Security Stop-Press: Scattered Spider Shifts Focus to Insurance Firms

June 25, 2025

Security Stop-Press: Scattered Spider Shifts Focus to Insurance Firms

Scattered Spider, a teenage-led (mainly UK and US-based) hacking group has begun targeting insurance companies, sparking fresh warnings from cyber security experts.

Google’s Threat Intelligence Group (GTIG) confirmed multiple US insurance firms have recently suffered attacks matching the group’s methods. Known for breaching major retailers like M&S and Tiffany, the group uses tactics such as phishing, SIM-swapping, and MFA fatigue to bypass identity checks and helpdesk protocols.

Two incidents in early June, affecting Philadelphia Insurance and Erie Insurance, show the threat is real and growing. GTIG warned that the group tends to focus on one sector at a time, and insurance firms are now clearly in its sights. Experts believe UK providers could be next.

Unlike ransomware gangs, Scattered Spider relies on social engineering to move fast and exploit human error. “They don’t need advanced exploits,” said Jon Abbott, CEO of ThreatAware. “They get in by tricking people – not by breaking software.”

To stay safe, insurers and other businesses should strengthen helpdesk verification, use phishing-resistant MFA, and monitor for unusual login activity. Above all, building a culture of security awareness is essential to stop attackers in their tracks.

Security Stop-Press: Blur Your Property on Google Maps for Better Security
July 16, 2025
Blurring your property on Google Maps is a simple, permanent step available to any homeowner or tenant that may help reduce the risk of targeted crime.
Featured Article : AI Agents Failing (40% Cancellations Predicted)
July 16, 2025
New research has found that 70 per cent of AI agents struggle to complete standard office tasks successfully, while Gartner warns that over 40 per cent of current agentic AI projects will be scrapped by the end of 2027.
More Posts