TL;DR
In the past ten days, Scattered Spider (UNC3944 / Octo Tempest / Muddled Libra) has dominated legal dockets on three continents: a British national pleaded guilty on April 21, 2026 to an $8 million cryptocurrency theft, and a 19-year-old dual US–Estonian citizen named Peter Stokes was arrested in Finland on April 27 while attempting to board a flight to Japan. These are the sixth and seventh known arrests of group members since 2024. The group's operational tempo has not slowed. Law enforcement is playing whack-a-mole against a collective that recruits faster than it loses members. The attack surface — human help desk agents — remains almost entirely undefended at most enterprises.
Background
Scattered Spider first made international headlines in September 2023 when it breached MGM Resorts International and Caesars Entertainment, encrypting MGM's systems and extorting Caesars for a reported $15 million ransom. The group was already known to CISA and CrowdStrike under several tracking designations (UNC3944 by Mandiant, Octo Tempest by Microsoft, Storm-0875 / Muddled Libra by Palo Alto, Scatter Swine by Okta), but the casino attacks turned a niche threat-intel curiosity into a household name.
What set the group apart was not technical sophistication. It was cultural. Scattered Spider's operatives are native English speakers — predominantly US, UK, and Commonwealth nationals in their teens and early twenties — recruited through the broader cybercriminal network known as "The Com." They sound exactly like a stressed employee calling the IT help desk. Because, in voice, they essentially are one.
The group is loosely organized, not a formal criminal enterprise with a hierarchy. Membership is fluid. Some members act as initial access brokers, selling footholds to ransomware affiliates. Others handle the full intrusion chain themselves, affiliating with RaaS platforms to deploy encryption payloads.
Ransomware affiliate history:
- 2023: ALPHV/BlackCat — MGM Resorts, Caesars Entertainment
- 2025: DragonForce — Marks & Spencer (initial access via TCS outsourced help desk), Co-op, Harrods
Technical / Strategic Analysis
Phase 1: Target Selection and OSINT Reconnaissance
Scattered Spider selects targets through a disciplined pre-operation OSINT phase. CrowdStrike's Q2 2025 incident response data documents a clear sector-rotation pattern: US and UK retail through spring, insurance in June, airlines in late June. The group prioritizes organizations with outsourced IT service desks, because a single compromised vendor credential opens doors to multiple client organizations.
Before any call is placed, operators build an impersonation profile using LinkedIn (reporting chain, titles, tenure), SEC filings, conference materials, out-of-office reply harvesting, and data broker aggregation sites. ReliaQuest has documented that skilled operators can assemble a usable pretext in under 15 minutes.
The M&S attack blueprint: The group identified TCS (Tata Consultancy Services) as M&S's outsourced IT desk provider. By impersonating M&S employees with detailed profile data, they bypassed TCS verification protocols, triggered an Active Directory credential reset, then enrolled attacker-controlled MFA devices. DragonForce ransomware was deployed weeks later after lateral movement and data exfiltration.
Phase 2: Vishing the Help Desk
The live phone call is where traditional detection fails entirely. The attacker presents:
- Correct employee name, ID number, and manager's name
- Correct last four of Social Security (sourced from data broker sites, $0.50/record)
- Plausible pretext: new phone, traveling, locked out
- Manufactured urgency: "I'm about to go on stage at a conference"
Call centers do not have behavioral detection engines. They have lookup tables and empathy training. Neither helps when the impersonator has done more research on the target than the target's own colleagues.
MFA bypass chain once credentials are obtained:
1. Attacker authenticates with stolen credential
2. Triggers MFA push to victim's real device
3. Calls victim simultaneously, impersonating IT security: "We detected unusual login, please approve or we'll lock your account"
4. Victim approves the push
5. Alternatively, attacker initiates SIM swap via carrier social engineering or compromised carrier employee access to redirect SMS OTP codes
The average window from initial access to domain admin in the CISA AA23-320A advisory: less than 4 hours.
Phase 3: Persistence and Lateral Movement
Once inside, Scattered Spider demonstrates competent post-exploitation tradecraft. Observed TTPs from CISA joint advisory (AA23-320A, updated July 2025):
- Remote monitoring and management (RMM) tool deployment: ConnectWise, AnyDesk, Splashtop — legitimate tools that bypass EDR signatures
- Identity provider manipulation: Microsoft Entra ID / Azure AD — adding attacker-controlled accounts, modifying Conditional Access policies, disabling MFA for privileged accounts
- Cloud environment abuse: AWS credential harvesting via IMDS (instance metadata service), S3 bucket enumeration, CloudTrail log manipulation
- Data staging and exfiltration: Rclone to actor-controlled cloud storage; MEGA.io observed in multiple cases
- Tunneling: Ngrok, Cloudflare Tunnel for C2 channel persistence that blends with legitimate traffic
The group does not rush. In several documented incidents, the dwell time between initial access and ransomware deployment exceeded three weeks. During that window, they exfiltrate data and identify additional targets for double-extortion leverage.
The Arrest Waves and Why They Haven't Worked
Wave 1 (late 2024–early 2025):
- November 2024: US unseals charges against five members including Tyler Buchanan (UK), Ahmed Hossam Eldin Elbadawy (US), Evans Onyeaka Osiebo (US), Noah Michael Urban (US), Joel Martin Evans (US)
- Urban sentenced to 10 years, $13M restitution, April 2025
Wave 2 (July 2025):
- Four additional suspects arrested in the UK in connection with the M&S and Co-op attacks
Wave 3 (April 2026, ongoing):
- Tyler Buchanan, 24, pleads guilty April 21, 2026 — conspiracy to commit wire fraud, aggravated identity theft. Faces up to 22 years. Buchanan was the group's most senior UK operator.
- Peter Stokes, 19, dual US–Estonian citizen from Chicago, arrested in Finland on approximately April 13 while attempting to board a flight to Japan. Federal complaint filed under seal in Chicago alleges he was a "prolific member" responsible for high-profile intrusions against large corporations.
Why arrests fail as a control: Scattered Spider is not an organization. It is a community. The Com recruits continuously on Telegram and Discord with postings specifying requirements: minimal accent, corporate communication fluency, comfort with phone-based impersonation, ideally previous help desk or BPO work experience. ReliaQuest observed Russian-aligned criminal forums explicitly advertising for native English speakers matching this profile. When a member is arrested, their operational knowledge is not lost to the organization — because there is no organizational knowledge repository. Tactics spread virally through the community. The arrested member's contacts simply continue operating.
The group's 2025–2026 arrest wave has, if anything, accelerated recruitment as remaining members gain status through continued operation and the arrests generate media coverage that serves as advertising for the collective's notoriety.
IOCs / Indicators
The following indicators are drawn from CISA AA23-320A (updated July 2025), Mandiant threat intelligence, and public incident post-mortems. Use for detection, not attribution.
Infrastructure patterns (network):
- RMM tool C2: Domains matching
-support[.]com,-helpdesk[.]net,*-itsupport[.]ioregistered within 30 days of observed intrusion - Phishing infrastructure: Subdomains mimicking corporate identity providers —
okta-[company].com,[company]-sso.com,[company]-vpn.net - DNS over HTTPS usage (DoH via Cloudflare 1.1.1.1 / Google 8.8.8.8) to hide lookups from corporate DNS logging
- Ngrok tunnel connections:
.ngrok.io,.ngrok-free.app
Cloud and Identity IOCs:
- New Azure AD / Entra ID MFA device enrollment from IPs not previously associated with the account
- Conditional Access policy modifications, particularly disabling "require compliant device" for privileged roles
- Rclone process execution with remote cloud storage arguments (
rclone copy --config) - CloudTrail:
CreateUser,AttachUserPolicy,CreateAccessKeyevents in rapid succession from IP not in organizational IP range
Behavioral indicators:
- After-hours help desk call requesting MFA reset or credential change for C-suite or IT admin account
- Employee receives unexpected MFA push simultaneously with incoming call from "IT Security"
- Multiple failed SAML assertion attempts followed immediately by successful assertion from new device/IP
- Bulk email to company employees from internal account (used for out-of-office reply harvesting)
MITRE ATT&CK TTPs:
- T1566.004 — Phishing: Voice (Vishing)
- T1621 — Multi-Factor Authentication Request Generation (MFA fatigue)
- T1078.004 — Valid Accounts: Cloud Accounts
- T1556.006 — Modify Authentication Process: MFA modification
- T1537 — Transfer Data to Cloud Account
- T1219 — Remote Access Software (RMM abuse)
- T1484.002 — Domain Policy Modification: Domain Trust Modification
Lyrie Take
The Lyrie Verdict: Scattered Spider is the clearest proof that the identity perimeter is the new network perimeter — and that it is almost universally undefended. No EDR catches a legitimate phone call. No firewall blocks a help desk agent who has been socially engineered. No MFA policy survives an operator who calls the victim and walks them through approving the push.
>
The AI dimension here is underappreciated. Scattered Spider's current OSINT pipeline takes 15 minutes per target because operators do it manually. With AI-assisted profile generation, that drops to under 60 seconds — and deepfake voice synthesis means the "native English speaker" requirement disappears entirely. The 2026 version of this attack, executed by an AI-augmented operator, will be indistinguishable from a legitimate help desk call by any human listener.
>
The only control that survives this threat class is device-bound, hardware-anchored identity verification — FIDO2 passkeys or hardware security keys that cannot be proxied, phished, or approved by a tricked employee. Any MFA that terminates in a push notification, an SMS code, or a voice confirmation is breakable by this attack chain. This is not a criticism. It is a design constraint that most enterprises have not yet accepted as real.
>
Lyrie's autonomous detection approach addresses this at the behavioral layer: anomaly detection on identity provider events, real-time correlation of help desk ticket creation with MFA enrollment events, and machine-speed response to post-authentication lateral movement — because by the time the human analyst sees the alert, Scattered Spider is already moving.
Defender Playbook
Immediate (0–72 hours):
1. Audit help desk verification procedures. If your IT service desk accepts caller-provided PII (name, employee ID, last 4 SSN) as sufficient for a credential reset, you are one call away from compromise. Require out-of-band, device-bound verification — call back to a pre-registered number or require the employee to initiate the request from an authenticated portal session.
2. Enforce FIDO2 for privileged accounts. Phishing-resistant MFA (hardware keys, passkeys with device binding) is non-negotiable for all accounts with admin rights. TOTP and push-based MFA are documented bypass paths for this group.
3. Monitor for new MFA device enrollment. Alert on any MFA device registration event for accounts with elevated privileges, particularly outside business hours or from new IP addresses.
Short-term (1–4 weeks):
4. Deploy SIEM correlation rules for identity provider events. Flag: new Entra ID / Okta device enrollment + Conditional Access policy change + new privileged account creation within a 2-hour window.
5. Restrict RMM tool installation. Allowlist approved RMM solutions at the endpoint level. ConnectWise and AnyDesk running outside approved deployment channels is a high-fidelity signal.
6. Implement Rclone and cloud sync tool controls. Block or alert on rclone execution, MEGAsync, and similar cloud sync binaries that are not standard in your environment. Exfiltration via these tools precedes ransomware deployment.
Strategic (30–90 days):
7. Run social engineering tabletop exercises targeting your help desk. Hire a red team to attempt vishing your IT service desk with realistic pretexts. The results are reliably humbling and create the organizational will to fix verification processes.
8. Implement just-in-time privileged access. Domain admin rights that exist permanently are an acquisition target. Rights that expire after 4 hours eliminate the value of stolen credentials for lateral movement.
9. Third-party help desk audit. If you outsource your IT service desk, your outsourced provider's verification protocols are your verification protocols. Contractually require and audit them.
Sources
1. US DOJ — British National Pleads Guilty to Hacking Companies and Stealing at Least $8 Million in Virtual Currency (April 21, 2026) — justice.gov
2. Help Net Security — Scattered Spider hacker pleads guilty to stealing $8 million in cryptocurrency (April 21, 2026) — helpnetsecurity.com
3. Chicago Tribune — Teen charged in Chicago was part of international 'Scattered Spider' hacker group, feds say (April 27, 2026) — chicagotribune.com
4. BleepingComputer — US reportedly charges Scattered Spider hacker arrested in Finland (April 28, 2026) — bleepingcomputer.com
5. Trusona — The Scattered Spider Field Manual: How They Pick Targets, Build Profiles, and Make the Call (April 2026) — trusona.com
6. CISA Joint Advisory AA23-320A (updated July 2025) — Scattered Spider — cisa.gov
7. CrowdStrike — Q2 2025 Incident Response Observations: Scattered Spider UK Retail Campaign (2025)
8. Mandiant / Google GTIG — UNC3944 Threat Profile (2025)
9. ReliaQuest — Scattered Spider Domain Infrastructure Analysis (2025)
10. SecurityWeek — British Scattered Spider Hacker Pleads Guilty in the US (April 2026) — securityweek.com
Lyrie.ai Cyber Research Division — Senior Analyst Desk
Lyrie Verdict
Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces — no signature update required.