Back to blog

Blog Post

Scattered Spider Shifts Focus to Insurance Industry

Share on social

Jun 27, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Scattered Spider Shifts Focus to Insurance Industry

[Scattered Spider Insurance]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

Scattered Spider, notorious for its recent high-profile attacks on U.K. and U.S. retailers, has pivoted to target American insurance companies according to intelligence from Google’s Threat Intelligence Group.

Google tracks the financially motivated group as UNC3944 and has previously linked it to a string of ransomware attacks against British retailers and supermarket chains earlier this year. Now, the same tactics are appearing within the U.S. insurance industry.

“Google Threat Intelligence Group is now aware of multiple intrusions in the U.S. which bear all the hallmarks of Scattered Spider activity. We are now seeing incidents in the insurance industry,” John Hultquist, chief analyst at Google Threat Intelligence Group, said in an email.

“Given this actor’s history of focusing on a sector at a time, the insurance industry should be on high alert, especially for social engineering schemes which target their help desks and call centers,” Hultquist added.

Known for its sector-focused campaigns, Scattered Spider often uses social engineering techniques, including help desk impersonation and SIM swapping, to gain access to corporate systems.

At least one organization has already reported a serious incident. Erie Insurance, a Fortune 500 firm based in Pennsylvania, disclosed “unusual activity” on its network discovered on June 7th. The business started its incident response plan and took systems offline to mitigate the situation.

“Upon learning of this activity, the company activated its incident response protocols and took immediate action to respond to the situation to safeguard our systems,” the company said in a June 11 regulatory filing.

The organization has not attributed the attack to Scattered Spider or any other groups. It confirmed its online systems remain offline, preventing customers access to accounts and digital services. Erie has advised customers to stay vigilant and avoid clicking unknown links or sharing personal information via email or phone.

Lizzie Clark

Author

Lizzie Clark

Marketing Executive at Searchlight Cyber

Lizzie is an experienced IT and cybersecurity marketing professional with six years of specialist experience in the industry. Lizzie produces a range of content - from blogs and long-form articles to newsletters and social media - with a focus on writing that informs and engages technical audiences.

Related Blog Posts

September 16, 2026

How AI Is Collapsing Exploitation Timelines

September 15, 2026

Faster Leaked Credential Search with a rebuilt experience

September 10, 2026

Beacon: Searchlight Researchers Uncover JavaScript Sandbox Flaw Enabling RCE in Zendesk and Nuclei

September 3, 2026

Beacon: FulcrumSec Claims Responsibility for Manchester Airport Group Breach

September 1, 2026

Searchlight Threat + RST Cloud: Instant insights from 1,000s of threat reports

August 27, 2026

Beacon: North Korean Hackers Linked to Rust Supply Chain Attack

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient