Ptechhub
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs
No Result
View All Result
PtechHub
No Result
View All Result

Scattered Spider Tactics Include Data Theft, Extortion: CrowdStrike

CRN by CRN
July 2, 2025
Home News
Share on FacebookShare on Twitter


Threat researchers from CrowdStrike are pointing to the hacker group’s focus on more than just traditional ransomware attacks — as experts have separately linked the group to a data theft attack against Australian airline Qantas.

The notorious threat group Scattered Spider has indeed been known to focus on more than just traditional ransomware attacks in the past — with data theft and extortion attacks constituting a lesser-known part of its repertoire, according to threat researchers at CrowdStrike.

The advisory from CrowdStrike’s Counter Adversary Operations unit Wednesday comes as other experts have separately linked the Scattered Spider hacker group to a data theft attack against Australian airline Qantas.

[Related: 10 Major Ransomware Attacks And Data Breaches In 2024]

The hacker group tracked as Scattered Spider has previously been blamed for high-profile ransomware attacks including the hugely disruptive 2023 attacks against casino operators MGM and Caesars Entertainment.

Recently, researchers have connected Scattered Spider to a series of attacks against three British retailers — Marks & Spencer, the Co-op and Harrods — as well as insurers such as Aflac.

Scattered Spider then reportedly moved on to targeting airlines, with the group blamed for incidents including attacks against Hawaiian Airlines and WestJet.

On Wednesday morning, Australian airline Qantas confirmed that “a cyber incident has occurred in one of its contact centres impacting customer data,” affecting a platform containing the records of 6 million customers.

“We are continuing to investigate the proportion of the data that has been stolen, though we expect it will be significant,” the airline said in a statement posted online. “An initial review has confirmed the data includes some customers’ names, email addresses, phone numbers, birth dates and frequent flyer numbers.”

CRN has reached out to Qantas for comment.

Security experts including Abnormal AI CIO Mike Britton have suggested the Qantas attack is “likely” to turn out to be linked to Scattered Spider.

In their advisory on the CrowdStrike blog Wednesday, threat researchers from the cybersecurity vendor noted that Scattered Spider does continue to hold ransomware deployment as the “primary goal” of their activities.

However, “if an incident is contained prior to ransomware deployment, the adversary often threatens to publicly leak stolen data and demands a ransom,” CrowdStrike researchers wrote in the advisory.

The hacker group is also not above “stealing sensitive data before deploying ransomware for double extortion,” the researchers noted.

CrowdStrike – which coined the name Scattered Spider for tracking the group – has been publishing research on the cybercrime group since 2022.

CrowdStrike researchers on Wednesday also added further confirmation that Scattered Spider has “recently broadened its target scope to include the aviation sector, in addition to its established focus on the insurance and retail industries, as observed by CrowdStrike Services.”

“Throughout Q2 2025, SCATTERED SPIDER’s activities have primarily centered on U.S.-based insurance and retail entities, along with U.K.-based retail entities,” the CrowdStrike researchers wrote. “However, incidents in late June 2025, specifically targeting U.S.-based airlines, demonstrated tactics, techniques, and procedures (TTPs) consistent with the adversary’s previous operations.”



Source link

Tags: CyberattacksCybersecurityData breaches
CRN

CRN

Next Post
inTouch Addresses .7 Billion Senior Loneliness Crisis with Launch of AI Conversational Companion for North America

inTouch Addresses $6.7 Billion Senior Loneliness Crisis with Launch of AI Conversational Companion for North America

Recommended.

Huawei Digital Power, Yenilikçi İş Stratejileri ve Güvenlik Ekosistemi için Şebeke Oluşturma ve ESS Güvenlik Forumu’na Ev Sahipliği Yapıyor

Huawei Digital Power, Yenilikçi İş Stratejileri ve Güvenlik Ekosistemi için Şebeke Oluşturma ve ESS Güvenlik Forumu’na Ev Sahipliği Yapıyor

June 23, 2025
BeyondTrust Discloses Compromise Of Remote Support Software

BeyondTrust Discloses Compromise Of Remote Support Software

December 23, 2024

Trending.

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

Google Sues 25 Chinese Entities Over BADBOX 2.0 Botnet Affecting 10M Android Devices

July 18, 2025
Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

Stocks making the biggest moves premarket: Salesforce, American Eagle, Hewlett Packard Enterprise and more

September 4, 2025
Wesco Declares Quarterly Dividend on Common Stock

Wesco Declares Quarterly Dividend on Common Stock

December 1, 2025
HeyGears Launches Reflex 2 Series 3D Printers – Enabling Users to Go Beyond Prototypes and Start Production

HeyGears Launches Reflex 2 Series 3D Printers – Enabling Users to Go Beyond Prototypes and Start Production

October 24, 2025
⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

⚡ THN Weekly Recap: New Attacks, Old Tricks, Bigger Impact

March 10, 2025

PTechHub

A tech news platform delivering fresh perspectives, critical insights, and in-depth reporting — beyond the buzz. We cover innovation, policy, and digital culture with clarity, independence, and a sharp editorial edge.

Follow Us

Industries

  • AI & ML
  • Cybersecurity
  • Enterprise IT
  • Finance
  • Telco

Navigation

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Subscribe to Our Newsletter

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Copyright © 2025 | Powered By Porpholio

No Result
View All Result
  • News
  • Industries
    • Enterprise IT
    • AI & ML
    • Cybersecurity
    • Finance
    • Telco
  • Brand Hub
    • Lifesight
  • Blogs

Copyright © 2025 | Powered By Porpholio