Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Scattered Spider: Identity-Based Cyber Threats in 2025

Veeam
03/12/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


In this age of misinformation and disinformation, it's very difficult to cut through the noise. And I know personally on my side, I am subscribed to an enormous amount of cyber news on a day-to-day basis. And one of the names that keeps popping up that I've been super interested in is Scattered Spider. And early on when we were putting this show together, we pinged Ray and said, hey, you know, I'm wondering if there are any kind of threat actors that uniquely go after identity as a way to wreak the maximum amount of havoc. And he said immediately the first group that comes to mind is Scattered Spider. Now he did make a note, this organization doesn't call themselves Scattered Spider. That's a name that those of us in the ecosystem, I think CrowdStrike in particular has put on them. And he made a good point. This is a loosely organized group compared to some other threat actor groups that we have, but they are very effective at going after a specific playbook. Now we keep talking about Ray. For those who haven't seen the show before and are wondering who that cold open was, Ray Ulmerle is the field CISO for Covert by Veeam. And he is an industry expert. He is a multi-time ransomware survivor at his various organizations, including a Fortune 500 company. He is also CISSP certified. He's been recognized and is an absolute professional in his field. And he really is that sage wisdom that so many of us go to as we're trying to learn about this space because he has that site security arm. We have the IT arm and together we're bringing these stories to life. Now I had a great chat with Ray last week talking about Scattered Spider and really trying to analyze their movements a bit more when it comes to identity. And when we say identity, we're talking about Microsoft 365, Active Directory and Enter ID, how you identify a user within your infrastructure stack, your cloud stack. It's safe to say that identity becomes that connective tissue that provides context and trust throughout everything we do. And when that trust is broken, it can be incredibly harmful and detrimental, especially when you're in an active attack. So let's go ahead and roll back another clip of Ray telling us a bit more about Scattered Spider's movements. And once inside, these Scattered Spider threat actors often pivot to cloud identity systems like Enter ID. Evidence from our incident reports indicate they may elevate privileges, modify your identity policies, tamper with audit visibility, effectively redefining who the environment believes is in control. At that point, every login and MFA prompt must be treated as potentially untrusted. And once they've established this identity persistence, they exploit those collaboration platforms to blend in. Our investigations have documented attackers using legitimate accounts to access Exchange, SharePoint, OneDrive, even Teams. And this includes forwarding mail, creating OAuth apps and quietly staging data for exfiltration. Result is an erosion of trust in shared workspaces and communications. Now, this leads to, however, the most disruptive component of their attack, which is really about prolonged containment and eradication. In order to sever command and control, rebuild assurance, remove this entrenched adversary, organizations frequently must segment networks, rotate every privileged and service account and reissue credentials from a clean route. These deliberate time-consuming steps can extend recovery timelines days, weeks, or even longer, but they're essential to restoring confidence in our identity-driven systems. And Scattered Spider really proves that when identity itself becomes the battleground, recovery isn't about decrypting files, it's about rebuilding trust. Until identity layers are reestablished and verified, no other layer can be considered secure.

TL;DR

  • Scattered Spider is a loosely organized but highly effective cybercrime group that specializes in identity-based attacks targeting Microsoft 365, Active Directory, and Entra ID systems through social engineering and MFA bypass tactics.
  • Once inside networks, the group elevates privileges, modifies identity policies, and tampers with audit systems to establish persistent control while using legitimate collaboration platforms like Exchange, SharePoint, and Teams to blend in and stage data exfiltration.
  • Recovery from Scattered Spider attacks is uniquely challenging because it requires rebuilding trust in identity infrastructure through network segmentation, rotating all privileged credentials, and comprehensive verification—a process that can extend recovery timelines for weeks or longer compared to traditional ransomware.

Summary

This video examines Scattered Spider, a loosely organized but highly effective cybercrime group that has emerged as one of the most dangerous threat actors in 2025. Named by the cybersecurity community rather than self-identified, Scattered Spider distinguishes itself through sophisticated identity-based attacks that target Microsoft 365, Active Directory, and Entra ID infrastructure. The group's methodology centers on exploiting identity as the connective tissue of modern IT environments, using social engineering and MFA bypass techniques to gain initial access before pivoting to cloud identity systems. Once inside, attackers elevate privileges, modify identity policies, and tamper with audit visibility to redefine who the environment trusts as legitimate. The presentation features insights from Ray Ulmerle, Field CISO for Coveware by Veeam, who brings real-world perspective as a multi-time ransomware survivor and CISSP-certified security expert. The analysis emphasizes that recovery from Scattered Spider attacks requires rebuilding trust in identity systems through network segmentation, credential rotation, and comprehensive verification—a process that can extend timelines for weeks or longer compared to traditional ransomware incidents focused on file decryption.

Chapters

0:00 - Introduction to Scattered Spider
1:03 - Meet Ray Ulmerle, Field CISO
1:40 - Identity as Attack Surface
2:26 - Attack Methodology and Recovery Challenges

Key Quotes

0:19 "... one of the names that keeps popping up that I've been super interested in is Scattered Spider ..."
2:32 "... once inside, these Scattered Spider threat actors often pivot to cloud identity systems like Enter ID. Evidence from our incident reports indicate they may elevate privileges, modify your identity policies, tamper with audit visibility, effectively redefining who the environment believes is in control ..."
3:45 "Scattered Spider really proves that when identity itself becomes the battleground, recovery isn't about decrypting files, it's about rebuilding trust ..."
Categories:
  • » Cybersecurity » Cloud Security
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Identity & Access
  • Cloud Security
  • Security Operations
  • Technical Deep Dive
  • Scattered Spider threat actor group
  • Identity-based cyberattacks
  • Microsoft 365 security
  • Active Directory compromise
  • Entra ID vulnerabilities
  • MFA bypass techniques
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Scattered Spider: Identity-Based Cyber Threats in 2025

              Upcoming Webinar Calendar

              • 06/17/2026
                12:00 PM
                06/17/2026
                Action1: The Remediation Gap: Vulnerability Management in the Age of AI
                https://www.truthinit.com/index.php/channel/2010/action1-the-remediation-gap-vulnerability-management-in-the-age-of-ai/
              • 06/23/2026
                01:00 PM
                06/23/2026
                The AI-Powered VMware Alternative
                https://www.truthinit.com/index.php/channel/2009/the-ai-powered-vmware-alternative/
              • 06/24/2026
                11:00 AM
                06/24/2026
                LATAM: Accelerating Insights on AI Through an Engaging Webinar Series
                https://www.truthinit.com/index.php/channel/2012/accelerating-insights-on-ai-through-an-engaging-webinar-series/
              • 06/25/2026
                01:00 PM
                06/25/2026
                Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier
                https://www.truthinit.com/index.php/channel/1998/generative-ai-security-preventing-ai-from-becoming-a-data-breach-multiplier/
              • 07/01/2026
                04:00 AM
                07/01/2026
                Schutz von KI in Anwendungen, Agenten und APIs.
                https://www.truthinit.com/index.php/channel/2008/schutz-von-ki-in-anwendungen-agenten-und-apis/
              • 07/02/2026
                10:00 AM
                07/02/2026
                Resilience Insights from Hybrid Threats When the Cloud Faces Challenges
                https://www.truthinit.com/index.php/channel/2011/resilience-insights-from-hybrid-threats-when-the-cloud-faces-challenges/

              Upcoming Events

              • Jun
                17

                Action1: The Remediation Gap: Vulnerability Management in the Age of AI

                06/17/202612:00 PM ET
                • Jun
                  23

                  The AI-Powered VMware Alternative

                  06/23/202601:00 PM ET
                  • Jun
                    24

                    LATAM: Accelerating Insights on AI Through an Engaging Webinar Series

                    06/24/202611:00 AM ET
                    • Jun
                      25

                      Generative AI Security: Preventing AI from Becoming a Data Breach Multiplier

                      06/25/202601:00 PM ET
                      • Jul
                        01

                        Schutz von KI in Anwendungen, Agenten und APIs.

                        07/01/202604:00 AM ET
                        More events
                        Truth in IT
                        • Sponsor
                        • About Us
                        • Terms of Service
                        • Privacy Policy
                        • Contact Us
                        • Preference Management
                        Desktop version
                        Standard version