before an important meeting.

The specific goal of the call is to get the agent to perform one of two actions: reset the account password or reset the second authentication factor, for example by enrolling a new device or phone number controlled by the attacker. If the help desk does not require strong, out-of-band identity verification, the agent fulfils the request in good faith and, at that instant, the attacker takes control of the account.

Password and MFA resets

Resetting the password alone may not be enough if the account is protected with MFA. That is why the MFA reset is the real prize. When the attacker gets a new factor enrolled under their control, multifactor protection turns against the victim: now the attacker holds the second factor. This is why MFA enrolment and reset should be treated as high-risk operations, not routine formalities. If you want to understand the model being abused, review what MFA is and which factors better resist this type of manipulation.

The role of vishing

A good part of these intrusions begins by voice. Vishing (voice phishing) is the natural channel for help desk social engineering because it lets the attacker improvise, apply pressure and project urgency in real time, something far harder over email. An experienced attacker adjusts their tone, answers verification questions on the fly and conveys the sense that there is a crisis to solve. We go deeper into this channel in our guide on what vishing is and how it affects businesses.

Other techniques in the arsenal

Help desk social engineering is the hallmark, but Scattered Spider combines several vectors depending on what each intrusion requires.

MFA fatigue and push bombing

When the attacker already knows the victim's password (through phishing, credential reuse or purchase on underground markets), they can launch a wave of MFA push notifications to the employee's device. This technique, known as MFA fatigue or push bombing, aims to exhaust the victim's patience until they accept one of the requests just to make them stop. A single approval is enough for the attacker to get in. That is why number matching, which forces the user to enter a number shown on the login screen, is such a valuable countermeasure: it turns a reflexive tap into a deliberate action.

SIM swapping

SIM swapping involves deceiving or bribing a telecommunications operator into transferring the victim's phone number to a SIM controlled by the attacker. Once the number is in their hands, any MFA code sent by SMS or any verification call goes straight to the attacker. It is one of the reasons SMS-based MFA is considered weak against determined adversaries: the telephone channel can be hijacked.

Phishing and AiTM attacks

Scattered Spider also uses classic phishing and, more sophisticatedly, adversary-in-the-middle (AiTM) attacks. In an AiTM attack, an intermediary proxy server captures not only the credentials but also the already authenticated session cookie, which allows even MFA to be bypassed because the valid session is stolen after authentication. We explain this technique in detail in our analysis of AiTM phishing and session hijacking, a particularly dangerous vector because it neutralises defences many organisations consider sufficient.

What happens after initial access

Getting an account is only the beginning. From there, Scattered Spider acts quickly to maximise impact before being detected.

Privilege escalation and lateral movement

With access to a legitimate account, the group explores the environment looking for higher permissions: administrator accounts, access to identity platforms, cloud management consoles or remote administration tools. Escalation is usually fast, taking advantage of permissive configurations and the implicit trust placed in already authenticated internal accounts. The goal is to reach positions from which to control large portions of the infrastructure.

Data theft and ransomware

Once control is consolidated, the group proceeds to steal data and, frequently, to deploy ransomware. Scattered Spider has collaborated with Ransomware-as-a-Service operations, a model in which specialised actors provide the encryption software and extortion infrastructure in exchange for a share of the ransom. To understand this final phase, it helps to review what ransomware is and how the double extortion that combines encryption with the threat of leaking stolen data works.

Affected sectors

Scattered Spider has been linked to high-profile breaches across several sectors. These include casinos and hospitality, retail, airlines and insurers. These campaigns should be attributed with caution, without treating unconfirmed details as established fact, but the sector pattern is illustrative: these are organisations with large employee bases, distributed support processes and, often, outsourced help desks, conditions that widen the attack surface for social engineering. The larger and more dispersed the IT support, the harder it becomes to maintain a uniform and strict verification process.

How to defend your organisation

The good news is that defences against Scattered Spider are largely known and applicable. The key is to treat identity as the real perimeter and harden the points where human manipulation has the most room to operate.

Harden identity verification at the help desk

This is the most direct measure against their signature technique. No password or MFA reset should be carried out without strong, out-of-band identity verification. That may involve a callback to a previously registered number, validation through the direct manager, the use of a code issued over an independent channel or a check based on verifiable credentials that cannot be improvised over a call. Security questions based on data an attacker can gather (date of birth, employee identifier, email) do not constitute strong verification.

Phishing-resistant MFA and number matching

Not all factors are equal. SMS-based MFA is vulnerable to SIM swapping, and simple push notifications are vulnerable to push bombing. Adopting phishing-resistant MFA (for example, with standards based on cryptographic keys bound to the device and domain) neutralises phishing and AiTM attacks, along with many impersonation vectors. It does not, however, stop post-authentication session theft by other means (for example, an infostealer on the victim's device), which requires additional controls such as device-bound tokens, conditional access, and anomalous session-reuse detection. Where push notifications are still used, number matching reduces the risk of accidental approvals under pressure.

Restrict self-service reset

Self-service portals for resetting passwords or MFA are convenient, but they are also a target. It is wise to limit which operations they allow without supervision, require additional factors for sensitive actions and log every reset for review. Reducing the number of paths through which an account can be recovered also reduces the attacker's opportunities.

Monitoring, ITDR and incident response

Identity threat detection and response (ITDR) makes it possible to watch for anomalous behaviour around accounts: unusual resets, new factor enrolments, logins from improbable locations or devices, and suspicious activity from support itself. We recommend relying on an ITDR approach that correlates identity signals and triggers early alerts. In addition, integrating intelligence about this actor into your security programme, following a structured threat intelligence lifecycle, helps anticipate TTPs and prepare incident response before the crisis arrives.

Frequently asked questions

What is Scattered Spider?

Scattered Spider is a financially motivated cybercriminal group, also tracked as UNC3944, Octo Tempest, Muddled Libra and Scatter Swine. It is known for its aggressive social engineering, especially against the help desk, and for including native English speakers who are convincing on support calls.

Why does MFA not always stop Scattered Spider?

Because the group does not break MFA by brute force but manipulates the process around it. They get the help desk to enrol a new factor under their control, wear the victim down with push bombing, hijack the phone number through SIM swapping or steal the already authenticated session with AiTM attacks. That is why the type of MFA and the hardening of the reset process matter so much.

What is SIM swapping and how do they use it?

SIM swapping involves transferring the victim's phone number to a SIM controlled by the attacker by deceiving or bribing the operator. With the number in their possession, they intercept MFA codes sent by SMS and telephone verifications. It is one of the reasons SMS-based MFA is considered weak against determined adversaries.

How can I protect my help desk from these attacks?

By hardening identity verification: allowing no password or MFA reset without a strong, out-of-band check, avoiding security questions based on public data, restricting self-service reset and logging and reviewing every sensitive operation. Training support agents to recognise artificial pressure and urgency is also key.

Does Scattered Spider deploy ransomware?

Yes. After initial access and privilege escalation, the group usually steals data and deploys ransomware, collaborating with Ransomware-as-a-Service operations. Its model combines identity compromise with subsequent extortion.

What is ITDR and why does it help against this actor?

ITDR (identity threat detection and response) is a set of capabilities for monitoring and responding to anomalous behaviour at the identity layer, such as suspicious resets, new factor enrolments or improbable logins. Because Scattered Spider attacks identity precisely, ITDR provides visibility and early alerts about their movements.

Test your resistance to social engineering

Scattered Spider proves that identity is the new perimeter and that the help desk can be the fastest way into your organisation. Secra is an offensive cybersecurity company with its own CVE research programme, with findings published in NVD and INCIBE-CERT (CVE-2025-40652 in CoverManager and CVE-2023-3512 in Setelsa ConacWin CB). We help organisations audit their identity verification processes, test their help desk through controlled social engineering exercises and harden their MFA and identity defences.

If you want to assess how your IT support would respond to an actor like Scattered Spider, get in contact with our team.

About the author

Secra Solutions team

Ethical hackers with OSCP, OSEP, OSWE, CRTO, CRTL and CARTE certifications, 7+ years of experience in offensive cybersecurity, and authors of CVE-2025-40652 and CVE-2023-3512.

Share article