Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Google warns of scattered spider attacks targeting IT support teams of US insurance companies
Identity

Google warns of scattered spider attacks targeting IT support teams of US insurance companies

userBy userJune 17, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

June 17, 2025Ravi LakshmananThreat Intelligence/Identity Security

Scattered spider attacks targeting IT support teams

According to the Google Threat Intelligence Group (GTIG), the infamous cybercrime group (UNC3944), known recently as scattered spiders (aka UNC3944), which targets a variety of UK and US retailers, has begun targeting major insurance companies.

“Google Threat Intelligence Group is currently aware of multiple US intrusions,” GTIG chief analyst John Hartquist told an email Monday.

“We are currently seeing incidents in the insurance industry. Given the history of this actor focusing on the sector at once, the insurance industry should be highly vigilant, especially due to the social engineering schemes targeting their help desks and call centers.”

Scattered spiders are names assigned to amorphous populations known for using advanced social engineering tactics to violate organizations. In recent months, threat actors are believed to have fake their alliance with the Dragon Force ransomware cartel in the wake of the latter’s takeover of the Ransom Hub infrastructure.

“The group has repeatedly demonstrated its ability to impersonate employees, deceive IT support teams and bypass multifactorial authentication (MFA) through psychological tactics,” SOS Intelligence said.

Cybersecurity

“Although often referred to as “native English speakers,” they are suspected of having or having connections with Western countries, resulting in cultural urgency that makes phishing and telephone-based attacks surprisingly effective. ”

Earlier this month, ReliaQuest revealed that scattered Spider and Dragonforce are increasingly targeting managed service providers (MSPs) and IT contractors to gain access to several downstream customers through a single compromise.

Mandiant, owned by Google, said threat actors often want to select large enterprise organizations and perhaps land a larger payday.

Particularly targeted are companies with large-scale help desks, outsourcing IT functions that are susceptible to social engineering attacks.

To oppose the tactics exploited by e-crime groups, we recommend training help desk personnel to strengthen authentication, implement strict identity controls, implement access restrictions and boundaries to prevent privilege escalation and lateral movement, and actively identify employees before resetting their accounts.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleSequoia-backed Crosby launches a new kind of AI-powered law firm
Next Article The 2-year-old Defense Tech Mach Industries has confirmed a $100 million salary increase led by Khosla.
user
  • Website

Related Posts

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

July 20, 2025

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

July 20, 2025

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

July 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

Astronomer CEO resigns following Cold Play Concert Scandal

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.