Skip to content
AI-Powered Cyberattack: Scattered Spider

AI-Powered Cyberattack: Scattered Spider

Cybersecurity Insights

By Patricia A. Pramono • Studio 1080, Published on November 20, 2025

If attackers didn’t need to hack your system to get in (just your employees) how fast could they move? 

Scattered Spider is a cybercrime collective known for turning social engineering into a precision, identity-first attack method. Instead of brute-forcing logins, they convince help desks to reset credentials or add new Multi-Factor Authentication (MFA) devices, then move with alarming speed. 

Security researchers have linked the group to more than 100 breached organizations since 2022, with total extortion amounts exceeding $66 million (Cybercrime, 2025).

This case matters because it highlights how AI has upgraded social engineering. Attackers can now scale convincing emails, chats, and even voice calls, compressing operations that once took days into minutes.

Also read: 

As Cisometric’s Head of Tech Security emphasized in a national cybersecurity forum this year, Scattered Spider is a critical case to study. It represents how AI, human manipulation, and identity abuse now intersect, and why traditional security controls alone are no longer enough.

Also read: Cisometric at NCSC 2025: How AI Is Reshaping the Future of Cyber Defense

Who is Scattered Spider?

AI-Powered Cyberattack_ Scattered Spider - 2.png 98.85 KB

Also tracked as UNC3944, Muddled Libra, Octo Tempest, and Star Fraud, Scattered Spider blends native-English social skills with cloud and identity expertise.

The group first gained global attention after breaching MGM Resorts and Caesars Entertainment in 2023 through help-desk manipulation and MFA abuse (Cyber Security News, 2025). 

Since then, their activity has expanded to industries such as hospitality, retail, insurance, aviation, and technology (Cybercrime, 2025).

By mid-2025, researchers observed the group re-emerging with a dangerous twist, AI-powered deception. Their latest campaigns target UK retailers, US insurers, and airlines, using generative AI for tailored phishing messages and even voice cloning to impersonate employees (Command Zero, 2025).

Also read: Phishing: New Methods and How to Stay Safe

The Challenge of Detecting Scattered Spider Attacks

Traditional defenses look for malware or abnormal network activity. Scattered Spider, on the other hand, uses valid accounts and legitimate admin tools, blending perfectly into normal IT operations.

Their attack chain often begins with a simple phone call, for example, “Hi, I’m from IT. I’m locked out of my MFA, can you help me reset it?” That call is enough to bypass even the strongest authentication systems. Once the attacker convinces the help desk to reset credentials or re-register a device, they gain full access, no malware required.

In June 2025, the FBI issued a public warning to airlines after identifying multiple cases where attackers impersonated crew members or contractors to gain unauthorized system access (Web Asha Technologies, 2025).

CrowdStrike’s 2025 Threat Hunting Report detailed a typical Scattered Spider attack timeline:

1. Initial access

Attackers impersonate employees and convince IT support to reset passwords or MFA.

2. Login & persistence

They register their own device and log into cloud systems.

3. Pivoting

Attackers move laterally within Microsoft 365 and cloud services.

4. Data exfiltration

They export Entra ID user data, search internal SharePoint folders, and delete MFA notifications to hide traces.

How AI Accelerates Scattered Spider’s Operations

In 2025, Scattered Spider now leverages AI-written phishing, voice cloning, and automated reconnaissance to imitate real users (Jun Cyber, 2025). Their messages use personalized tone, internal jargon, and even dynamic phrasing that adapts to responses, making each interaction feel authentic.

From our own internal research on AI threat behavior, these tactics reflect a broader pattern of how attackers are using AI to speed up targeting, mimic human communication, and bypass verification barriers that rely on trust and familiarity.

This AI boost has turned social engineering into an operation of minutes rather than hours. Analysts observed that once Scattered Spider gains initial access, their intrusion unfolds at remarkable speed (CrowdStrike, 2025):

  • Password resets and MFA registrations occur within one minute
  • Internal reconnaissance through SharePoint within three minutes
  • Full data exfiltration in under five minutes

This level of automation and precision shows why AI is now both a tool and a threat in cybersecurity. By the time a suspicious login alert reaches an inbox, the attackers are often long gone.

How to Stay Safe Against AI-Powered Attacks Like the Scattered Spider Case

Defending against AI-driven social engineering requires more than just strong passwords or MFA. It demands awareness, verification discipline, and a combination of human vigilance with advanced monitoring systems.

AI-Powered Cyberattack_ Scattered Spider - 3.png 75.42 KB

For companies:

1. Strengthen help-desk verification

Implement call-back validation to a verified corporate number before performing any password or MFA reset. Require dual approval for high-privilege accounts, and train staff to slow down when urgency is used as pressure, a strong sign of social engineering (Web Asha Technologies, 2025).

2. Monitor subtle identity anomalies

Scattered Spider often hides through low-priority alerts, new MFA enrollments, or quiet SharePoint activity. Security teams should correlate small anomalies and elevate their importance during investigation (Command Zero, 2025).

3. Integrate behavioral analytics and SOC monitoring

A next-generation Security Operations Center (SOC), enables 24/7 monitoring of login velocity, MFA changes, and admin actions. Early detection of these patterns helps stop attacks before they escalate.

Also read: How Cisometric’s SOC Protected Businesses from Hundreds of Cyber Threats

4. Adopt zero-trust principles

Apply continuous validation for every access request. Use least-privilege access and contextual MFA that adjusts based on user behavior, device, or location (Jun Cyber, 2025).

Also read: What to Do After a Cyber Attack: A Step-by-Step Guide from Our Cyber Expert

5. Train and simulate regularly

Conduct phishing, vishing, and MFA-reset simulations to help employees recognize real-world threats. Continuous awareness is still the most effective first line of defense (Cyber Security News, 2025).

For individuals:

  • Never approve MFA prompts you didn’t initiate
  • Always verify unexpected IT or support calls through official internal channels
  • Report repeated MFA prompts, strange login alerts, or suspicious account activity immediately

AI-powered social engineering thrives on human trust and speed. A moment’s hesitation, a quick verification call, or an alert to your security team can make the difference between prevention and compromise.

Conclusion

The Scattered Spider case reveals how AI is not just transforming cybersecurity, it’s also transforming cybercrime. These attackers exploited trust, urgency, and routine workflows, now supercharged by AI.

As AI continues to accelerate both innovation and deception, the boundary between human error and machine precision grows thinner. The best defense is no longer just a stronger system, but a smarter one, powered by awareness, supported by process, and continuously monitored by experts.

Also read: AI and Machine Learning, the Future of Cybersecurity

At Cisometric, we believe that cybersecurity must evolve in lockstep with the threats it faces. Through our next-generation Security Operations Center (SOC), we help organizations detect, analyze, and respond to sophisticated attacks like Scattered Spider before they cause lasting damage.

If your organization is ready to strengthen its defenses against AI-powered cyber threats, our team can help. Connect with our cybersecurity experts to learn how our AI-driven SOC capabilities can protect your business from modern, identity-based attacks.

Schedule a free consultation with our experts today, click here.

For more updates on digital scams, cybersecurity insights, and expert tips, follow our social media:

LinkedIn: Cisometric

Instagram: @cisometric

Youtube: @Cisometric 

You may like this...

We use cookies to enhance your browsing experience, analyse site traffic, and deliver relevant content. Choose which cookies you allow. Privacy Policy