Cookie Consent by Free Privacy Policy Generator

Scattered Spider Leaders Sentenced to 66 Months in UK

Two leading members of the Scattered Spider cybercriminal group have been sentenced in the UK to 66 months in prison. Thalha Jubair and Owen Flowers were identified as leaders who directed many of the attacks attributed to the group, which is also known as a subset of The Com. US authorities had previously accused Jubair of participating in at least 120 attacks. Scattered Spider gained significant attention for high-profile breaches targeting major organisations, often using social engineering techniques such as calling help desks to reset credentials, followed by exploitation of cloud environments and identity systems. The group's tactics have been characterised by their use of legitimate tools, stolen credentials and an understanding of how enterprise IT and cloud infrastructure operate. The sentencing represents a significant enforcement action against a group that has caused substantial disruption to organisations in the UK, US and beyond.

Why this matters for UK organisations

Scattered Spider's attacks have frequently targeted sectors including hospitality, retail, technology and managed services, often resulting in data theft, ransomware deployment and significant operational disruption. The group's methods, particularly their reliance on social engineering and abuse of identity and access management weaknesses, reflect broader trends in how attackers are bypassing traditional perimeter defences. Rather than exploiting complex technical vulnerabilities, Scattered Spider operators have demonstrated that convincing a help desk operator to reset a password or gaining access to a single set of credentials can provide a direct route into cloud environments, SaaS platforms and critical business systems. For UK organisations, the case underscores the importance of resilience against social engineering, robust identity controls and the need for clear processes around credential resets and privileged access. The operational risk is not limited to large enterprises; any organisation with a help desk, IT support function or cloud environment is potentially vulnerable to these techniques.

What to review

UK businesses should review how help desk and IT support processes handle credential resets, particularly for privileged or administrative accounts. Consider whether your teams have sufficient training to recognise social engineering attempts, whether there are verification procedures in place before credentials are reset or access is granted, and whether multi-factor authentication is enforced across all access points including help desk tools, cloud platforms and administrative interfaces. Review whether there are monitoring controls in place to detect unusual credential activity, such as password resets followed by immediate login from unusual locations, or changes to privileged accounts outside normal business hours. Consider whether there is a clear escalation process for suspicious requests, whether help desk staff feel empowered to challenge requests that seem unusual, and whether there are regular exercises or simulations to test how well these processes hold up under pressure. Ensure there is clear ownership for identity and access management across IT, security and business teams, and that there is a process for reviewing and improving these controls based on emerging threats and lessons learned from incidents.

Source: CyberScoop

News and blog posts
Today's stories reflect a recurring theme: attackers are targeting the...
Cybersecurity researchers have identified a new software supply chain attack...
Two leading members of the Scattered Spider cybercriminal group have been...
Hugging Face, the world's largest repository of AI models and a widely used...