Scattered Spider’s Playbook: Unmasking Help Desk Scams That Cost Companies Millions


# Scattered Spider: Beyond Help Desk Scams

In the aftermath of major attacks on UK retailers Marks & Spencer and Co-op, Scattered Spider has dominated cybersecurity headlines. While these incidents have raised valuable awareness about security challenges, the focus on help desk scams represents just one facet of a more complex threat landscape.

## The Help Desk Scam Playbook

Help desk scams involve attackers impersonating legitimate users to convince support staff to reset credentials or bypass MFA. The typical approach is straightforward:

1. Call the help desk claiming to need MFA reset due to a “new device”
2. Redirect the reset link to attacker-controlled contact points
3. Use self-service password reset functionality to take control of the account
4. Target high-privilege accounts to minimize the need for privilege escalation

## A Well-Established Threat Vector

Despite recent media attention, Scattered Spider has successfully employed these techniques since 2022. Previous high-profile victims include:

– **Caesars** (August 2023): Attackers impersonated IT staff, compromised the customer loyalty database, and secured a $15 million ransom
– **MGM Resorts** (September 2023): Using LinkedIn information to impersonate an employee led to 6TB of stolen data and $100+ million in damages
– **Transport for London** (September 2024): Resulted in exposure of 5,000 users’ bank details and months of service disruption

## Strengthening Help Desk Security

Organizations should implement enhanced verification processes, particularly for privileged accounts:

– Require multi-party approval for admin-level resets
– Implement in-person verification when remote processes are insufficient
– Freeze self-service resets when suspicious activity is detected

Common security pitfalls include:
– Callback verification failing against SIM swapping
– Video verification vulnerable to deepfakes
– Help desk performance metrics that prioritize speed over security

## The Broader Scattered Spider Arsenal

Help desk scams are just one component of Scattered Spider’s identity-focused attack methodology. Their toolkit includes:

– Credential phishing via email and SMS
– SIM swapping to bypass SMS-based MFA
– MFA fatigue attacks against push authentication
– Vishing to directly social engineer MFA codes
– DNS hijacking to take over business applications
– MFA-bypass techniques using AiTM (Adversary-in-the-Middle) phishing kits

## Evading Established Security Controls

Scattered Spider deliberately circumvents traditional security measures by:

1. Targeting cloud and SaaS services where monitoring is often less robust
2. Tampering with cloud logs to avoid detection
3. Deploying ransomware in VMware environments via the hypervisor layer, bypassing endpoint security

## The Path Forward

Organizations must recognize Scattered Spider as a “post-MFA” threat actor that systematically evades conventional security controls. Effective defense requires addressing the broader identity attack surface, including MFA gaps, local account backdoors, and sophisticated phishing techniques that can bypass standard protections.

Share This Article