- US retailers need to “take note”, Google warns
- Spread spider was seen targeting several US retailers this year
- The group has been on a “long hiatus”
Scattered Spider, a well -known Ransomware collective, expands its target and no longer focuses exclusively on British companies. This is according to Google’s threat information group (TIG) that told Bleeping computer That US retailers “should pay attention.”
“The US retail sector is currently targeting ransomware and extortion operations, which we suspect is linked to UNC3944, also known as scattered spider,” John Hultquist, chief analyst at Google Threat Intelligence Group, told the publication. Hultquist added that scattered spider has returned after a “long hiatus” to target more companies.
The group is not as closely composed as organizations such as Lockbit or CL0P. It is relatively loose and works within a larger hacking community known as “the com”. Its members participate in all kinds of attacks, from Social Engineering and SIM exchange, to ransomware. Scattered Spider’s usual goals are financial institutions, technology companies and entertainment/gaming organizations.
Names and addresses
Google warns retailers to note however Quiet push reported that by 2025, some of scattered Spider’s victims Chick-Fil-A, Forbes, Instacart, New York Digital Investment Group, News Corporation, Nike, Twitter/X, Tinder, T-Mobile and Vodafone.
Among the retailers who were targeted this year, Bleeping computer Designated Marks & Spencer, Co-Op and Harrods. In all these attacks, the threat actors used Dragonforce – a ransomware operation that occurred in December 2023 and got some notoriousness since then.
In April 2025, the British National Cyber Security Center (NCSC) published new guidance and helped British companies defend themselves against scattered spider better. The organizations encouraged the retail sector to “wake up” and tighten up security.
“Although we have insight, we are not yet able to say whether these attacks are linked if this is a coordinated campaign of a single actor or if there is no connection between them at all,” NCSC said. “We cooperate with the victims and colleagues on law enforcement to establish it.”
Via Bleeping computer