Join our Newsletter — 33% off our NHI Course

Why do insurance companies attract Scattered Spider-style attacks?

Insurance firms are attractive because they concentrate personal and financial data, rely heavily on outsourced IT, and often have help desks that can be reached through social engineering. That combination creates a large attack surface with fragmented accountability. A successful reset or SIM swap can give attackers a fast path into accounts, internal systems, and downstream business operations.

Why insurers are such efficient targets for Scattered Spider-style operations

Insurers tend to be attractive because the environment combines high-value personal and financial data with a large service ecosystem. That creates many places where attackers can start with help-desk impersonation, then move into password resets, MFA re-enrolment, or outsourced support workflows that are easier to influence than a hardened core system.

The practical issue is not just data volume. It is the mix of broad account access, distributed third parties, and business processes that assume identity proofing will usually be trustworthy. When those assumptions are wrong, a single successful social-engineering step can open multiple systems at once.

There is also a strong incentive factor. Insurance operations support claims, payments, customer servicing, and sensitive identity records, so attackers can pressure victims with both operational disruption and data exposure. That is why the same access path can be used for theft, extortion, or rapid lateral movement.

  • Help desks and service desks often become the first reliable foothold.
  • Outsourced IT and shared service models expand the number of people and processes an attacker can impersonate.
  • Customer and employee identity data increases the quality of pretexting and account recovery fraud.
  • Once inside, attackers can pivot from one compromised identity to broader enterprise access.

What makes the attack path work in practice

scattered spider-style activity succeeds when identity proofing is treated as a routine support task rather than a high-risk control point. Attackers exploit the gap between what a caller can persuade a help desk to do and what the environment should require before resetting credentials, changing MFA, or issuing a new device trust decision.

That gap is widened in organisations where vendors, call centres, and internal teams each hold a piece of the workflow but no one owns the entire assurance chain. In those conditions, attackers do not need a technical exploit first; they need a social path that reaches a trusted operator.

For insurers, the most dangerous pattern is speed. A reset or SIM swap can be enough to convert an initial pretext into authenticated access, and then into privileged internal actions before monitoring or escalation catches up.

  • Recovery workflows should be treated as privileged actions, not administrative conveniences.
  • Shared or outsourced support processes need the same scrutiny as production access paths.
  • Any step that changes MFA, phone number, device binding, or recovery contact details materially changes the attack surface.

Risk and Threat Considerations

Insurance firms face a compound risk: valuable data, operational urgency, and recovery workflows that can be manipulated through social engineering. When help-desk controls, telecom processes, or vendor-managed support are weak, attackers can turn one identity event into enterprise-wide compromise.

Failure mechanism: The attacker abuses trusted recovery paths, such as password reset, MFA re-enrolment, or SIM swap, to bypass normal authentication without needing malware first.

Impact: A successful reset can expose customer records, claims systems, payment workflows, and internal administrative tools, while also enabling extortion and further lateral movement.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 PR.AA — Identity Management, Authentication, and Access Control Insurance attack paths hinge on recovery and authentication abuse.
GV.SC — Cybersecurity Supply Chain Risk Management Outsourced IT and support vendors materially expand the attack surface.
PR.DS — Data Security Insurers concentrate personal and financial data that attackers seek after access.
Recommendation — Harden recovery and authentication flows that can reissue access. Govern third-party support paths that can alter identity or access. Protect sensitive records with tighter segmentation and access restrictions.
CIS Controls v8 5 — Account Management Reset, re-enrolment, and access reissuance are central to the attack path.
6 — Access Control Management Scattered Spider-style compromise turns weak access decisions into breach paths.
Recommendation — Restrict and review account recovery and reactivation processes. Enforce least privilege and tighten access revalidation for support changes.
NIST SP 800-63 6 — Authenticator Lifecycle Management SIM swaps and MFA re-binding exploit weaknesses in authenticator lifecycle.
4 — Identity Proofing Pretexting succeeds when support accepts weak proofing during recovery.
Recommendation — Apply stronger lifecycle checks before changing authenticators or recovery factors. Require stronger identity proofing for high-risk account recovery events.
MITRE ATT&CK T1566 — Phishing Social engineering is the usual entry mechanism for these campaigns.
T1110 — Brute Force Attackers often combine persuasion with credential and account abuse.
T1098 — Account Manipulation Resetting MFA, changing recovery data, and altering access are core abuse steps.
Recommendation — Detect and train against social-engineering entry attempts. Monitor for account access patterns that indicate credential or session abuse. Alert on unauthorized account and recovery-data changes.

Practitioner Guidance

What to verify: Treat every recovery channel as a control surface. Verify which steps require out-of-band confirmation, which ones can be completed by a single agent, and where vendors can request changes without a second approval.

What good looks like: The safest environments make account recovery slow enough to be suspicious, with clear ownership, strong logging, and mandatory step-up checks for any change that could rebind identity or redirect access.

Common mistake: Teams often harden user login while leaving password resets, MFA changes, and telephony-based recovery comparatively weak. That creates a bypass that is easier to attack than the main sign-in flow.

Practitioner takeaway: If an attacker can convince support to reissue trust, the rest of the security stack becomes much less important, so the recovery process must be defended like a privileged admin path.