πΊπΈπ¬π§ Scattered Spider¶
Threat-actor battle card Β· maintained from public sources Β· last updated 2026-08-13 Β· also known as UNC3944, Octo Tempest, Oktapus, Muddled Libra, Scatter Swine
Overview¶
Scattered Spider (UNC3944 / Octo Tempest) is a data-extortion crew active since late 2022, profiled in CISA advisory AA23-320A (updated July 2025). It specialises in social engineering of IT help desks to breach large enterprises, and has increasingly paired its intrusions with DragonForce ransomware. Members are predominantly English-speaking teenagers and young adults from the UK and US operating within "The Com" β a loosely connected online criminal ecosystem. Tracked qualitatively (no DLS leaderboard).
Tradecraft¶
- Help-desk social engineering, MFA push-bombing and SIM-swapping to capture credentials and bypass MFA.
- Registers its own MFA tokens and deploys RMM tools for persistence.
- Counter-IR: monitors victim Slack / Teams / Exchange for response activity and joins incident bridge calls to track defenders.
- Extensive OSINT recon on B2B sites and social media to pick high-value targets.
- Increasingly deploys DragonForce ransomware as the encryption stage following data exfiltration.
Notable recent victims¶
- Transport for London (TfL) β UK public transport authority β Aug 31βSept 3, 2024 intrusion; disrupted Oyster photocard services, refund portal, in-station information boards; 10 million Londoners' names, emails, phones, and home addresses exposed (BBC March 2026 investigation); Β£29M ($38.2M) in losses, incident response, and recovery. Thalha Jubair (20, East London) and Owen Flowers (18, Walsall) were each sentenced to 5 years and 6 months at Woolwich Crown Court on July 16, 2026 β the UK's largest cybercrime prosecution and the first convictions under Section 3ZA of the Computer Misuse Act 1990. They pleaded guilty on June 22 (day 1 of scheduled 6-week trial) and received a 15% reduction for the plea.
- SSM Health Care Corporation (US healthcare) β Sept 2024; admitted by Flowers at Woolwich Crown Court.
- Sutter Health (US healthcare) β Sept 2024; admitted by Flowers at Woolwich Crown Court.
- Aflac (US insurance) β June 2025 social-engineering intrusion; 22.6 million people notified (β₯13.9M with PHI).
- Aflac Life Insurance Japan β unauthorized access June 15β25, 2026; 4.38M customer records exposed (names, addresses, phones; bank details for ~230K); officially unattributed but TTPs consistent with Scattered Spider per industry analysis; π₯ unverified attribution.
Assessment¶
The premier social-engineering threat to large enterprises β your help desk and identity-recovery flows are the attack surface, not just your perimeter. Phishing-resistant MFA and hardened help-desk verification are the controls that matter. The July 16 sentencing of Jubair and Flowers (5.5 years each β UK's largest cybercrime prosecution, first Section 3ZA CMA 1990 convictions) and the extradition of Peter Stokes ("Bouquet"), 19 (dual US/Estonian citizen, arrested Finland April 2026, extradited July 1, 2026; faces CFAA, wire fraud, and conspiracy charges in the US) mark the peak of Five Eyes enforcement pressure on the group so far. However, Mandiant notes other crews have already copied the TTP playbook. The cost of Scattered Spider membership is visibly rising, but the social-engineering model is now commodity knowledge β a key distinction for defenders.
Sources¶
- CISA β Scattered Spider (AA23-320A)
- CISA/FBI β Updated Scattered Spider Advisory (July 2025)
- BleepingComputer β TfL guilty pleas June 22, 2026
- Krebs on Security β TfL plea coverage
- Help Net Security β TfL plea details
- HIPAA Journal β UK hacker SSM/Sutter Health admissions
- Huntress β Scattered Spider Threat Actor Profile
- DOJ β Peter Stokes extradition announcement July 1, 2026
- The Hacker News β Stokes extradition coverage
- The Hacker News β Jubair/Flowers sentencing July 16, 2026
- The Register β Sentencing detail
- Intel 471 β Sentencing analysis
ποΈ Attacks & victims¶
All disclosed victims attributed to this actor, newest first.
June 2026