Security Stop-Press: Scattered Spider Shifts Focus to Insurance Firms

Written by Pronetic

Pronetic is a leading provider of core IT support for ISO 27001, Cyber Essentials and Cyber Essentials Plus compliance.

June 25, 2025

Scattered Spider, a teenage-led (mainly UK and US-based) hacking group has begun targeting insurance companies, sparking fresh warnings from cyber security experts.

Google’s Threat Intelligence Group (GTIG) confirmed multiple US insurance firms have recently suffered attacks matching the group’s methods. Known for breaching major retailers like M&S and Tiffany, the group uses tactics such as phishing, SIM-swapping, and MFA fatigue to bypass identity checks and helpdesk protocols.

Two incidents in early June, affecting Philadelphia Insurance and Erie Insurance, show the threat is real and growing. GTIG warned that the group tends to focus on one sector at a time, and insurance firms are now clearly in its sights. Experts believe UK providers could be next.

Unlike ransomware gangs, Scattered Spider relies on social engineering to move fast and exploit human error. “They don’t need advanced exploits,” said Jon Abbott, CEO of ThreatAware. “They get in by tricking people – not by breaking software.”

To stay safe, insurers and other businesses should strengthen helpdesk verification, use phishing-resistant MFA, and monitor for unusual login activity. Above all, building a culture of security awareness is essential to stop attackers in their tracks.

You May Also Like…

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Why Choose Pronetic

We Are ISO 27001 & Cyber Essentials Plus Certified

Be reassured that we have been externally audited. You can have complete peace of mind that the team managing your IT systems and safeguarding your data are independently vetted annually.

Seamless & Comprehensive IT Support

Our investment in people, tools and processes, continuously improved, ensures that we don’t just deliver exceptional I.T. support but include your compliance to Cyber Essentials or ISO 27001 “baked-in”. Yes, that means no more annual headaches and stress when your certification comes round.

Expert Support Money Back Guarantee

We're confident in the value we deliver. That's why we offer a 90-day, no-quibble money-back guarantee. If, for any reason, you're not completely satisfied with our IT support services, we'll provide a full refund and cancel your contract without any hassle.

Book Your Free IT Strategy Call Now!

Simply Fill In The Form Below To Receive Your Free IT Strategy Call:

By submitting this form, you consent to us using your personal information to contact you. For more information please see our privacy policy.