Scattered Spider Social Engineering
First seen Jul 3, 2026 · Updated Jul 3, 2026
English-speaking group using SIM-swapping and MFA fatigue attacks to compromise enterprise identity providers via IT help desk impersonation calls.
Affected Systems
Okta, Azure AD, IT help desks without strict identity verification
Indicators of Compromise
- MFA push floods >10/min
- Residential proxy credential stuffing
- Help desk calls for exec resets
- Anomalous MFA registrations
Remediation Steps
- 1
Deploy FIDO2 Keys
Implement hardware security keys and deprecate SMS/push MFA
- 2
Verified Callbacks
Establish callback verification for all help desk requests
- 3
Impossible Travel Detection
Alert on geographically impossible authentication patterns
- 4
Help Desk Training
Regular social engineering tabletop exercises
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.