← Intelligence Center

CISA and Partners Release Updated Advisory on Scattered Spider Group

PublishedJul 30, 2025
Updated
VendorN/A
SeverityUnspecified
Known ExploitedNo
Advisory IDINTEL-000022
CVEs
None identified.
Products
  • Not specified.

Executive Summary

CISA, the FBI, the Canadian Centre for Cyber Security, the Royal Canadian Mounted Police, the Australian Cyber Security Centre, and other partners released an updated joint Cybersecurity Advisory on Scattered Spider, a cybercriminal group targeting commercial facilities sectors and subsectors. The advisory provides updated tactics, techniques, and procedures (TTPs) obtained through FBI investigations conducted through June 2025. Scattered Spider actors have used various ransomware variants in data extortion attacks, most recently including DragonForce ransomware, and frequently use social engineering such as phishing, push bombing, and SIM swap attacks to obtain credentials, install remote access tools, and bypass multi-factor authentication.

Municipal Impact

Municipal organizations in the commercial facilities sector and state/local governments should review the advisory's mitigations and harden identity and MFA practices against credential theft.

SMB Impact

Small and medium businesses, particularly in commercial facilities subsectors, should implement the advisory's mitigations, especially around MFA bypass and social engineering resistance.

Recommended Actions

  1. Review the Mitigations section of the Scattered Spider joint Cybersecurity Advisory.
  2. Fortify defenses against phishing, push bombing, and SIM swap attacks used to obtain credentials.
  3. Implement protections against MFA bypass and remote access tool abuse.

Grey Matter Analysis

Analysis pending review.

Need help with this advisory?

Contact Grey Matter to assess your exposure and prioritize remediation.

Contact Grey Matter