FBI warns on Scattered Spider hackers, urges victims to come forward


FILE PHOTO: An exterior view of MGM Grand hotel and casino, after MGM Resorts shut down some computer systems due to a cyber attack in Las Vegas, Nevada, U.S., September 13, 2023. REUTERS/Bridget Bennett/File Photo

SAN FRANCISCO (Reuters) - The FBI warned organizations to guard against the Scattered Spider hacking group, which has breached dozens of American organizations over the past year, stealing their sensitive data for extortion.

The FBI alert follows a Reuters report this week that said the agency had struggled to stop these hackers that are known to be skilled at using fake profiles and impersonations to trick a victim organisation's help desk into giving them access.

They were behind the September hacks into casino companies MGM Resorts International and Caesars Entertainment, but have intruded various organisations from telecom companies to healthcare groups, security researchers say.

The statement, issued jointly with the U.S. Cybersecurity and Infrastructure Security Agency, sheds new light into how these hackers operate.

Even after they've gained access into an organization's systems, the hackers keep checking its internal communication channels such as Slack, Microsoft Teams, and Microsoft Exchange online, for emails or conversations that might show if their breach had been discovered, the statement said.

The criminals "frequently join incident remediation and response calls and teleconferences, likely to identify how security teams are hunting them and proactively develop new avenues of intrusion in response to victim defenses," it added.

The FBI and CISA urged critical infrastructure organisations to implement a series of security measures they recommended and urged victim organisations to share information about the hacks with the agencies.

Everything from a sample ransom note, communications with the hackers, their cryptocurrency wallet information, or samples of malicious files could be useful, they said.

"FBI and CISA do not encourage paying ransom as payment does not guarantee victim files will be recovered," they said, adding that ransom payments may embolden the hackers into going after more targets.

(Reporting by Zeba Siddiqui in San Francisco; Editing by Nick Zieminski)

Follow us on our official WhatsApp channel for breaking news alerts and key updates!

   

Next In Tech News

Poco launches its C75 smartphone (priced from RM499) and Poco Pad (from RM1,399) in Malaysia
Chinese social media buzzes with admiration for Trump’s comeback
In this US school district, some parents are pushing back against a cellphone ban
After Trump took the lead, election deniers went suddenly silent
Australia moves to ban children under 16 from social media
South Korea fights deepfake porn with tougher punishment and regulation
PlayStation 5 Pro goes on sale, will gamers pay hefty price to play?
Roblox will ban kids under 13 from ‘social hangouts’
This robot can fold laundry
Canada orders TikTok’s Canadian business to be dissolved but won’t block app

Others Also Read