Scattered Spider
   HOME

TheInfoList



OR:

Scattered Spider, also referred to as UNC3944, is a hacking group mostly made up of teens and young adults believed to live in the United States and the United Kingdom. The group gained notoriety for their involvement in the hacking and extortion of
Caesars Entertainment Caesars Entertainment, Inc., formerly Eldorado Resorts, Inc., is an American hotel and casino entertainment company founded and based in Reno, Nevada, that operates more than 50 properties. Eldorado Resorts acquired Caesars Entertainment Corpora ...
and
MGM Resorts International MGM Resorts International is an American Multinational corporation, multinational hospitality, sports and entertainment company. It operates resorts in Las Vegas, Massachusetts, Michigan, Mississippi, Maryland, Ohio, New Jersey, Macau, Shanghai, ...
, two of the largest casino and gambling companies in the United States. Scattered Spider has also targeted Visa,
Marks & Spencer Marks and Spencer plc (commonly abbreviated to M&S and colloquially known as Marks & Sparks or simply Marks) is a major British multinational retailer based in London, England, that specialises in selling clothing, beauty products, home produc ...
, PNC Financial Services Group Inc., Transamerica, New York Life Insurance Co.,
Synchrony Financial Synchrony Financial is an American consumer financial services company with its headquarters in Stamford, Connecticut, United States. The company offers consumer financing products, including credit, promotional financing and loyalty programs, ...
,
Truist Bank Truist Financial Corporation () is an American bank holding company headquartered in Charlotte, North Carolina. The company was formed in December 2019 as the result of the merger of BB&T (Branch Banking and Trust Company) and SunTrust Banks. I ...
, and Twilio. More recently, members of Scattered Spider have been connected with the hacks against Snowflake cloud storage customers in the US.


Names

The group's most common name as used in press releases and by journalists is Scattered Spider, though many other names have been attributed to the group. Star Fraud, Octo Tempest, Scatter Swine, and Muddled Libra have all been names used to refer to the group previously. Scattered Spider is a component of a larger global hacking community, known as "the Community" or "the Com", itself having members who have hacked major American technology companies.


Early history

Scattered Spider is believed to have been founded in May 2022, when the group was focused on attacks on telecommunications firms. The group utilized SIM swap scams, multi-factor authentication fatigue attacks, and phishing by SMS and
Telegram Telegraphy is the long-distance transmission of messages where the sender uses symbolic codes, known to the recipient, rather than a physical exchange of an object bearing the message. Thus flag semaphore is a method of telegraphy, whereas pi ...
. The group typically exploited the security bug CVE-2015-2291, a cybersecurity issue in Windows' anti-
DoS DOS (, ) is a family of disk-based operating systems for IBM PC compatible computers. The DOS family primarily consists of IBM PC DOS and a rebranded version, Microsoft's MS-DOS, both of which were introduced in 1981. Later compatible syste ...
software, to terminate security software, allowing the group to evade detection. The group is believed to have a deep understanding of
Microsoft Azure Microsoft Azure, or just Azure ( /ˈæʒər, ˈeɪʒər/ ''AZH-ər, AY-zhər'', UK also /ˈæzjʊər, ˈeɪzjʊər/ ''AZ-ure, AY-zure''), is the cloud computing platform developed by Microsoft. It has management, access and development of ...
, the ability to conduct reconnaissance in cloud computing platforms powered by
Google Workspace Google Workspace (formerly G Suite, formerly Google Apps) is a collection of cloud computing, Productivity software, productivity and Collaborative software, collaboration tools, software and products developed and marketed by Google. It con ...
and AWS, and utilizes legitimately-developed remote-access tools. The group later became known for targeting critical infrastructure prior to moving on to its 2023 casino hacks.


Casino hacks (2023)

Scattered Spider gained access to both Caesars' and MGM's internal systems through the use of social engineering. The group was able to bypass multi-factor authentication technologies by attaining login credentials and one-time passwords. The group claims that it targeted MGM due to them catching the group attempting to rig slot machines in their favor.


Caesars hack

Caesars Entertainment paid a ransom of $15 million to Scattered Spider, half their original demand of $30 million. Scattered Spider, using similar tactics to its attack on MGM, was able to access driver's license numbers and possibly
Social Security number In the United States, a Social Security number (SSN) is a nine-digit number issued to United States nationality law, U.S. citizens, Permanent residence (United States), permanent residents, and temporary (working) residents under section 205(c)(2 ...
s, for a "significant number" of Caesars customers. Statements made by Caesars noted that while the company cannot guarantee the deletion of the information attained by Scattered Spider, the casino operator will take all necessary actions to attain such result. Sources dispute on whether Scattered Spider was the group which targeted Caesars, with some believing it was the British-American group while others say the perpetrators were not the group or unknown.


MGM Resorts hack

Scattered Spider collaborated with ALPHV, a software development team which provides
ransomware Ransomware is a type of malware that Encryption, encrypts the victim's personal data until a ransom is paid. Difficult-to-trace Digital currency, digital currencies such as paysafecard or Bitcoin and other cryptocurrency, cryptocurrencies are com ...
as a service. Scattered Spider called MGM's
help desk A help desk is a department or person that provides assistance and information, usually for electronic or computer problems. In the mid-1990s, research by Iain Middleton of Robert Gordon University studied the value of an organization's help des ...
posing as an employee it found on
LinkedIn LinkedIn () is an American business and employment-oriented Social networking service, social network. It was launched on May 5, 2003 by Reid Hoffman and Eric Ly. Since December 2016, LinkedIn has been a wholly owned subsidiary of Microsoft. ...
to gain internal access. The group gained access on September 11, 2023. MGM Resorts first disclosed the cyberattack on September 12, 2023, in a
Form 8-K Form 8-K is a very broad form used to notify investors in United States public companies of specified events that may be important to shareholders or the United States Securities and Exchange Commission. This is one of the most common types of for ...
report with the SEC the next day. The company stated that though it has "dealt" with the cyberattack, many of the computer systems at its resorts remain offline, which include but are not limited to credits for food, beverages, and free credits. The attack further disabled on-site ATMs as well as remote room keys, and prevented MGM from charging patrons for parking. In July 2024, a 17-year old hacker from the United Kingdom was arrested in connection with the hack and attempted ransom. He has been released on bail pending trial. The arrest was coordinated by local and international law enforcement.


Casino hacks aftermath

MGM and the US FTC and
FBI The Federal Bureau of Investigation (FBI) is the domestic Intelligence agency, intelligence and Security agency, security service of the United States and Federal law enforcement in the United States, its principal federal law enforcement ag ...
are at present investigating the cyberattack, and the casino operator temporarily took down its website.
Moody's Corporation Moody's Corporation is an American business and financial services company. It is the holding company for Moody's Ratings (previously known as Moody's Investors Service), an American credit rating agency, and Moody's (previously known as Moody ...
has stated that due to MGM's heavy reliance on computers for much of its operations, its
credit rating A credit rating is an evaluation of the credit risk of a prospective debtor (an individual, a business, company or a government). It is the practice of predicting or forecasting the ability of a supposed debtor to pay back the debt or default. The ...
could go down as a result of the cyberattack. Upon the announcement of both companies' attacks, the stock prices for both Caesars and MGM dropped. MGM's CEO William Hornbuckle went on to note at an industry conference that the hack caused the company to be "completely in the dark" about its properties. Both MGM and Caesars were sued in
class action lawsuits A class action is a form of lawsuit. Class Action may also refer to: * ''Class Action'' (film), 1991, starring Gene Hackman and Mary Elizabeth Mastrantonio *Class Action (band), a garage house band * "Class Action" (''Teenage Robot''), a 2002 epi ...
following the hacks, with all stating that the failure for both of the casino operators to adequately secure their data constituted breach of contract. The law firms' clients also all demanded jury trials. In January 2025, MGM agreed to pay a $45 million dollar settlement to the victims of the breach.


Snowflake hacks

Two members of the group have been connected with hacks against customers of Snowflake's cloud computing. The hackers accessed and stole customer data, demanding millions of dollars in extortion to not publicly release the data. Nearly a hundred victims were targeted, including: AT&T,
Ticketmaster Ticketmaster Entertainment, LLC is an American ticket sales and distribution company based in Beverly Hills, California, with operations in many countries around the world. In 2010, it merged with Live Nation under the name Live Nation Ente ...
,
Advance Auto Parts Advance Auto Parts, Inc. is an American automotive aftermarket parts provider. Headquartered in Raleigh, North Carolina, it serves professional installer and do it yourself (DIY) customers. Company History In April 1932, Arthur Taubman purch ...
, Lending Tree and
Neiman Marcus Neiman Marcus is an American department store chain founded in 1907 in Dallas, Texas by Herbert Marcus, his sister Carrie Marcus Neiman, and her husband Abraham Lincoln Neiman. It has been owned by Saks Global, a Corporate spin-off, spin-o ...
.


Arrests

In January 2024, Noah Michael Urban, a member of the group and known as "Sosa", "King Bob", "Elijah", and other aliases, was arrested in Florida for the cumulative theft of about $800,000 in cryptocurrency. Sosa used SIM-swapping techniques in order to compromise victims' email and financial account details. In June 2024, the alleged leader of the group, Tyler Buchanan (aka TylerB), was arrested in Spain when attempting to board a flight to Italy. At the time of his arrest, Spanish police allege that Buchanan possessed Bitcoins worth $27 million. In July 2024, the
West Midlands Police West Midlands Police is the territorial police force responsible for policing the metropolitan county of West Midlands (county), West Midlands in England. The force covers an area of with 2.93million inhabitants, which includes the cities of ...
with the help of the FBI arrested a 17-year old juvenile in connection with the MGM cyberattacks. The suspect, who lives in
Walsall Walsall (, or ; locally ) is a market town and administrative centre of the Metropolitan Borough of Walsall, in the West Midlands (county), West Midlands, England. Historic counties of England, Historically part of Staffordshire, it is located ...
and whose name was not published, was released on bail while law enforcement examined his devices. 19-year-old Remington Ogletree was arrested in November 2024 on charges related to his alleged involvement with the group.


References


External links

* Scattered Spider'
page
on the
Cybersecurity and Infrastructure Security Agency The Cybersecurity and Infrastructure Security Agency (CISA) is a component of the United States Department of Homeland Security (DHS) responsible for cybersecurity and infrastructure protection across all levels of government, coordinating cyber ...
's website {{Authority control Hacker groups Cyberattack gangs Cybercrime in the United States