Doppel Email Security is now generally available
The agentic email security solution that empowers you to fight back against social engineering attacks. Detection isn't enough. Disruption is the difference.
Scattered Spider keeps turning help desk trust into initial access. See what changed through 2026 and how to harden resets, MFA, and frontline decisions.

A phone rings at your IT support desk, and the caller claims to be a senior marketing director.
Their phone met a puddle, the replacement device won’t cooperate, and they’re locked out of the company identity system. An executive presentation is in ten minutes. Could you please reset their multi-factor authentication (MFA) (opens in new tab)?
The technician wants to help. The caller knows the right employee details, sounds convincingly stressed, and keeps the clock visible. A password gets reset. A new MFA method gets enrolled. The caller says thanks and hangs up.
The support ticket looks closed. The incident has just opened.
No zero-day and no cinematic hoodie montage. The attacker talked a helpful person into granting legitimate access.
Welcome to the operating theater of Scattered Spider (opens in new tab).
Also tracked under names including UNC3944, 0ktapus, and Octo Tempest, Scattered Spider built its reputation on an awkward truth: It’s often easier to persuade someone with override privileges than to out-code the security stack.
The July 2025 joint advisory (opens in new tab) from CISA, the FBI, and international partners remains the clearest consolidated account of the group’s tactics. Then 2026 supplied a fresh reminder that the playbook still matters: A July Justice Department complaint (opens in new tab) described an alleged member’s role in help desk social engineering, MFA resets, and more than 100 intrusions attributed to the group.
Here’s what the playbook looks like, what recent cases add to the picture, and how to make your help desk a much less accommodating front door.
Despite all the headlines, their primary initial access vector rarely involves complex code. It relies entirely on vishing (voice phishing) and impersonation. They bypass your heavily funded identity access management tools by tricking the people who hold the override keys.
Here’s how they execute the initial breach:
Once the help desk agent clicks that reset button, the attacker has a fully authenticated, legitimate session token. They walk right through the front door.
Scattered Spider started out by heavily targeting telecommunications and business process outsourcing (BPO) companies. But they did not stay there.
The 2025 advisory documented activity across commercial facilities and other sectors, while public reporting connected Scattered Spider-style operations with retail, insurance, and aviation targets. In 2026, enforcement actions added detail without eliminating the threat.
The opening move still leans heavily on social engineering. What happens after access can vary: cloud-data theft, persistence, lateral movement, extortion, and — in some incidents — ransomware. That flexibility is the point. Defenders can’t count on one tidy kill chain.
The 2025 advisory describes actors using compromised credentials to access Snowflake environments and rapidly query and exfiltrate data. The lesson extends beyond one vendor: cloud access inherited through a trusted identity can turn one help desk decision into a major data problem.
The 2025 advisory says actors associated with Scattered Spider used multiple ransomware variants, including DragonForce, and encrypted VMware ESXi environments in some incidents. Data theft and encryption can occur together, but ransomware isn’t required in every intrusion.
When it is time to demand payment, they avoid traditional communication methods that law enforcement can easily trace. They initiate their extortion demands through Tor networks, secure email providers, or encrypted messaging applications like Telegram and Signal, making the negotiation process a nightmare for incident responders.
Whenever a threat actor finds a highly successful, low-barrier-to-entry tactic, the rest of the cybercriminal underground pays attention.
Because Scattered Spider’s help desk social engineering script is now public knowledge — thanks to countless CISA advisories, industry breakdowns, and incident reports—you aren't just defending against the A-team anymore. You are defending against anyone with a microphone.
Less sophisticated actors and lower-tier initial access brokers are currently running the exact same MFA-reset pretexts.
Here’s a look at how the elite syndicate compares to the swarm of copycats currently hitting your IT lines:
Threat trait | Scattered Spider | Copycats |
Initial access | Highly targeted vishing with deep OSINT research and AI voice cloning | Generic, poorly researched help desk calls using leaked employee lists |
Post-access goal | Cloud environment compromise, massive data exfiltration, and ransomware | Basic account takeover, business email compromise, or selling the access to higher-tier brokers |
Technical polish | Uses custom tools to bypass EDR and pivots seamlessly through cloud tenants | Relies entirely on basic, off-the-shelf tools and panics if they hit a segmented network |
Extortion method | DragonForce ransomware and encrypted communication channels | Simple email demands or immediate wire fraud attempts |
Even if a copycat lacks the technical sophistication to deploy DragonForce ransomware, they can still cause massive financial damage just by gaining access to your internal email servers or accounting platforms.
You can’t patch a person, but you can fix the process around them. If a high-risk reset depends on one technician deciding whether a stressed caller “sounds legit,” the attacker gets to choose the most favorable moment.
The goal is to engineer ambiguity out of account recovery. Start with three controls that reinforce one another:
A phone call or chat message shouldn’t be enough to reset a password or enroll a new factor. Use a separate, pre-established channel and an approved verification method that the requester can’t change during the same interaction.
Design the recovery process with your identity and legal teams; a video call by itself can still be spoofed. Manager confirmation, verified-device signals, in-person checks, recovery codes, and documented exception paths can all play a role. The right mix adds deliberate friction where the blast radius justifies it.
Reduce reliance on SMS codes and simple push approvals for sensitive access. CISA recommends phishing-resistant MFA (opens in new tab), including FIDO/WebAuthn-based authenticators. Pair stronger authentication with controls on factor enrollment and recovery; the best key in the world can’t help if the help desk is allowed to replace it after one persuasive phone call.
Help desk teams face a different test than the average employee. Give them role-specific vishing simulations that exercise urgent reset requests, executive impersonation, recovery exceptions, and escalation paths. The objective isn’t to catch people out. It’s to find where the process buckles before an attacker does.
When you analyze the entire Scattered Spider kill chain, you realize almost the entire operation relies on a single, isolated moment of human vulnerability.
Everything the attacker does after the reset is highly technical — navigating Snowflake environments, deploying DragonForce ransomware, and establishing Tor communications. But the reset itself? That is simply a person choosing to trust a voice on the phone.
Strengthening that decision point won’t solve every identity threat. It can remove one of the group’s favorite shortcuts.
Doppel’s helpdesk resilience and security program combines role-specific vishing simulations, threat-informed scenarios, and targeted coaching for the people attackers call when they want an exception. It’s built to exercise real decisions, not merely confirm that someone finished a video.
Teams can practice spotting manufactured urgency, suspicious recovery requests, and pressure to skip steps, then use the results to improve both behavior and process. The help desk won’t become impenetrable — nothing useful is — but it can become a far less profitable target.
Give your IT team something better than a vibe check.
Ready to make urgent reset requests less exciting? Schedule a demo with Doppel to see how targeted vishing simulations and helpdesk resilience programs strengthen the decisions attackers try to exploit.