TL;DR: Scattered Spider’s recent campaign shows how help desk impersonation, MFA push bombing, SIM swapping, and living-off-the-land tactics let attackers turn human and procedural weaknesses into privileged access, extortion, and major disruption, according to SafeBreach. The pattern confirms that identity governance, help desk controls, and phishing-resistant MFA now matter as much as endpoint defence.
NHIMG editorial — based on content published by SafeBreach: Scattered Spider: What You Need to Know
Questions worth separating out
Q: How should organisations reduce help desk impersonation risk in identity recovery flows?
A: Use multi-step verification for every sensitive reset or device-enrolment request, separate approval from execution, and require stronger checks for outsourced support channels.
Q: Why do push-based MFA and SMS codes fail against social engineering campaigns?
A: They fail because attackers target the human and the delivery channel, not the underlying authentication protocol.
Q: What breaks when identity programmes rely on help desk knowledge checks alone?
A: Knowledge checks often use data that is exposed, guessable, or already assembled through OSINT.
Practitioner guidance
- Harden account recovery and reset flows Require multi-approver verification for password resets, MFA re-enrolment, and other high-risk identity changes, especially where outsourced help desks are involved.
- Move to phishing-resistant MFA Prioritise number matching, FIDO2 security keys, and other phishing-resistant factors while removing SMS from workflows that can unlock privileged access.
- Validate every support interaction Treat help desk calls and group-response bridges as identity events and require stronger caller validation before any credential or device change is approved.
What's in the full article
SafeBreach's full article covers the operational detail this post intentionally leaves for the source:
- A step-by-step breakdown of Scattered Spider's help desk impersonation and SIM swapping tactics.
- Detailed examples of the group's use of living off the land tools and remote access utilities after entry.
- The incident history behind MGM Resorts and Caesars Entertainment, including disruption and exfiltration outcomes.
- Practical defensive guidance for validating identity workflows during live attack simulation.
👉 Read SafeBreach's analysis of Scattered Spider's identity-led attack playbook →
Scattered Spider and help desk compromise: what IAM teams missed?
Explore further
Human identity recovery workflows have become an attack surface, not a backup control. Scattered Spider succeeds because help desk verification, password reset logic, and MFA re-enrolment are still too easy to social-engineer. The group does not need to defeat the identity stack if the recovery path can be persuaded to issue a new one. Practitioners should treat account recovery as a privileged operation, not an administrative convenience.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities.
A question worth separating out:
Q: Who is accountable when social engineering leads to credential compromise?
A: Accountability sits with the identity programme, the help desk, and the business process owners who define recovery and approval paths. Social engineering succeeds when identity controls are too easy to override, so governance has to cover the workflow, not just the authentication toolset.
👉 Read our full editorial: Scattered Spider shows why identity controls fail under social engineering