Scattered Spider
Downtime Duration
n/a
Estimated Costs
n/a
Records Exposed
n/a
Summary
Discover the origins and workings of Scattered Spider, one of the most prominent hacker groups behind some of the most disruptive cyber-attacks in the 21st Century.
Full Analysis
Origins
Scattered Spider was first founded in 2022 by unknown hackers individuals that started out with a campaign to targeting telecommunication and Business Process Outsourcing (BPO) organisations by SIM card swapping and various social engineering tactics to steal credentials and persistently gain access to mobile carrier networks (Parisi, 2022) (Oluoch, 2023). In 2025, prior to the Jaguar Land Rover hack, Scattered Spider reorganised into the group called Scattered Lapsus$ Hunters, representing the merger of several notorious hacker groups including themselves, Lupsus$ and Shiny Hunters (Lakshmanan, 2025).
The group have been referred to by several other names over the years, including Star Fraud, Octo Tempest, Scatter Swine, and Muddled Libra (Oluoch, 2026) (Abrams, 2025).
Structure/hierarchy
It should be important to note that Scattered Spider lacks a hierarchy; it’s less of a gang with a single leader making all the decisions and their lieutenants ensuring their orders are carried out by underlings, but rather a decentralised community of like-minded hackers living across the UK and USA working together over web forums.
Reflecting their structure, Scattered Spider is also believed to be involved in a larger, decentralised cyber-criminal enterprise known as ‘The Com’ (Lakshmanan, 2025) known for its extreme ideological views, violent blackmail and extortion, and even crimes against children (Kapko, 2025).
Prominent attacks
MGS Resort
Scattered Spider first rose to prominence in September 2023 when they launched a cyberattack on MGM resorts, where they used phishing tactics to deploy ransomware that encrypted systems and stole 6 Terabytes of Data for the purpose of collecting a ransom, something that even drew the attention of the FBI (Siddiqui and Bing, 2023). The attack crippled MGM’s main Website as well as systems in their Las Vegas casino location such as ATM machines, hotel passes and slot machines, forcing the resort to revert to manual operations (Ilascu, 2023).
MGM would go on to quickly recover their systems within the same month of the attack, though they lost a staggering $84 million in revenue and even lawsuits to claim compensation for the damages caused by the attack. (Schrader, 2025)
Marks and Spencer
In April 2025, Scattered Spider targeted Marks and Spencer (M&S) to collect a bitcoin ransom. They did this by illicitly accessing M&S’s operating system and unleashing DragonForce malware that simultaneously stole and encrypted data on 9.4 million customers as well as crashed the systems that managed M&S’s customer database and their supply chain (Abrams, 2025).
Whilst M&S eventually recovered, they still suffered severe operational disruption (BBC.com, 2025A) and lost an estimated £43 million in online sales (BBC. com, 2025B). They have never disclosed whether they’d paid the ransom, although there have been no signs that Scattered Spider went through with their plans to leak customer data (ITV.com, 2025).
Jaguar Land Rover
Just at the end of August 2025, Scattered Spider targeted Jaguar Land Rover (JLR) by disrupting their car manufacturing plants across the UK, several disrupting their supply chains both globally and locally, for the purpose of extorting the company (BBC.com, 2025D).
JLR were able to recover their manufacturing plants and eventually resume production, but the effects of the hack extended far beyond that; many local suppliers were hit severely by the hack, being forced to try and access emergency loans. And most damning of all, JLR entering talks with the UK government to accept a £1.5bn private loan, whilst accepting £2bn in new debt from private banks to support them (Jolly, 2025). Considering how the hack led to a 0.1% drop in UK GDP in September as well as 23.8% drop in car production in an economy showing flatlining output (Conway, 2025), the impact of this hack alone creates ominous implications of the future.
Transport for London
In 2024, Transport for London (TFL)’s main internal systems and database was hacked, leading to the personal data of 10 million people being stolen (BBC.com, 2026A) and many of their services, including message boards, online services and TFL’s oyster travel card system, leaving customers confused and unable to properly travel. Services would remain severely disrupted for the next 3 months, leading to TFL losing £39m in damages (BBC.com, 2026C) and thousands of customers contacted to inform them that their personal data had been stolen .
It was concluded that the hackers were motivated not just for financial reasons, but to gain social standing within Scattered Spider and even bragging rights (Milmo and Pinner 2026).
Ransomware and Technology
Scattered Spider’s ‘Modis operandi’ is to use social engineering tactics like email and SMS phishing, SIM swapping and vulnerability exploits to trick unsuspecting employees into allowing ransomware into systems, at which point they gain access and steal data, encrypting systems as they go to the point of critical failure. Their digital equipment includes tools like malicious driver software STONESTOP and POORTRY (Oluoch, 2026), as well as ransomware developed by other groups like DragonForce.
They usually coordinate attacks and communicate using online forums and chatrooms hosted on websites like Telegram and Discord, as is with the JLR and M&S hacks, where they planned and even bragged about the strikes (Abrams, 2025) (BBC.com, 2025C).
Arrests
In July 2025, Four individuals were arrested by the police in Staffordshire, London and the West Midlands for ‘Computer Misuse Act offences, blackmail, money laundering and participating in the activities of an organised crime group’. The four are believed to be connected to the M&S attacks as well as preceding attacks on Co-op and Harrods. (BBC.com, 2025I)
In September 2025, shortly after the JLR hack, four adults from Staffordshire, the West Midlands and London were arrested by the National Crime Agency for the crime. However, all members have since been released on bail (BBC.com, 2025D).
In response to the TFL hack, two people were arrested in 2024, shortly after the hack. The hackers were Thalha Jubair and Owen Flowers, a pair of mentally ill young adults who had direct contact with Scattered Spider and had gone under the radar of the West Midlands police for computer misuse offences, who tried to guide them away from a life of cybercrime using training and social service programs (Milmo and Pinner 2026). Jubair and Flowers eventually pled guilty to computer misuse and causing severe damage and were both sentenced to 5 years and 6 months in prison (NCA.org, 2026).
Most recently in July 2026, a US-Estonian national with suspected ties to Scattered Spider was arrested in Finland and extradited to the USA on charges of fraud, conspiracy and illegal computer intuition after he and other operatives hacked a US jewelery company to try and extort $8m in cryptocurrency (BBC.com, 2026B).
Conclusion
Scattered Spider has proven to be a consistent threat to businesses across the world, from the biggest corporations to your local Small to Medium Businesses (SMBs). And whilst they are financially driven like many other hacker groups, their perception of hacking the biggest companies, and causing the most confusion and disruption, all just for fun is arguably their most devious characteristic. To them, this is a game. To small businesses, it can be a matter of life and death. A matter that requires the most seamless of solutions to keep them safe and secure.
Sources
- Abrams, L (2025): Marks & Spencer breach linked to Scattered Spider ransomware attack. News Article published by Bleepingcomputer.com: https://www.bleepingcomputer.com/news/security/marks-and-spencer-breach-linked-to-scattered-spider-ransomware-attack/
- BBC.com (2025A): M&S supplier resorts to pen and paper after cyber attack. Online News Article published by BBC.com: https://www.bbc.co.uk/news/articles/cvgnyplvdv8o
- BBC.com (2025B): When will I be able to shop online at M&S again? Online News Article published by BBC.com: https://www.bbc.co.uk/news/articles/c0el31nqnpvo
- BBC.com (2025C): M&S hackers claim to be behind Jaguar Land Rover cyber attack. Online News Article published by BBC.com: https://www.bbc.co.uk/news/articles/c4gqepe5355o
- BBC.com (2025D): M&S hackers claim to be behind Jaguar Land Rover cyber attack. Online News Article published by BBC.com: https://www.bbc.co.uk/news/articles/c4gqepe5355o
- BBC.com (2026A): TfL hack in 2024 affected around 10 million people, BBC can reveal. Online News Article published by BBC.com: https://www.bbc.co.uk/news/articles/cz0ggkr2g77o
- BBC.com (2026B): Alleged Scattered Spider hacker arrested in Finland. Online News Article published by BBC.com: https://www.bbc.co.uk/news/articles/cwy0we4yw1lo
- BBC.com (2026C): Two men plead guilty over £39m TfL cyber attack. Online News Article published by BBC.com: https://www.bbc.co.uk/news/articles/czx5yp9qy0do
- Conway, E (2025): Budget 2025: The extraordinary impact of a crime on UK growth that Reeves could do without. Online News Article published by news.sky.com: https://news.sky.com/story/budget-2025-the-extraordinary-impact-of-a-crime-on-uk-growth-that-reeves-could-do-without-13469485
- Ilascu, I (2023): MGM Resorts shuts down IT systems after cyberattack. News Article published by Bleepingcomputer.com: https://www.bleepingcomputer.com/news/security/mgm-resorts-shuts-down-it-systems-after-cyberattack/
- ITV.com (2025): M&S resumes online orders six weeks after cyber attack. Online News Article Published by ITV.com: https://www.itv.com/news/2025-06-10/m-and-s-resumes-online-orders-six-weeks-after-cyber-attack
- Jolly, J (2025): Jaguar Land Rover parts makers asked by banks to put up homes as loan security after hack. Online News Article published by theguradian.com: https://www.theguardian.com/business/2025/oct/01/jaguar-land-rover-suppliers-asked-to-put-up-homes-as-loan-security-after-hack
- Kapko, M (2025): FBI alerts tie together threats of cybercrime, physical violence from The Com. Onlien News Article Published by cyberscoop.com: https://cyberscoop.com/fbi-warning-the-com-cybercrime-extortion-violence/
- Lakshmanan, R (2025): A Cybercrime Merger Like No Other — Scattered Spider, LAPSUS$, and ShinyHunters Join Forces. Online News Article published by thehackernews.com: https://thehackernews.com/2025/11/a-cybercrime-merger-like-no-other.html
- Milmo, D; and Pinner, J (2026): ‘Keys to the kingdom’: hackers who gained access to heart of London transport network jailed. Online News Article published by theguardian.com: https://www.theguardian.com/technology/2026/jul/16/hackers-2024-cyber-attack-transport-for-london-tfl-jailed
- NCA.org (2026): Two sentenced for hacking Transport for London in UK’s biggest ever cyber crime case. Online News Article published by the National Crime Agency: https://www.nationalcrimeagency.gov.uk/news/two-sentenced-for-hacking-transport-for-london-in-uk-s-biggest-ever-cyber-crime-case
- Oluoch, P (2023): Scattered Spider: The Modus Operandi. Online blog published by Trellix.com: https://www.trellix.com/blogs/research/scattered-spider-the-modus-operandi/
- Parisi, T (2022): Not a SIMulation: CrowdStrike Investigations Reveal Intrusion Campaign Targeting Telco and BPO Companies. Online News Blog published by Crowdstrike.com: https://www.crowdstrike.com/en-us/blog/analysis-of-intrusion-campaign-targeting-telecom-and-bpo-companies/
- Schrader, D (2025): An Overview of the MGM Cyber Attack. Online Blog published by netwrix.com: https://netwrix.com/en/resources/blog/mgm-cyber-attack/
- Siddiqui, Z; and Bing, C (2023): MGM Resorts breached by ‘Scattered Spider’ hackers. Online News Article published by Reuters.com: https://www.reuters.com/technology/moodys-says-breach-mgm-is-credit-negative-disruption-lingers-2023-09-13/