{"id":24992,"date":"2025-06-29T17:08:10","date_gmt":"2025-06-29T17:08:10","guid":{"rendered":"https:\/\/www.europesays.com\/us\/24992\/"},"modified":"2025-06-29T17:08:10","modified_gmt":"2025-06-29T17:08:10","slug":"fbi-warning-issued-as-2fa-bypass-attacks-surge-get-prepared","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/24992\/","title":{"rendered":"FBI Warning Issued As 2FA Bypass Attacks Surge \u2014 Get Prepared"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2025\/06\/1751216890_202_960x0.jpg\" alt=\"The Federal Bureau of Investigation seal is displayed on a mobile phone screen with open laptop in background.\" data-height=\"3621\" data-width=\"5431\" style=\"position:absolute;top:0\"\/><\/p>\n<p class=\"color-body light-text\" role=\"button\">The FBI issues Scattered Spider attack warning.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Update, June 29, 2025: This story, originally published on June 28, has been updated with expert comment from cybersecurity professionals regarding the Scattered Spider threat group referenced in the latest FBI 2fa-bypass attack warning.<\/p>\n<p>When the Federal Bureau of Investigation issues a cybersecurity alert, you would be well advised to pay attention and take action. Whether that\u2019s involving <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/09\/fbi-warns-iphone-and-android-messaging-app-users-not-to-click\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/09\/fbi-warns-iphone-and-android-messaging-app-users-not-to-click\/\" target=\"_self\" aria-label=\"malicious SMS messages\" rel=\"nofollow noopener\">malicious SMS messages<\/a>, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/28\/new-fbi-attack-warning---hang-up-and-do-this-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/28\/new-fbi-attack-warning---hang-up-and-do-this-now\/\" target=\"_self\" aria-label=\"AI-powered phishing\" rel=\"nofollow noopener\">AI-powered phishing<\/a> attacks, or, as I recently reported, the skyrocketing number of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/07\/fbi-issues-critical-cyberattack-alert---act-now-as-victims-skyrocket\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/07\/fbi-issues-critical-cyberattack-alert---act-now-as-victims-skyrocket\/\" target=\"_self\" aria-label=\"ransomware threats\" rel=\"nofollow noopener\">ransomware threats<\/a>. And ransomware is the subject of this latest, critical, warning from the FBI. This time involving the Scattered Spider threat group which has made headlines after taking responsibility for multiple retail sector attacks including that against Marks &amp; Spencer in the U.K. which is estimated to have cost the high street chain at least <a class=\"color-link\" href=\"https:\/\/www.insurancetimes.co.uk\/news\/cost-of-mands-and-co-op-cyber-attacks-up-to-440m-cmc\/1455580.article\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.insurancetimes.co.uk\/news\/cost-of-mands-and-co-op-cyber-attacks-up-to-440m-cmc\/1455580.article\" aria-label=\"$600 million\">$600 million<\/a>. Now the group is targeting the airline industry, the FBI has warned, both directly and through the entire supply chain. Here\u2019s what you need to know.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-3\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" target=\"_blank\" aria-label=\"11 Million Critical Vulnerabilities Exposed \u2014 Act Now\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\">Forbes11 Million Critical Vulnerabilities Exposed \u2014 Act NowBy Davey Winder<\/a><\/p>\n<p>FBI Confirms Scattered Spider Attacks Targeting Transportation<\/p>\n<p>A June 26 <a class=\"color-link\" href=\"https:\/\/www.halcyon.ai\/blog\/scattered-spider-tactics-observed-amid-shift-to-us-targets\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.halcyon.ai\/blog\/scattered-spider-tactics-observed-amid-shift-to-us-targets\" aria-label=\"report\">report<\/a> from ransomware analysts at Halcyon warned that there were \u201cindications that Scattered Spider is also now targeting the Food, Manufacturing, and Transportation (particularly Aviation) sectors in the US.\u201d This has now been confirmed by the FBI which provided a statement to me by email that said: \u201cThe FBI has recently observed the cybercriminal group Scattered Spider expanding its targeting to include the airline sector.\u201d<\/p>\n<p>The statement, also <a class=\"color-link\" href=\"https:\/\/x.com\/FBI\/status\/1938746767031574565\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/x.com\/FBI\/status\/1938746767031574565\" aria-label=\"posted to X\">posted to X<\/a>, fomrerly known as Twitter, continued to confirm that the ransomware group is using the same methods during this surge of attacks into new sectors, namely \u201csocial engineering techniques, often impersonating employees or contractors to deceive IT help desks into granting access.\u201d<\/p>\n<p>Specifically, Scattered Spider looks to bypass mutli-factor authentication, commonly referred to as MFA or 2FA, by using various methods to get those help desks to \u201cadd unauthorized MFA devices to compromised accounts.\u201d<\/p>\n<p>Scattered Spider has been on the FBI radar for a number of years, with a <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-320a\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-320a\" aria-label=\"joint cybersecurity advisory\">joint cybersecurity advisory<\/a> alongside the Cybersecurity and Infrastructure Security Agency published in 2023 in response to what it described as \u201cactivity by Scattered Spider threat actors against the commercial facilities sectors and subsectors.\u201d<\/p>\n<p>The FBI told me that it is currently actively working with aviation and industry partners \u201cto address this activity and assist victims,\u201d and urged anyone who thinks their organization may have been targeted to contact their local FBI office. In the meantime, beware of anyone asking for unauthorized 2FA devices to be added to accounts and follow established security processes and procedures to the letter, no matter what the person making the request may say.<\/p>\n<p> <a class=\"embed-base color-body color-body-border link-embed embed-4\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/warning-some-kind-of-god-hacker-demands-1650-for-your-sins\/\" target=\"_blank\" aria-label=\"Warning: \u2018Some Kind Of God\u2019 Hacker Demands $1,650 For Your Sins\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/warning-some-kind-of-god-hacker-demands-1650-for-your-sins\/\">ForbesWarning: \u2018Some Kind Of God\u2019 Hacker Demands $1,650 For Your SinsBy Davey Winder<\/a><br \/>\nFBI Warned Of Aviation Attacks, But Insurance Sector Also Now Being Targeted By Scattered Spider<\/p>\n<p>Although the latest FBI warning focused on current attack threats targeting the transportation, and specifically aviation, sector and its supply chain, Scattered Spider has also expanded to include the insurance industry in its crosshairs. &#8220;Google Threat Intelligence Group is now aware of multiple intrusions in the US which bear all the hallmarks of Scattered Spider activity,\u201d John Hultquist, the chief analyst with the Google Threat Intelligence Group, has said, \u201cwe are now seeing incidents in the insurance industry.\u201d<\/p>\n<p>Jon Abbott, CEO at ThreatAware, prudently advised that while \u201cthe rising tide of attacks on US insurers\u201d is a serious threat that should not be underestimated, it also represents \u201ca warning for other industries to stay vigilant.\u201d Although the Scattered Spider group has historically leaned towards targeting one industry sector at a time, there is a danger that, as aviation is now in the spotlight, other organizations take their eye off the remaining peril in front of them.<\/p>\n<p>With one common denominator between many attacks being the exploitation of the supply chain, with such compromise enabling lateral movement onto bigger fish, this is evidence that businesses that might not consider themselves in the aviation, insurance or retail sectors are still at risk.<\/p>\n<p>Richard Orange, a vice president at Abnormal AI, reiterates what the FBI has said. \u201cThis group relies on social engineering rather than technical exploits,\u201d Orange said, \u201cand bypasses traditional security controls by manipulating people, such as posing as IT staff or trusted partners.\u201d This can often appear like an isolated incident or breach, but Scattered Spider will move laterally, Orange concluded, \u201charvesting credentials to deceive other departments, customers, and partners.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/27\/windows-warning-issued-as-printers-used-in-new-hack-attacks\/\" target=\"_blank\" aria-label=\"Windows Warning Issued As Printers Used In New Hack Attacks\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/27\/windows-warning-issued-as-printers-used-in-new-hack-attacks\/\">ForbesWindows Warning Issued As Printers Used In New Hack AttacksBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"The FBI issues Scattered Spider attack warning. NurPhoto via Getty Images Update, June 29, 2025: This story, originally&hellip;\n","protected":false},"author":3,"featured_media":24993,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[22353,22358,64,22359,22352,22357,22351,22360,22354,22356,22355,67,132,68],"class_list":{"0":"post-24992","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"tag-2fa","9":"tag-airlines-cyberattack","10":"tag-business","11":"tag-clickfix","12":"tag-fbi-alert","13":"tag-fbi-ransomware-alert","14":"tag-fbi-warning","15":"tag-it-help-desk-hack","16":"tag-mfa","17":"tag-ransomware","18":"tag-scattered-spider","19":"tag-united-states","20":"tag-unitedstates","21":"tag-us"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/114767758794700379","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/24992","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=24992"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/24992\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/24993"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=24992"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=24992"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=24992"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}