highPhishing

Scattered Spider Social Engineering

First seen Jul 3, 2026 · Updated Jul 3, 2026

Social EngineeringIdentityMFA Bypass

English-speaking group using SIM-swapping and MFA fatigue attacks to compromise enterprise identity providers via IT help desk impersonation calls.

Affected Systems

Okta, Azure AD, IT help desks without strict identity verification

Indicators of Compromise

  • MFA push floods >10/min
  • Residential proxy credential stuffing
  • Help desk calls for exec resets
  • Anomalous MFA registrations

Remediation Steps

  1. 1

    Deploy FIDO2 Keys

    Implement hardware security keys and deprecate SMS/push MFA

  2. 2

    Verified Callbacks

    Establish callback verification for all help desk requests

  3. 3

    Impossible Travel Detection

    Alert on geographically impossible authentication patterns

  4. 4

    Help Desk Training

    Regular social engineering tabletop exercises

Industries Most Exposed

TechnologyFinancialTelecommunications

Respond to this threat

Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.