US Insurance Cyberattacks: Hacker Shift
- insurance companies are facing a heightened threat as Scattered Spider, a notorious hacking group, sets its sights on the industry.
- John Hultquist, chief analyst at Google Threat Intelligence Group (GTIG), confirmed the trend.
- Given the group's pattern of targeting one sector at a time, he warned that "the insurance industry should be on high alert." GTIG advises companies to pay close...
Teh U.S. insurance industry is under siege. Scattered Spider, a notorious hacking group, has shifted its focus, launching sophisticated cyberattacks designed to exploit vulnerabilities within insurance firms. Learn about the group’s tactics, including social engineering, phishing, and ransomware deployment, and understand why companies must prioritize employee education and robust authentication protocols.News Directory 3 examines expert advice and defense strategies for navigating this evolving threat landscape. Discover what’s next in the fight against cybercrime.
Scattered Spider hackers Target U.S. Insurance Firms
Updated June 17, 2025
U.S. insurance companies are facing a heightened threat as Scattered Spider, a notorious hacking group, sets its sights on the industry. Threat intelligence researchers are raising alarms about multiple breaches exhibiting tactics consistent with Scattered Spider activity. This marks a shift for the group, known for its sector-specific focus, having previously targeted retail organizations in both the United Kingdom and the United States.
John Hultquist, chief analyst at Google Threat Intelligence Group (GTIG), confirmed the trend. “Google Threat Intelligence Group is now aware of multiple intrusions in the U.S. which bear all the hallmarks of Scattered Spider activity. We are now seeing incidents in the insurance industry,” Hultquist said.
hultquist emphasized the need for vigilance. Given the group’s pattern of targeting one sector at a time, he warned that “the insurance industry should be on high alert.” GTIG advises companies to pay close attention to potential social engineering attempts targeting help desks and call centers, a common entry point for Scattered spider.
Scattered spider Tactics and the Cybersecurity Role
Scattered Spider,also known as 0ktapus,UNC3944,Scatter Swine,starfraud,and Muddled Libra,is a fluid coalition of threat actors known for sophisticated social engineering attacks. These attacks are designed to bypass even mature security programs. The group has been linked to breaches at numerous high-profile organizations, employing techniques such as phishing, SIM-swapping, and MFA fatigue/MFA bombing to gain initial access. In later stages, they have been observed deploying ransomware, including RansomHub, Do, and DragonForce.
The National Cyber Security Centre (NCSC) in the U.K. shared advice for improving cybersecurity defenses after Scattered Spider, using similar social engineering tactics, breached retailers Marks & Spencer, Co-op, and Harrods. In all three attacks, dragonforce ransomware was deployed.
Defense Strategies Against Cyber threats
Organizations seeking to defend against Scattered Spider should prioritize gaining complete visibility across their entire infrastructure, identity systems, and critical management services. Experts recommend segregating identities and implementing strong authentication criteria,along with rigorous identity controls for password resets and MFA registration
