Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Scan for outdated or missing drivers - takes under a minute3Repair Windows errors before they cause bigger problemsInsurance companies have joined the sectors targeted by activity associated with Scattered Spider, but the evidence points to an expanding, shifting campaign—not a permanent insurance-only focus. In mid-2025, Google Threat Intelligence Group reported that the actor it tracks as UNC3944 was targeting insurance organizations. Public reporting says UNC3944 overlaps substantially with Scattered Spider, so incident-level attribution still requires care.
For insurers, the immediate lesson is practical: the principal weakness may be identity recovery and help-desk procedures rather than a newly discovered software flaw. A convincing caller who obtains a password reset or new multifactor-authentication (MFA) enrollment can reach cloud systems, steal data and pursue extortion even when ransomware is never deployed.
What changed in 2025
Scattered Spider has previously been associated with campaigns affecting telecommunications, financial services, technology, gaming, hospitality, retail and other large enterprises. Google described recurring sector-focused waves, including financial-services activity in late 2023 and food-services targeting in May 2024, often involving organizations with large help desks or outsourced IT operations. Its 2025 reporting identified a campaign involving insurance, retail and airline organizations, followed by broader activity affecting aviation and transportation.
That pattern supports “expanded insurance targeting,” not a proven permanent pivot. Google tracks the relevant activity as UNC3944 and notes overlap with public reporting on Scattered Spider; the names should not be treated as interchangeable for every incident. Google’s insurance-sector analysis is at its July 2025 technical report.
#1 Best Overall
What the public evidence establishes
| Evidence | What it supports | Important qualification |
|---|---|---|
| Google Threat Intelligence Group reporting | UNC3944 activity targeting insurance organizations in mid-2025 | UNC3944 overlaps with, but is not automatically identical to, every use of “Scattered Spider” |
| Singapore Cyber Security Agency alert | Scattered Spider targeting insurance and retail, with aviation expansion reported by June 2025 | Sector reporting does not attribute every individual victim |
| FBI, CISA and international advisory, July 29, 2025 | Active targeting of commercial facilities and other sectors using social engineering, credential theft, remote-access tools, data theft and ransomware or extortion | Investigative intelligence in the advisory ran through June 2025 |
| Aflac SEC filing | Unauthorized access to U.S. systems on June 12, 2025 | The filing does not establish Scattered Spider as the culprit |
Read the primary materials: Singapore CSA alert, the joint FBI advisory, the CISA announcement and Aflac’s filing.
Why insurance companies are attractive
Insurers combine concentrated data value with complicated access arrangements. A compromise can expose personally identifiable information, health and life records, claims files, policy and beneficiary details, employment information, payment data and broker records. Customer and broker portals, call centers, distributed staff, outsourced IT and large cloud and SaaS estates add more identity and administrative pathways.
- High-value data: A single environment may contain records useful for fraud, blackmail, identity theft and regulatory investigations.
- Operational pressure: Claims, medical and customer-service teams cannot simply stop all account-recovery work, which can make poorly designed emergency procedures attractive to attackers.
- Delegated administration: Managed-service providers, contact centers, claims platforms and identity contractors may hold powerful access outside the insurer’s direct control.
- Multiple extortion levers: An attacker can threaten publication, customer harm, regulatory consequences or business interruption. Encryption is not required for leverage.
This is an attractive combination, not proof that insurers are uniquely vulnerable. The same characteristics explain why the group has pursued other large enterprises.
How the attack chain works
The recurring pattern is an identity and support-process attack:
- Research: Attackers collect employee names, roles, reporting lines, contact details and identity-verification information.
- Credential acquisition: They may use voice phishing (vishing), SMS phishing (smishing), infostealers, exposed credentials or other theft methods.
- Help-desk impersonation: A caller claims to have lost a phone, replaced a device or faces an urgent access problem.
- Recovery manipulation: The caller persuades support staff to reset a password, enroll a new MFA device or alter a recovery method.
- Cloud and SaaS access: The intruder enters identity providers, virtual infrastructure, file stores, CRM, claims and other business applications.
- Privilege discovery: They search for administrative roles, secrets, service accounts, vault credentials, API keys and cloud permissions.
- Data theft and persistence: Files and databases are collected; sessions, federated identity or cloud mechanisms may preserve access.
- Extortion or disruption: Stolen data may be used for pressure, with ransomware added when it increases leverage.
Google’s technical analysis describes repeated service-desk social engineering and detailed employee information used to defeat verification. See the SaaS targeting analysis and the vishing analysis. The initial access described in these reports often relies on persuasion rather than exploitation of a software vulnerability; the subsequent cloud and identity activity can still be sophisticated.
Techniques security teams should watch
- Repeated MFA push requests (“push bombing”), SIM swapping and phone-number changes.
- Password resets, new MFA-device enrollment, recovery-email changes and temporary-access credentials.
- New federation settings, SAML changes, rogue identity providers, OAuth grants, service principals and unexpected privileged-role assignments.
- Legitimate remote-access or tunneling tools used from unusual devices, locations or times.
- Credential searches in password stores, code repositories, administrative systems and cloud consoles.
- Bulk downloads, unusual exports or attacker-controlled cloud storage linked to claims, policy or customer systems.
- Persistence through Microsoft Entra, federated identity, virtualization platforms or other cloud-control mechanisms.
- Data theft followed by extortion, with ransomware variants such as DragonForce reported in the broader 2025 activity—not necessarily in every insurance incident.
Five controls to check today
1. Make help-desk verification independent
Do not let a caller authenticate solely with information an attacker can research, buy or steal, such as a manager’s name, employee number, caller ID or the last four digits of an identifier. Use a pre-registered, independent channel for password and MFA recovery. Require dual approval for administrative MFA changes, escalate privileged-account resets and add a cooling-off period for high-risk changes where claims operations allow it.
Rank #3
2. Secure MFA recovery as tightly as login
Alert on new authenticator enrollment, phone-number or recovery-email changes and temporary credentials. Treat “lost phone,” “new device” and “travel emergency” requests as high risk. Use phishing-resistant passkeys or hardware security keys for administrators and help-desk staff where deployment and replacement procedures can support them. Push MFA and SMS recovery remain exposed to push bombing and SIM swapping, respectively.
3. Monitor the identity provider
Centralize Entra, Okta or other identity-provider audit logs. Review federation, SAML, OAuth, service-principal and privileged-role changes. Ensure responders can revoke sessions and tokens quickly after suspected takeover.
4. Remove unnecessary help-desk privilege
Separate support permissions from administrative permissions. Routine support agents should not directly reset highly privileged accounts. Use workflow approvals, ticket-quality checks and authorized social-engineering exercises to test whether procedures—not employee caution alone—stop an attacker.
Rank #4
5. Protect cloud, SaaS and vendors
Inventory sensitive data in CRM, claims, policy-administration, document-management, collaboration and analytics systems. Restrict third-party OAuth applications and cloud-storage synchronization; rotate exposed secrets; review dormant accounts, service accounts, API keys and excessive permissions; and detect bulk exports. Contracted help desks and delegated administrators need the same identity-proofing, phishing-resistant authentication, logging and notification requirements as internal staff.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Balance security with claims availability
A rule that delays every legitimate reset will be bypassed during a medical or claims emergency. Use risk-based friction instead:
- Standard recovery: automated, strongly verified and logged.
- Privileged or unusual recovery: independent confirmation, human escalation and dual approval.
- Business-continuity emergency: an exception path with enhanced logging, time limits and retrospective review.
Prepare for theft-only extortion
Preventing encryption does not prevent a breach. Identify which claims, health, beneficiary, employment and payment data would create the greatest legal, regulatory, fraud or customer impact. Predefine notification and decision procedures involving privacy, legal, communications, law enforcement, brokers and cyber-insurance contacts. Preserve identity, cloud and SaaS logs before containment removes evidence, and rehearse a scenario in which attackers steal data but deploy no ransomware.
Best Value
What leaders should ask now
- Can a caller reset a privileged account using publicly discoverable information?
- Are MFA enrollments and recovery changes independently approved and centrally alerted?
- Are every help-desk action and vendor support action logged for security review?
- Can responders revoke sessions, tokens and OAuth grants quickly?
- Are bulk exports from claims and policy systems detected?
- Do outsourced providers meet the insurer’s authentication and logging standard?
- Has the incident team practiced a data-extortion event without ransomware?
Attribution: why the wording matters
“Scattered Spider” is a public-facing label used across reporting, while Google uses UNC3944 for related activity and describes overlap with other clusters. Names may cover overlapping crews, affiliates, aliases or shared tooling. Therefore, describe an event as “Scattered Spider-linked,” “associated with UNC3944” or “bearing the group’s hallmarks” unless law enforcement or the victim has made an incident-specific attribution. Aflac’s June 12, 2025 disclosure confirms unauthorized access, not responsibility by this group.
Bottom line for insurers
The insurance-sector risk is an identity and support-process problem that can become a data-extortion crisis. Harden account recovery, require phishing-resistant authentication for the people who can change it, monitor identity-provider and SaaS administration, control vendors and practice response to data theft. Those measures address the attack path whether or not an incident is ultimately labeled Scattered Spider.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




