🔴 [LATEST] PARAGUAY'S MITIC SERVER DOWN FOR 24 HOURS, THEGARUDAEYE IN SPOTLIGHT    ◆    🔴 [LATEST] THEHATMAN SELLS 3.6 MILLION AZURE EMPLOYEE RECORDS FROM FORTUNE 500 COMPANIES    ◆    🔴 [LATEST] 24 HOURS OF DIGITAL BLACKOUT: THEGARUDAEYE SILENCES PARAGUAY'S CULTURE MINISTRY PORTAL IN THE NAME OF PALESTINE    ◆    🔴 [LATEST] WHERE HAS DRAGONFORCE MALAYSIA GONE? THE SILENCE OF SOUTHEAST ASIA'S PREMIER HACKTIVISTS    ◆    🔴 [LATEST] BREACHFORUMS ADMIN: HASANBROKER WAS A PREDATOR? DARK WEB FORUM WARS EXPLODE

> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE

Global
SCATTERED SPIDER

/actor/scattered-spider/  ·  1 intel report

Year Established
2022
Attribution
Western (USA/UK, Native English Speakers)
Motivation
Financial
Modus Operandi (MO)
Social engineering, SIM swapping, MFA fatigue attacks, ransomware deployment, casino and hospitality targeting
Primary Aliases
UNC3944, Muddled Libra, Octo Tempest, 0ktapus, Starfraud

Scattered Spider is a loosely organised, financially motivated cybercriminal collective comprising primarily young, English-speaking threat actors based in the United States and United Kingdom. Unlike the stereotype of state-sponsored hackers, Scattered Spider members are largely teenagers and young adults who communicate through online gaming communities, Discord, and Telegram channels collectively known as "The Com."

Despite their age and apparent informality, Scattered Spider has demonstrated sophisticated social engineering capabilities that have outmanoeuvred the security controls of major corporations. Their hallmark attack methodology involves telephonic impersonation of IT helpdesk staff, where they convince corporate employees or IT administrators to reset credentials or bypass multi-factor authentication (MFA), granting the group initial access to enterprise networks.

The group achieved international infamy through their 2023 attacks on MGM Resorts International and Caesars Entertainment, two of the largest casino operators in the United States. The MGM breach caused an estimated $100 million USD in losses and disrupted casino and hotel operations across Las Vegas for over a week. Caesars quietly paid a reported $15 million ransom to suppress public disclosure.

Scattered Spider subsequently partnered with the ALPHV/BlackCat ransomware operation to deploy ransomware within compromised networks, demonstrating their evolution from pure social engineering specialists into full-spectrum cybercriminals. Multiple members have been arrested by the FBI and UK law enforcement, though the collective continues to operate under new aliases.

STATUS: ACTIVE CLASSIFICATION: RANSOMWARE SYNDICATE LAST SEEN: Aug 2026

> LINKED_INTEL_REPORTS (1)

> cd ../articles