Scattered Spider's Social Engineering: Experts & Governments Urge Stronger Help Desk Verification
Finn Jensen | Founder, FastPasscorp
How many warnings do we need before we understand that our IT help desk can be a critical backdoor to our IT systems, easily exploited by sophisticated hackers like Scattered Spider? The threat is real, and the consequences can be devastating.
Recent breaches at major UK retailers like Marks & Spencer, Co-op, and Harrods, attacks at US insurance companies, Australian Airline Qantas etc this year serve as stark reminders. In all three attacks, the modus operandi was strikingly similar: the threat actors leveraged social engineering tactics associated with the infamous Scattered Spider group to gain initial access, often by tricking help desk agents into resetting passwords or modifying MFA settings, ultimately leading to the deployment of DragonForce ransomware.
The Experts Are Speaking: Heed Their Warnings
Leading cybersecurity authorities are sounding the alarm, emphasizing the critical need to fortify help desk security:
John Hultquist, Chief Analyst at Google Threat Intelligence Group (GTIG), explicitly states that companies must "pay particular attention to potential social engineering attempts on help desk and call centers." GTIG recommends segregating identities, using strong authentication criteria, and implementing rigorous identity controls for password resets and MFA registration. They also recently warned that Scattered Spider has expanded its targeting to include US insurance companies, further highlighting the pervasive nature of this threat.
Similarly, the U.K.’s National Cyber Security Centre (NCSC), in the wake of the retail breaches, has shared crucial tips for organizations to improve their cybersecurity defenses. A key piece of advice from the NCSC is for organizations to "review how the helpdesk service authenticates credentials before resetting them, especially for employees with elevated privileges." Their recommendations also include activating multi-factor authentication, monitoring for unauthorized logins, and meticulously checking for legitimate access to highly privileged accounts like Domain Admin and Cloud Admin.
The Unanswered Question: How Do We Truly Verify Identity?
Despite these vital recommendations, a fundamental challenge remains: how can a help desk agent truly verify the person at the other end of the phone line? Common sense, general education, or even strict written instructions often prove insufficient against a skilled social engineer. These threat actors are adept at manipulating human trust, using publicly available information and even aggressive language to scare targets into compliance.
Scattered Spider, a fluid coalition of threat actors, thrives on these sophisticated social engineering attacks to bypass even mature security programs. They exploit human vulnerabilities, often impersonating employees or contractors to deceive IT help desks into granting unauthorized access, including adding unauthorized MFA devices or performing self-service password resets.
The Solution: Automated, Forced Verification Workflows
The most robust answer lies not in relying solely on human judgment, but in implementing an automated workflow integrated directly with your IT Service Management (ITSM) system. This forces help desk agents to utilize a stringent process for all critical validation situations, ensuring absolute certainty about who they are communicating with.
This is precisely where FastPass Identity Verification Manager comes in. Our system provides this essential automated verification, integrating seamlessly with common ITSM platforms like ServiceNow and major MFA providers such as OKTA, Duo, and TOTP Authenticators. Available both on-premise and in the cloud, FastPass Identity Verification Manager is designed to remove human error and emotion from the identity verification process, providing dynamic and contextual data to ensure secure identity checks.
Don't Be the Next Victim. Protect Your Organization.
The warnings are clear, and the attacks are happening now. Don't wait to become the next host for Scattered Spiders.
Contact FastPassCorp today to discuss how our Identity Verification Manager can protect your organization against these sophisticated social engineering attacks and secure your help desk against critical breaches.
Learn more about Scattered Spider and their evolving tactics in this detailed article: Google Warns Scattered Spider Hackers Now Target US Insurance Companies