{"id":27358,"date":"2025-06-30T14:45:10","date_gmt":"2025-06-30T14:45:10","guid":{"rendered":"https:\/\/www.europesays.com\/us\/27358\/"},"modified":"2025-06-30T14:45:10","modified_gmt":"2025-06-30T14:45:10","slug":"fbi-warning-issued-as-2fa-bypass-attacks-surge-get-prepared-2","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/27358\/","title":{"rendered":"FBI Warning Issued As 2FA Bypass Attacks Surge \u2014 Get Prepared"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.europesays.com\/us\/wp-content\/uploads\/2025\/06\/1751216890_202_960x0.jpg\" alt=\"The Federal Bureau of Investigation seal is displayed on a mobile phone screen with open laptop in background.\" data-height=\"3621\" data-width=\"5431\" style=\"position:absolute;top:0\"\/><\/p>\n<p class=\"color-body light-text\" role=\"button\">The FBI issues Scattered Spider attack warning.<\/p>\n<p>NurPhoto via Getty Images<\/p>\n<p>Update, June 30, 2025: This story, originally published on June 28, has been updated with an in-depth analysis of the Scattered Spider threat group, along with expert comment from cybersecurity professionals as the FBI warns that the dangerous threat actors are now moving into a new sector to attack: transportation. <\/p>\n<p>When the Federal Bureau of Investigation issues a cybersecurity alert, you would be well advised to pay attention and take action. Whether that\u2019s involving <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/09\/fbi-warns-iphone-and-android-messaging-app-users-not-to-click\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/09\/fbi-warns-iphone-and-android-messaging-app-users-not-to-click\/\" target=\"_self\" aria-label=\"malicious SMS messages\" rel=\"noopener\">malicious SMS messages<\/a>, <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/28\/new-fbi-attack-warning---hang-up-and-do-this-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/05\/28\/new-fbi-attack-warning---hang-up-and-do-this-now\/\" target=\"_self\" aria-label=\"AI-powered phishing\" rel=\"noopener\">AI-powered phishing<\/a> attacks, or, as I recently reported, the skyrocketing number of <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/07\/fbi-issues-critical-cyberattack-alert---act-now-as-victims-skyrocket\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/07\/fbi-issues-critical-cyberattack-alert---act-now-as-victims-skyrocket\/\" target=\"_self\" aria-label=\"ransomware threats\" rel=\"noopener\">ransomware threats<\/a>. And ransomware is the subject of this latest, critical, warning from the FBI. This time involving the Scattered Spider threat group which has made headlines after taking responsibility for multiple retail sector attacks including that against Marks &amp; Spencer in the U.K. which is estimated to have cost the high street chain at least <a class=\"color-link\" href=\"https:\/\/www.insurancetimes.co.uk\/news\/cost-of-mands-and-co-op-cyber-attacks-up-to-440m-cmc\/1455580.article\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.insurancetimes.co.uk\/news\/cost-of-mands-and-co-op-cyber-attacks-up-to-440m-cmc\/1455580.article\" aria-label=\"$600 million\">$600 million<\/a>. Now the group is targeting the airline industry, the FBI has warned, both directly and through the entire supply chain. Here\u2019s what you need to know.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/30\/googles-android-warning-for-3-billion-users-change-this-setting-now\/\" target=\"_blank\" aria-label=\"Google\u2019s Android Warning For 3 Billion Users: Change This Setting Now\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/30\/googles-android-warning-for-3-billion-users-change-this-setting-now\/\">ForbesGoogle\u2019s Android Warning For 3 Billion Users: Change This Setting NowBy Davey Winder<\/a><\/p>\n<p>FBI Confirms Scattered Spider Attacks Targeting Transportation<\/p>\n<p>A June 26 <a class=\"color-link\" href=\"https:\/\/www.halcyon.ai\/blog\/scattered-spider-tactics-observed-amid-shift-to-us-targets\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.halcyon.ai\/blog\/scattered-spider-tactics-observed-amid-shift-to-us-targets\" aria-label=\"report\">report<\/a> from ransomware analysts at Halcyon warned that there were \u201cindications that Scattered Spider is also now targeting the Food, Manufacturing, and Transportation (particularly Aviation) sectors in the US.\u201d This has now been confirmed by the FBI which provided a statement to me by email that said: \u201cThe FBI has recently observed the cybercriminal group Scattered Spider expanding its targeting to include the airline sector.\u201d<\/p>\n<p>The statement, also <a class=\"color-link\" href=\"https:\/\/x.com\/FBI\/status\/1938746767031574565\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/x.com\/FBI\/status\/1938746767031574565\" aria-label=\"posted to X\">posted to X<\/a>, fomrerly known as Twitter, continued to confirm that the ransomware group is using the same methods during this surge of attacks into new sectors, namely \u201csocial engineering techniques, often impersonating employees or contractors to deceive IT help desks into granting access.\u201d<\/p>\n<p>Specifically, Scattered Spider looks to bypass mutli-factor authentication, commonly referred to as MFA or 2FA, by using various methods to get those help desks to \u201cadd unauthorized MFA devices to compromised accounts.\u201d<\/p>\n<p>Scattered Spider has been on the FBI radar for a number of years, with a <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-320a\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-320a\" aria-label=\"joint cybersecurity advisory\">joint cybersecurity advisory<\/a> alongside the Cybersecurity and Infrastructure Security Agency published in 2023 in response to what it described as \u201cactivity by Scattered Spider threat actors against the commercial facilities sectors and subsectors.\u201d<\/p>\n<p>The FBI told me that it is currently actively working with aviation and industry partners \u201cto address this activity and assist victims,\u201d and urged anyone who thinks their organization may have been targeted to contact their local FBI office. In the meantime, beware of anyone asking for unauthorized 2FA devices to be added to accounts and follow established security processes and procedures to the letter, no matter what the person making the request may say.<\/p>\n<p> <a class=\"embed-base color-body color-body-border link-embed embed-7\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\" target=\"_blank\" aria-label=\"11 Million Critical Vulnerabilities Exposed \u2014 Act Now\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/11-million-critical-vulnerabilities-exposed---act-now\/\">Forbes11 Million Critical Vulnerabilities Exposed \u2014 Act NowBy Davey Winder<\/a><br \/>\nWho, Or What, Is Scattered Spider?<\/p>\n<p>The Reliaquest Threat Research Team has published an in-depth analysis of the <a class=\"color-link\" href=\"https:\/\/reliaquest.com\/blog\/scattered-spider-cyber-attacks-using-phishing-social-engineering-2025\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/reliaquest.com\/blog\/scattered-spider-cyber-attacks-using-phishing-social-engineering-2025\/\" aria-label=\"Scattered Spider\">Scattered Spider<\/a> threat group behind the attacks as referenced in the latest FBI cybersecurity warning.<\/p>\n<p>The headline pullouts from the analysis are that 81% of the Scattered Spider domains impersonate technology vendors, with system administrators and executives, anyone likely to possess high-value credentials in other words, in the crosshairs. Leveraging phishing frameworks like Evilginx, and social engineering methods including video calls, initial access into targets such as the technology, finance,and retail trade sectors, has made Scattered Spider a threat to be taken very seriously indeed. Beyond the headline key points, however, lies the in-depth analysis of the hackers.<\/p>\n<p>Scattered Spider is a financially motivated cybercriminal organization heavily associated with The Community, a well-known yet loosely knit hacking collective. \u201cThrough strategic alliances with major ransomware operators ALPHV, RansomHub, and DragonForce,\u201d the Reliaquest report said, Scattered Spice has been able to gain access to the tools it needs. Of most concern, however, has been the collaboration between with Russia-aligned threat groups and English-speaking threat actors. Scattered Spider has exploited this to perfection in order to deliver highly polished impersonation attacks, the kind of which are at the heart of many of its exploits.To further refine such impersonation tactics, social engineers with \u201chighly specific qualifications\u201d are being recruited, the report said. There are requirements such as no accent or a specific geographic one, a good level of fluency in the English language, and the understanding that working hours align with Western business times.<\/p>\n<p>\u201cCallers are also provided with detailed scripts and real-time guidance from a so-called curator to help them handle any situation during the call,\u201d Reliaquest said, adding that targets are specified to be outside of Russia and the Commonwealth of Independent States. The collaboration, Reliaquest concluded, \u201ccombines technical expertise with cultural fluency, enabling attackers to convincingly impersonate employees and leadership, bypass security protocols, and exploit trust-based systems like help desks.\u201d<\/p>\n<p>Reliaquest said that it anticipates Scattered Spider adopting AI-powered attack methodologies in the near future, streamlining the group\u2019s ability to manipulate trust-based systems such as IT help desks.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-8\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/warning-some-kind-of-god-hacker-demands-1650-for-your-sins\/\" target=\"_blank\" aria-label=\"Warning: \u2018Some Kind Of God\u2019 Hacker Demands $1,650 For Your Sins\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/29\/warning-some-kind-of-god-hacker-demands-1650-for-your-sins\/\">ForbesWarning: \u2018Some Kind Of God\u2019 Hacker Demands $1,650 For Your SinsBy Davey Winder<\/a><br \/>\nFBI Warned Of Aviation Attacks, But Insurance Sector Also Now Being Targeted By Scattered Spider<\/p>\n<p>Although the latest FBI warning focused on current attack threats targeting the transportation, and specifically aviation, sector and its supply chain, Scattered Spider has also expanded to include the insurance industry in its crosshairs. &#8220;Google Threat Intelligence Group is now aware of multiple intrusions in the US which bear all the hallmarks of Scattered Spider activity,\u201d John Hultquist, the chief analyst with the Google Threat Intelligence Group, has said, \u201cwe are now seeing incidents in the insurance industry.\u201d<\/p>\n<p>Jon Abbott, CEO at ThreatAware, prudently advised that while \u201cthe rising tide of attacks on US insurers\u201d is a serious threat that should not be underestimated, it also represents \u201ca warning for other industries to stay vigilant.\u201d Although the Scattered Spider group has historically leaned towards targeting one industry sector at a time, there is a danger that, as aviation is now in the spotlight, other organizations take their eye off the remaining peril in front of them.<\/p>\n<p>With one common denominator between many attacks being the exploitation of the supply chain, with such compromise enabling lateral movement onto bigger fish, this is evidence that businesses that might not consider themselves in the aviation, insurance or retail sectors are still at risk.<\/p>\n<p>Richard Orange, a vice president at Abnormal AI, reiterates what the FBI has said. \u201cThis group relies on social engineering rather than technical exploits,\u201d Orange said, \u201cand bypasses traditional security controls by manipulating people, such as posing as IT staff or trusted partners.\u201d This can often appear like an isolated incident or breach, but Scattered Spider will move laterally, Orange concluded, \u201charvesting credentials to deceive other departments, customers, and partners.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/27\/windows-warning-issued-as-printers-used-in-new-hack-attacks\/\" target=\"_blank\" aria-label=\"Windows Warning Issued As Printers Used In New Hack Attacks\" rel=\"noopener noreferrer\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/27\/windows-warning-issued-as-printers-used-in-new-hack-attacks\/\">ForbesWindows Warning Issued As Printers Used In New Hack AttacksBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"The FBI issues Scattered Spider attack warning. NurPhoto via Getty Images Update, June 30, 2025: This story, originally&hellip;\n","protected":false},"author":3,"featured_media":24993,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[22353,22358,64,22359,22352,22357,22351,22360,22354,22356,22355,67,132,68],"class_list":{"0":"post-27358","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"tag-2fa","9":"tag-airlines-cyberattack","10":"tag-business","11":"tag-clickfix","12":"tag-fbi-alert","13":"tag-fbi-ransomware-alert","14":"tag-fbi-warning","15":"tag-it-help-desk-hack","16":"tag-mfa","17":"tag-ransomware","18":"tag-scattered-spider","19":"tag-united-states","20":"tag-unitedstates","21":"tag-us"},"share_on_mastodon":{"url":"https:\/\/pubeurope.com\/@us\/114772857786041704","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/27358","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=27358"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/27358\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/24993"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=27358"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=27358"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=27358"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}