Threat Spotlight

Four attacks. One playbook.

Real cyberattacks on Las Vegas–area businesses, broken down step by step. Pick a case to see the timeline, the technique, and what a small business can learn from it.

Who attacked them

Scattered Spider, a loose collective of young, English-speaking operators.

Scattered Spider is not a traditional ransomware crew. It is a fluid set of operators (many in their late teens and early twenties) who meet through gaming platforms, Discord, and Telegram channels that researchers loosely call “the Com.”

Their edge isn't a novel exploit. It is fluent English, a calm phone voice, and the patience to research one employee until they can convince an IT help desk they're that employee. They are responsible for three of the four cases above (MGM, Caesars, and the alleged direct Findlay breach).

Also tracked as
  • UNC3944 (Mandiant)
  • Octo Tempest (Microsoft)
  • 0ktapus
  • Scatter Swine
  • Muddled Libra (Unit 42)
  • Star Fraud
Each vendor names threat groups independently. These are the same activity tracked under different labels.
Where they are

Distributed across the US and UK. Several members have been publicly identified.

Jan 2024
Noah Michael Urban, 19
Palm Coast, Florida

Conspiracy to commit wire fraud, identity theft, and aggravated identity theft.

Jun 2024
Tyler Robert Buchanan, 22
Arrested in Palma de Mallorca, Spain (UK national)

Arrested at Palma airport; US filed wire fraud and aggravated identity theft charges.

Nov 2024
5 alleged members indicted
Central District of California

DOJ unsealed charges against Ahmed Elbadawy, Noah Urban, Evans Osiebo, Joel Evans, and Tyler Buchanan for a wire-fraud conspiracy.

Sources: DOJ press releases, Reuters, Bloomberg, KrebsOnSecurity. Charges do not equal conviction; individuals named are not assumed guilty.

How they do it

The eight-step playbook. No zero-day required.

  1. 1. Reconnaissance on LinkedIn

    Identify an IT or help-desk staff member at the target: name, role, manager, badge style, internal jargon.

  2. 2. Vish the help desk

    Call IT pretending to be the employee. Calm voice, correct context, ask for a password and MFA reset.

  3. 3. Reset MFA, log in

    Help desk resets MFA. Operator enrolls their own device. Now they log in as the real employee.

  4. 4. Pivot through Okta / Azure AD

    Abuse SSO to jump from one app to another, hunting for cloud admin and VMware vCenter credentials.

  5. 5. Exfiltrate first, encrypt later

    Sensitive data is copied out using common tools so it can be used as extortion leverage even if backups exist.

  6. 6. Deploy ransomware on hypervisors

    Reported deployment of ALPHV/BlackCat against MGM's VMware ESXi servers. Every VM on the host goes down at once.

  7. 7. Demand payment, threaten leaks

    Operators contact executives directly (often with harassment), demanding crypto payment to decrypt and to not publish data.

  8. 8. Move to the next victim

    Members rotate through the loose online community known as "the Com." When one is arrested, the playbook continues with others.

What it means for you

A ten-minute phone call broke a $30 billion company.

You are easier than MGM was. Six practical defenses cover almost everything Scattered Spider (and most other crews) use.

Train anyone who can reset a password

Anyone who handles password resets needs a verification script. Callers must answer specific identity questions before any reset happens.

Move off SMS-based MFA

SMS codes can be stolen via SIM swap. Use authenticator apps with number matching, or hardware keys (YubiKey) for accounts that matter.

Audit what staff posts on LinkedIn

Job titles, team names, internal jargon, badge photos. All give attackers what they need to sound like an insider on a phone call.

Ask vendors how they verify you

Caesars wasn't broken at Caesars. It was broken at an outsourced help desk. Ask every vendor how they handle reset requests.

Have a written incident plan

Who do you call at 2 a.m.? Which insurer, lawyer, bank? Print it. Tape it inside a desk drawer. Don't google answers mid-incident.

Back up what you can't survive losing

Customer records, accounting files, photos. Backups have to be offline, tested, and recent. Not just a cloud sync the attacker can encrypt.

Want to know if your business survives this playbook?

Free 15-minute call. We'll walk through your help-desk process, MFA setup, and three things you can fix this week.

Book a free consultation
Sources & disclaimer

Sources: US Department of Justice press releases, Bloomberg, CyberScoop, Las Vegas Review-Journal, News3LV, Clark County District Court filings, TRM Labs blockchain analysis, CDK Global public statements, Reuters, KrebsOnSecurity, MGM & Caesars SEC 8-K filings, Mandiant + Microsoft + Palo Alto Unit 42 threat-actor briefings. BlackSuit attribution for the CDK Global incident is based on widely reported industry analysis and blockchain tracing and has not been officially confirmed by CDK Global. Scattered Spider attribution for the direct Findlay breach is alleged and has not been officially confirmed by law enforcement as of this writing. Individuals named in arrest records and court filings are presumed innocent until proven guilty.