Scattered Spider Hacking Group Facilitates US Retailers Cyber-Attacks

The hacking group, Scattered Spider, has expanded its cyber-attacks from UK retailers to the US, with Google's cybersecurity experts warning of a pattern of disruption typical of the group. The group, named for its tactics rather than being an organized group, has been linked to attacks on UK retailers such as Marks & Spencer, the Co-op, and Harrods. Google's Mandiant cybersecurity unit chief technology officer, Charles Carmakal, stated that the threat had moved to the US, targeting unnamed retailers across the Atlantic.

The group's tactics involve ringing up IT help desks, pretending to be employees or contractors, to gain access to company systems. This has prompted the UK's National Cyber Security Agency to advise companies to look out for specific tactics, including checking how IT help desks assist staff members in resetting passwords. The group's members, primarily native English speakers from countries like the UK, US, and Canada, have been linked to ransomware attacks, typically orchestrated by Russian or former Soviet state gangs.

Key Takeaways:

  • Scattered Spider is facilitating cyber-attacks on US retailers, expanding from UK retailers.
  • The group's tactics involve ringing up IT help desks, pretending to be employees, to gain access to company systems.
  • Google's cybersecurity experts have warned US retailers to be aware of the threat, anticipating continued targeting in the near term.
  • The group's members primarily consist of native English speakers from countries like the UK, US, and Canada.
  • Scattered Spider's ransomware attacks are unusual, as the group typically targets a single sector at a time.
  • The group's tactics, including making telephone calls to IT help desks, are often carried out by younger members of the network.
  • The National Cyber Security Agency has advised companies to be vigilant, checking how IT help desks assist staff members in resetting passwords.

Statistics:

  • 3 major UK retailers (Marks & Spencer, the Co-op, and Harrods) have been linked to Scattered Spider's attacks.
  • 100s of phone calls have been made to IT help desks by Scattered Spider hackers.
  • Google's Mandiant cybersecurity unit has listened to "countless calls" made by Scattered Spider hackers.
  • 50% of ransomware gangs involved in Scattered Spider's attacks are from Russia or former Soviet states.

Sources:

  • Google Mandiant cybersecurity unit chief technology officer, Charles Carmakal, quoted in The Guardian article
  • John Hultquist, chief analyst at Google Threat Intelligence Group, in a statement
  • National Cyber Security Agency advisory note (date unavailable)
  • Dior statement regarding unauthorized external party accessing customer data