Skip to content

πŸ‡ΊπŸ‡ΈπŸ‡¬πŸ‡§ Scattered Spider

Threat-actor battle card Β· maintained from public sources Β· last updated 2026-08-13 Β· also known as UNC3944, Octo Tempest, Oktapus, Muddled Libra, Scatter Swine

CategoryData-extortion / social engineering
AttributionNative English-speaking, loosely organised (The Com ecosystem)
First seenLate 2022
StatusActive
Primary targetsTelecom, Entertainment, IT, Insurance, Healthcare, Large enterprises

Overview

Scattered Spider (UNC3944 / Octo Tempest) is a data-extortion crew active since late 2022, profiled in CISA advisory AA23-320A (updated July 2025). It specialises in social engineering of IT help desks to breach large enterprises, and has increasingly paired its intrusions with DragonForce ransomware. Members are predominantly English-speaking teenagers and young adults from the UK and US operating within "The Com" β€” a loosely connected online criminal ecosystem. Tracked qualitatively (no DLS leaderboard).

Tradecraft

  • Help-desk social engineering, MFA push-bombing and SIM-swapping to capture credentials and bypass MFA.
  • Registers its own MFA tokens and deploys RMM tools for persistence.
  • Counter-IR: monitors victim Slack / Teams / Exchange for response activity and joins incident bridge calls to track defenders.
  • Extensive OSINT recon on B2B sites and social media to pick high-value targets.
  • Increasingly deploys DragonForce ransomware as the encryption stage following data exfiltration.

Notable recent victims

  • Transport for London (TfL) β€” UK public transport authority β€” Aug 31–Sept 3, 2024 intrusion; disrupted Oyster photocard services, refund portal, in-station information boards; 10 million Londoners' names, emails, phones, and home addresses exposed (BBC March 2026 investigation); Β£29M ($38.2M) in losses, incident response, and recovery. Thalha Jubair (20, East London) and Owen Flowers (18, Walsall) were each sentenced to 5 years and 6 months at Woolwich Crown Court on July 16, 2026 β€” the UK's largest cybercrime prosecution and the first convictions under Section 3ZA of the Computer Misuse Act 1990. They pleaded guilty on June 22 (day 1 of scheduled 6-week trial) and received a 15% reduction for the plea.
  • SSM Health Care Corporation (US healthcare) β€” Sept 2024; admitted by Flowers at Woolwich Crown Court.
  • Sutter Health (US healthcare) β€” Sept 2024; admitted by Flowers at Woolwich Crown Court.
  • Aflac (US insurance) β€” June 2025 social-engineering intrusion; 22.6 million people notified (β‰₯13.9M with PHI).
  • Aflac Life Insurance Japan β€” unauthorized access June 15–25, 2026; 4.38M customer records exposed (names, addresses, phones; bank details for ~230K); officially unattributed but TTPs consistent with Scattered Spider per industry analysis; πŸŸ₯ unverified attribution.

Assessment

The premier social-engineering threat to large enterprises β€” your help desk and identity-recovery flows are the attack surface, not just your perimeter. Phishing-resistant MFA and hardened help-desk verification are the controls that matter. The July 16 sentencing of Jubair and Flowers (5.5 years each β€” UK's largest cybercrime prosecution, first Section 3ZA CMA 1990 convictions) and the extradition of Peter Stokes ("Bouquet"), 19 (dual US/Estonian citizen, arrested Finland April 2026, extradited July 1, 2026; faces CFAA, wire fraud, and conspiracy charges in the US) mark the peak of Five Eyes enforcement pressure on the group so far. However, Mandiant notes other crews have already copied the TTP playbook. The cost of Scattered Spider membership is visibly rising, but the social-engineering model is now commodity knowledge β€” a key distinction for defenders.

Sources

πŸ—‚οΈ Attacks & victims

All disclosed victims attributed to this actor, newest first.

June 2026

Jun 30 Aflac Life Insurance Japan Ltd. Scattered Spider Extortion Β· insurance Β· Japan unauthorized access June 15–25, 2026; 4.38M customer records exposed (names, addresses, phone numbers; bank account details for ~230K); access vector undisclosed; actor officially unattributed but TTPs consistent with Scattered Spider per industry analysis; Aflac disclosed June 30, 2026; Japan FSA and police notified; no misuse confirmed at disclosure; πŸŸ₯ unverified attribution Β· https://www.securityweek.com/aflac-japan-data-breach-impacts-4-38-million/ Β· https://www.bleepingcomputer.com/news/security/insurance-giant-aflac-discloses-data-breach-after-subsidiary-hack/ Β· https://www.japantimes.co.jp/business/2026/06/30/aflac-hack-4-million/ Β· Sources: [SecurityWeek] Β· [BleepingComputer] Β· [Japan Times]
Jun 19 Aflac Scattered Spider Extortion Β· insurance Β· US June 2025 social-engineering intrusion; 22.6M people notified (β‰₯13.9M with PHI) Β· Sources: The Record / HIPAA Journal

← All threat actors Β· Full victim database β†’