Gamer-Turned-Hacker Group Still Active
Scattered Spider has been active since 2023, using the same tactics to breach large organisations through call centres and identity resets. Most members are young, some still teenagers, and many come from gaming communities.
More recently, the group has been linked to new incidents across the US, UK, and Canada. Qantas may also be among the latest targets.
Their tools haven’t advanced much. They haven’t really had to because their easier attacks are still working. That’s part of the story.
Scattered Spider’s attack methods
Most of their access starts with a phone call.
- They’ll contact an IT help desk, impersonate an employee, and reset the password tied to single sign on.
- If MFA is linked to a mobile number, they’ll use SIM swapping to catch the code
- In some cases, they’ve moved from initial access to full ransomware deployment in less than a day.
It’s the kind of breach you’d expect from someone guessing security questions. In most cases, that’s exactly what’s happening.
Recent Qantas breach
Qantas is one of several recent incidents with a familiar pattern.
The target was a call centre platform. The method matched what we’ve seen before.
We broke that down here.
Why they’re still operating
Scattered Spider members move between groups, shift roles, and sometimes act independently. Some are involved for weeks. Others pass access or credentials and move on.
There’s also overlap with Russian ransomware groups like Play, Akira, and DragonForce.
So, when the breach looks like one actor, but the impact is shared across multiple crime groups, it gets harder to assign accountability.
Where they’re getting in
Help desks are still one of the easiest ways in. A convincing voice, a few HR-style questions, and password resets are still happening. This shouldn’t be possible in 2025, but it is.
If the attacker sounds helpful enough, that’s often all it takes.
SMS and voice call-based MFA are still active in too many environments. These methods are now predictable targets.
ESXi and similar hypervisor layers are still running below the surface of most security tooling. They don’t always log well. And they’re rarely prioritised in internal audits. That makes them an easy target to deploy ransomware once inside.
Third-party vendors still hold broad access, often without tight role scoping or regular reviews. Breaches through outsourced support platforms are expected at this point. The access hygiene around them hasn’t kept up.
What Justice?
A lot of members are under 18. Others are protected by mental health exceptions or regional legal systems that reduce detention timeframes. That limits what law enforcement can do, even with strong evidence.
What this leads to is a response gap. Arrests happen, but they don’t last long enough, and they don’t scale to the wider network. Access, tooling, and contacts circulate freely. The next group is already working while one case is still open.
What to take from this
Scattered Spider’s success doesn’t come from innovation. It comes from knowing exactly which gaps still haven’t been closed.
And until those gaps shrink, groups like this will keep going. They don’t need to adapt when the access stays the same.



