{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"},"incident":{"slug":"2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments","title":"US and UK charge Scattered Spider pair tied to $115M in ransom payments","date":"2025-09-18","date_precision":"day","year":2025,"victim_org":"47 US organisations including healthcare, transport and technology firms","sector":"Other","country":"United States","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)","Smishing (SMS)","Credential Phishing Portal"],"ai_involvement":"No AI reported","ai_notes":"","outcomes":["Extortion","Ransomware Deployment","Data Breach","Service Disruption"],"loss_usd":115000000,"loss_kind":"aggregate","loss_note":"US prosecutors tied the pair to at least $115 million in ransom payments across the charged intrusions.","records_affected":null,"threat_actor":"Scattered Spider / UNC3944","summary":"On 18 September 2025 US prosecutors unsealed charges against British nationals Thalha Jubair and Owen Flowers, alleging involvement in Scattered Spider intrusions at 47 US organisations and at least $115 million in ransom payments. UK authorities separately charged the pair in connection with the September 2024 attack on Transport for London. The charging documents described a campaign built on impersonating employees to IT help desks.","how_it_worked":"The group's method was consistent across victims: research a target employee, phone the company's IT service desk claiming to be that person locked out of their account, and request a password or multi-factor reset. Native English fluency, correct personal details and calm persistence defeated knowledge-based verification. Where calls failed they sent SMS messages warning of expiring single sign-on credentials and directed staff to lookalike Okta portals that relayed credentials and MFA codes live. Once inside they escalated privileges, exfiltrated data and deployed ransomware, then negotiated payment. The consistent weak point was a help desk empowered to reset access on the strength of a convincing voice.","lessons":"Help desk identity proofing with video or manager approval before credential and MFA resets, and phishing-resistant MFA, are the controls this group is specifically built to defeat.","confidence":"Confirmed","sources":[{"title":"Feds Tie 'Scattered Spider' Duo to $115M in Ransoms","url":"https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/","publisher":"Krebs on Security"},{"title":"US government charges British teenager accused of at least 120 Scattered Spider hacks","url":"https://techcrunch.com/2025/09/18/us-government-charges-british-teenager-accused-of-at-least-120-scattered-spider-hacks/","publisher":"TechCrunch"}],"entry_type":"incident","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2025-us-and-uk-charge-scattered-spider-pair-tied-to-115m-in-ransom-payments"}}