How to defend the full social engineering attack chain | Register for the webinar to learn more

Research

Scattered Spider’s Playbook: What You Need to Know in 2026

Scattered Spider keeps turning help desk trust into initial access. See what changed through 2026 and how to harden resets, MFA, and frontline decisions.

Scattered Spider’s Playbook: What You Need to Know in 2026

A phone rings at your IT support desk, and the caller claims to be a senior marketing director.

Their phone met a puddle, the replacement device won’t cooperate, and they’re locked out of the company identity system. An executive presentation is in ten minutes. Could you please reset their multi-factor authentication (MFA) (opens in new tab)?

The technician wants to help. The caller knows the right employee details, sounds convincingly stressed, and keeps the clock visible. A password gets reset. A new MFA method gets enrolled. The caller says thanks and hangs up.

The support ticket looks closed. The incident has just opened.

No zero-day and no cinematic hoodie montage. The attacker talked a helpful person into granting legitimate access.

Welcome to the operating theater of Scattered Spider (opens in new tab).

Also tracked under names including UNC3944, 0ktapus, and Octo Tempest, Scattered Spider built its reputation on an awkward truth: It’s often easier to persuade someone with override privileges than to out-code the security stack.

The July 2025 joint advisory (opens in new tab) from CISA, the FBI, and international partners remains the clearest consolidated account of the group’s tactics. Then 2026 supplied a fresh reminder that the playbook still matters: A July Justice Department complaint (opens in new tab) described an alleged member’s role in help desk social engineering, MFA resets, and more than 100 intrusions attributed to the group.

Here’s what the playbook looks like, what recent cases add to the picture, and how to make your help desk a much less accommodating front door.

Weaponizing the help desk

Despite all the headlines, their primary initial access vector rarely involves complex code. It relies entirely on vishing (voice phishing) and impersonation. They bypass your heavily funded identity access management tools by tricking the people who hold the override keys.

Here’s how they execute the initial breach:

  • Deep reconnaissance: Operators assemble enough open-source and stolen data to sound like insiders—employee roles, reporting lines, vendors, internal language, and the answers a support agent expects.
  • SIM swapping and MFA fatigue: Sometimes they spam a user's phone with MFA approval requests until the exhausted employee finally taps "Approve" just to make it stop.
  • Help desk hustle: The caller impersonates an employee, manufactures urgency, and asks for a password reset or a new MFA method. The performance doesn’t need Oscar-worthy voice cloning. It needs just enough believable context—and a process that lets urgency outrank verification.

Once the help desk agent clicks that reset button, the attacker has a fully authenticated, legitimate session token. They walk right through the front door.

What changed (and what didn’t) through 2026

Scattered Spider started out by heavily targeting telecommunications and business process outsourcing (BPO) companies. But they did not stay there.

The 2025 advisory documented activity across commercial facilities and other sectors, while public reporting connected Scattered Spider-style operations with retail, insurance, and aviation targets. In 2026, enforcement actions added detail without eliminating the threat.

The opening move still leans heavily on social engineering. What happens after access can vary: cloud-data theft, persistence, lateral movement, extortion, and — in some incidents — ransomware. That flexibility is the point. Defenders can’t count on one tidy kill chain.

1. Cloud-scale exfiltration via Snowflake

The 2025 advisory describes actors using compromised credentials to access Snowflake environments and rapidly query and exfiltrate data. The lesson extends beyond one vendor: cloud access inherited through a trusted identity can turn one help desk decision into a major data problem.

2. Deploying DragonForce ransomware

The 2025 advisory says actors associated with Scattered Spider used multiple ransomware variants, including DragonForce, and encrypted VMware ESXi environments in some incidents. Data theft and encryption can occur together, but ransomware isn’t required in every intrusion.

3. Untraceable extortion channels

When it is time to demand payment, they avoid traditional communication methods that law enforcement can easily trace. They initiate their extortion demands through Tor networks, secure email providers, or encrypted messaging applications like Telegram and Signal, making the negotiation process a nightmare for incident responders.

Attack of the copycats

Whenever a threat actor finds a highly successful, low-barrier-to-entry tactic, the rest of the cybercriminal underground pays attention.

Because Scattered Spider’s help desk social engineering script is now public knowledge — thanks to countless CISA advisories, industry breakdowns, and incident reports—you aren't just defending against the A-team anymore. You are defending against anyone with a microphone.

Less sophisticated actors and lower-tier initial access brokers are currently running the exact same MFA-reset pretexts.

Here’s a look at how the elite syndicate compares to the swarm of copycats currently hitting your IT lines:

Threat trait

Scattered Spider

Copycats

Initial access

Highly targeted vishing with deep OSINT research and AI voice cloning

Generic, poorly researched help desk calls using leaked employee lists

Post-access goal

Cloud environment compromise, massive data exfiltration, and ransomware

Basic account takeover, business email compromise, or selling the access to higher-tier brokers

Technical polish

Uses custom tools to bypass EDR and pivots seamlessly through cloud tenants

Relies entirely on basic, off-the-shelf tools and panics if they hit a segmented network

Extortion method

DragonForce ransomware and encrypted communication channels

Simple email demands or immediate wire fraud attempts

Even if a copycat lacks the technical sophistication to deploy DragonForce ransomware, they can still cause massive financial damage just by gaining access to your internal email servers or accounting platforms.

Practical defense: make the help desk hard to hustle

You can’t patch a person, but you can fix the process around them. If a high-risk reset depends on one technician deciding whether a stressed caller “sounds legit,” the attacker gets to choose the most favorable moment.

The goal is to engineer ambiguity out of account recovery. Start with three controls that reinforce one another:

1. Require out-of-band identity verification

A phone call or chat message shouldn’t be enough to reset a password or enroll a new factor. Use a separate, pre-established channel and an approved verification method that the requester can’t change during the same interaction.

Design the recovery process with your identity and legal teams; a video call by itself can still be spoofed. Manager confirmation, verified-device signals, in-person checks, recovery codes, and documented exception paths can all play a role. The right mix adds deliberate friction where the blast radius justifies it.

2. Implement phishing-resistant MFA

Reduce reliance on SMS codes and simple push approvals for sensitive access. CISA recommends phishing-resistant MFA (opens in new tab), including FIDO/WebAuthn-based authenticators. Pair stronger authentication with controls on factor enrollment and recovery; the best key in the world can’t help if the help desk is allowed to replace it after one persuasive phone call.

3. Run help desk-specific vishing simulations

Help desk teams face a different test than the average employee. Give them role-specific vishing simulations that exercise urgent reset requests, executive impersonation, recovery exceptions, and escalation paths. The objective isn’t to catch people out. It’s to find where the process buckles before an attacker does.

Doppel helps secure the human decision point

When you analyze the entire Scattered Spider kill chain, you realize almost the entire operation relies on a single, isolated moment of human vulnerability.

Everything the attacker does after the reset is highly technical — navigating Snowflake environments, deploying DragonForce ransomware, and establishing Tor communications. But the reset itself? That is simply a person choosing to trust a voice on the phone.

Strengthening that decision point won’t solve every identity threat. It can remove one of the group’s favorite shortcuts.

Doppel’s helpdesk resilience and security program combines role-specific vishing simulations, threat-informed scenarios, and targeted coaching for the people attackers call when they want an exception. It’s built to exercise real decisions, not merely confirm that someone finished a video.

Teams can practice spotting manufactured urgency, suspicious recovery requests, and pressure to skip steps, then use the results to improve both behavior and process. The help desk won’t become impenetrable — nothing useful is — but it can become a far less profitable target.

Give your IT team something better than a vibe check.

Ready to make urgent reset requests less exciting? Schedule a demo with Doppel to see how targeted vishing simulations and helpdesk resilience programs strengthen the decisions attackers try to exploit.

Learn how Doppel can protect your brand from social engineering attacks

Join hundreds of companies already using our platform to protect their brand and people from social engineering attacks.