The Scattered Spider cybercrime gang has shifted focus from attacking retailers to targeting insurance companies in the US.
Google Threat Intelligence Group (GTIG) researchers have detected multiple intrusions in the US, with a particular emphasis on the insurance industry.
Scattered Spider, a cybercriminal organization part of 'the Com,' is known for targeting industries sequentially and has now set its sights on the insurance sector.
The gang recently targeted high-end retailers in the UK and engaged in social engineering, SIM swapping, and ransomware attacks against US companies.
Insurance organizations are advised to be vigilant against social engineering schemes aimed at their help desks and call centers.
Recent cyberattacks reported by Erie Insurance and Philadelphia Insurance Company align with Scattered Spider's modus operandi, although not confirmed.
The cybercriminals typically initiate attacks with fake helpdesk calls to gain device access before deploying the DragonForce ransomware.
Defending against ransomware involves raising awareness among employees about phishing and social engineering tactics.