← All attack breakdowns
Identity Active and ongoing

Scattered Spider

Also tracked as UNC3944 · Octo Tempest · Storm-0875

No malware, no exploit — they phone your help desk and ask for access

Help desk call to domain admin in under 40 minutes

Scattered Spider does not start with an exploit. They research an employee using LinkedIn, company sites, and data from earlier breaches, then call the IT help desk impersonating that person and ask for an MFA reset.

The help desk follows its documented procedure. The attacker enrolls their own device and now holds legitimate, fully authenticated access. There is no malicious attachment to block and no vulnerability to patch.

Reporting puts the escalation from a single call to domain admin at under 40 minutes, with no malware involved. The group has extended the same playbook into Okta, AWS, and Microsoft 365 environments.

The attack chain

3 of 5 stages are broken by controls we verify. Where nothing we check would have helped, the stage says so.

1

Reconnaissance

Public sources and breach data are assembled into a profile detailed enough to pass a verbal identity check — job title, manager, start date, office location.

What we can't verify

Nothing we verify prevents open-source research about your staff. This stage is unavoidable; the defense is at the stages that follow.

2

Help desk impersonation

The attacker calls posing as the employee, typically claiming to be travelling and locked out, and requests an MFA reset or password change.

What we can't verify

Help desk identity-proofing is a human process, not a setting we can read from an API. CISA's guidance — video verification with liveness, manager attestation, and re-enrollment through a second registered authenticator — is the control here, and you own it.

3

MFA reset and re-enrollment

The factor is reset and the attacker enrolls a device they control. Where a reset isn't available, the fallback tactics are push-notification bombing, SIM swap, or phishing the one-time code.

Broken by

  • Admin MFA + Security Keys
  • All-User MFA + Security Keys
4

Authenticated access

The attacker is now a legitimate user. Where legacy or password-only authentication paths exist, a stolen password alone is sufficient and the second factor never applies.

Broken by

  • Less Secure App Access
  • Password Policy
5

Privilege escalation and blast radius

Administrative accounts are the objective. A single compromised super admin can disable security controls organization-wide.

Broken by

  • Super Admin Count
  • Admin MFA + Security Keys

How we verify the layer exists

Each of these reads a specific field from a provider's own API. The exact field is listed in our methodology.

Admin MFA with security keys

Verifies admins have 2-step verification enforced with a passkey or hardware key registered. CISA recognizes only FIDO2/WebAuthn and PKI as phishing-resistant — those are immune to push bombing, SIM swap, and code phishing.

All-user MFA with security keys

Measures how much of your workforce is on enforced, phishing-resistant MFA rather than SMS or prompts, which are the factors these fallback tactics target.

Legacy access disabled

Confirms no account can authenticate with a password alone — closing the path where a stolen credential bypasses the second factor entirely.

Minimal super admins

Counts full-access administrators. Fewer super admins means fewer accounts worth the phone call and a smaller blast radius when one is taken.

What passing these checks does not mean

  • ·Phishing-resistant MFA does not stop a help desk from resetting the factor and enrolling an attacker's device. It defeats push bombing, SIM swaps, and phished one-time codes — it does not defeat your own recovery process.
  • ·We can verify the technical controls are in place. We cannot verify how your help desk proves someone is who they claim to be, and that is the stage this group actually attacks.
  • ·Treat our identity checks as raising the floor, not closing the door. Pair them with a hardened help desk script and out-of-band verification.

Sources

Would these controls hold in your environment?

Connect read-only and find out in 60 seconds. Free.

Check my posture