Truth in IT
    • Sign In
    • Register
        • Videos
        • Channels
        • Pages
        • Galleries
        • News
        • Events
        • All
Truth in IT Truth in IT
  • Data Management ▼
    • Converged Infrastructure
    • DevOps
    • Networking
    • Storage
    • Virtualization
  • Cybersecurity ▼
    • Application Security
    • Backup & Recovery
    • Data Security
    • Identity & Access Management (IAM)
    • Zero Trust
    • Compliance & GRC
    • Endpoint Security
  • Cloud ▼
    • Hybrid Cloud
    • Private Cloud
    • Public Cloud
  • Webinar Library
  • TiPs
  • DRAW

Varonis: UK Retail Cyberattacks: Scattered Spider, Dragon Force & Defense

Varonis
08/16/2026
0 (0%)
Share
  • Comments
  • Download
  • Transcript
Report Like Favorite
  • Share/Embed
  • Email
Link
Embed

Transcript


Hey, David. How are you? I'm doing well. I think we should welcome everybody to another episode of State of Cybercrime. It's great to have you back, David, and to our audience. And where in the world are you today? You've got a nice fresh new background. Yes, I'm still in Connecticut, although it may look a lot neater than my normal background. That's awesome. How about you? Yeah, I'm in London today. And I also have a, it's just a background, though I wish that's what the view looked like. It's a bit gray and gloomy today here. The background, you're in luck, because the background kind of looks gray and gloomy anyway. That'll work. Well, we've got a jam-packed agenda today, mainly excited to talk about some of the attacks on retailers here in the UK. But with that, let's get into it. For those of you that are joining us for the first time today, we always like to start the show with good news, as oftentimes in cybersecurity, everything is doom and gloom, and we are one vulnerability or one new AI away from the end of the world. But there's often a lot of good things to talk about as well, and we certainly have a few good things today, starting with TikTok. TikTok was fined €530 million by the Irish Data Protection Commission for violating GDPR, claiming TikTok failed to prevent remote access by employees in China to European user data. Now, initially, TikTok claimed that no EU data was stored in China, and what the data commission was arguing is that EU data was accessed by employees in China while that data was residing in the EU, which raises concerns about nation-state level data sharing and snooping. Ultimately, TikTok is planning to appeal the fine. Yeah, this is kind of cute, right? No, we don't store data outside of the EU. We just read it from outside the EU. You know, it's an interesting distinction there. Yeah, and I don't think the Irish Data Protection Commission really, you know, it seems like by the fine that they have a pretty firm stance on this. Yeah, that wasn't a small fine there. This was good news. I think coming on the heels of some kind of scary news, a few episodes ago, we talked about how MITRE's funding was in question with all the changes. And I think it's fair to say everybody in security said, oh, yeah, we probably ought to have some redundancy for such a mission-critical thing as kind of our vulnerability tracking. Well, European Union Agency for Cybersecurity, or ENISA, has been created. I love it when an acronym is just as hard to remember as the actual thing it stands for. But this is, it's good. You're going to have another source to track vulnerabilities. Actually, this is going to amalgamate multiple sources. It complements MITRE, so it's going to include a new EUVD ID, as along with all the other identifiers for each vulnerability, like the CVE. It uses the Common Security Advisory Framework, which I think is a good thing because we can use automation to kind of help stay on top of vulnerabilities. And we have yet another vulnerability database to monitor until such time as we lose one. Hopefully we don't. Well, another one for the EU, I guess. Yeah. Yeah. Well, speaking of wins for the EU, another win for Europol. As a part of Operation Power Off, Europol took down a distributed denial of service for hire, and they were launching cybersecurity attacks and denial of service attacks all over the globe. In total, nine domains were seized by U.S. authorities, and four individuals aged 19 to 22 were arrested in Poland. What was interesting about these attacks is that they were launched for as little as payments of 10 euros, and they required no technical skills by those hiring the hackers. They literally just had to submit their 10-euro payment and provide a target IP address. Targets of attacks included things like schools, governments, businesses, and gaming platforms, and the attacks were carried out between 2022 and 2025. Curious. This is marketed as a stress-testing service, right? So make sure your website can handle DDoS attacks. But for 10 euros a month or whatever, you could take your school down or take your competition down. Glad this is sort of taken offline. Yes, it was pretty trivial. This is more cooperation between, actually, law enforcement agencies from multiple countries. Operation Moonlander involved U.S. authorities, Dutch authorities, Thai authorities, and they took down two proxy networks, anyproxy.net, 5sox.net. These were domains that were managed by a Virginia-based company, but it was actually a ransomware service or a botnet, rather, that made use of a lot of older routers. Linksys, Cisco, routers at the end of life, especially if you had remote admin on. And the reason it's called Moonlander is because when you had these vulnerable routers, they would load malware called the moon. And on their website, it said, working since 2004, they'd collected over 46 million. And three Russian nationals were indicted, and that's apparently where the service was really running from, even though the domains were managed by the Virginia-based company. So, another one for the good guys there. Yeah, and I feel like with every episode now, we're probably talking about cooperation between multiple international law enforcement agencies around cybersecurity. So, safe to say the trend is moving in the right direction for that. Cooperation is a good thing. Now on to our biggest segment, AI Bay, which will surely leave you saying AI Bay. Now, do you say it AI Bay, or do you say it AI Bay? I don't know. I mean, it's tomato, tomato, right? But this story is about a different kind of botnet. It's an influencer botnet powered by Claude. And actually, this botnet is influencer as a service. And you can buy social media influence. And the way this works, you know, okay, yeah, sign me up. I want to influence. I want to kind of propagate this position. And the way it worked is it used Claude to create 100 or so personas that would amplify different political perspectives. And since it was observed, both supporting and undermining political interests of different countries are like the EU, the UAE, and other countries and regions. You know, it very much looks like anybody could kind of pay to kind of say, this is the position I want to propagate. Not sure who is behind the different, you know, intentions there. But some of the interesting things is it used Claude to create content posts, you know, so that the posts themselves, but also prompts for AI image generating services. So, you know, you're kind of like having one AI write prompts to generate or, you know, to manipulate another AI. So you get the images there. But it also engineered the strategy for when to comment, when to like, when to reshare from humans. So, and actually one interesting thing, it would even respond with sarcasm and humor if people accused the influencers of being bots themselves. So this seems like a great idea. Yeah, I mean, look, if you're trying to boost your social media, this seems like an awesome way to take care of it. Yeah, so but this has been taken down by Anthropic. So it's a good thing there. So it's social media is a tricky thing. What's going on in Langflow? Longflow? Yeah. I heard you about pronouncing it. Langflow is a low code platform that you can use to develop AI apps and, you know, RAG AI agents. You can basically build AI workflows without too much coding. And people are using it to prototype chatbots and different things, different AI applications. And the way it works is it has endpoints. So there are these API endpoints where you can interact. And even though they're not really intended to be Internet facing, it happens, right? Researchers that found a flaw in these found at least 500 exposed instances of these endpoints on the Internet. And the problem is there's a remote code execution flaw in these that allows any attacker to connect to these endpoints without authenticating and then upload some malicious code and then, you know, take over essentially. So there's a very high likelihood of exploitation. There's a CVE-2025-3248. And so it's recommended to upgrade to version 1.40 and also restrict the network access. If you're using this in the federal agency, you've got until May 26th to apply the update or do other mitigations. So it's an LLM platform with a vulnerability. And Matt, do you think this is a vulnerable vulnerability? Maybe it belongs in the other segment. Speaking of which, let's jump on to our next segment, Vulnerable Vulnerabilities, where we talk about one in SAP, actually in a component called NetWeaver. For those of you unfamiliar with it, NetWeaver is an integration platform within the SAP ecosystem for integrating SAP components to each other and to third party software. Unpatched NetWeaver servers are being exploited with CVE-2025-31324, which affects a component in SAP called Visual Composer. This vulnerability allows an unauthenticated threat actor to upload a file and actually gain full control over the system. While not installed by default, this component, Visual Composer, is broadly installed across the SAP customer base. An emergency patch was deployed by SAP, however, but multiple ransomware attacks have already been carried out using the compromised SAP systems as entry points for stuff like data theft and encryption. And some of that activity was linked to Chinese threat actors, though other ransomware groups are also involved. This is a big deal. There's some pretty powerful stuff behind a lot of these SAP implementations, as I understand. And usually a lot of sensitive information, yeah. Yeah, totally. What's going on with Commvault? Okay, well, so researchers discovered a flaw impacting a component of Commvault called the Commvault Command Center. And this is a maximum security CVE-2025-03408, and it allows remote code execution from an unauthenticated user. The way it works is an attacker can upload a zip file that, when it's decompressed on the target server, can result in remote code execution. This is addressed in versions 11.3.8.2.0 and 11.3.8.2.5 with an additional update. So be careful if you're just upgrading. There's an extra step there. If you're in the federal executive branch, you have to get until May 23rd to apply this. Also, a couple of things to note. Again, this is not something that's a server that's commonly connected to the internet, but it does happen, especially if you've got third-party management and help think about sourcing components there. Another thing to note is that if you haven't registered with Commvault, which can happen if you bought the application through an application store, like a Microsoft store or AWS store, I think, then you might not see these updates. So just better to check, and of course, best not to have these things internet-facing to begin with. And that CVE-2025-03408, I think Frank also put it in the chat for a few people that were asking. Now, that's not the only vulnerability to be worried about, though. Fortinet's released a patch for CVE-2025-32756, which is a stack overflow vulnerability in FortiVoice, FortiMail, FortiNDR, FortiQuarter, and FortiCamera, which allows unauthenticated hackers to execute commands via specially crafted HTTP requests. And interestingly enough, Fortinet claimed it observed exploits of this vulnerability on their FortiVoice systems. Now, successful exploitations could lead to things like network scanning, the erasing of logs, and also the logging and copying of credentials from SSH tunnel attempts. And so patching is strongly, strongly recommended. Somewhere around 50,000 to 100,000 different organizations were impacted by this with millions and millions of end users. Well, let's jump on in the danger zone and let's talk about a few of things that you should be worried about. One of which being misconfigured Sentinel-1 EDRs are vulnerable to attack that's being coined, bring your own installer. A flaw in the upgrade and downgrade process of the Sentinel-1 agent under certain configurations would allow attackers to bypass anti-tamper protections and actually temporarily leave the endpoint unprotected by EDR. Specifically, what happens is during the downgrade process, Sentinel-1 protection goes unavailable or not working, not functioning for just under a minute. And security researchers proved how during this time attackers could terminate processes, execute malicious payloads, and ultimately what Sentinel-1 did in response is released a new default configuration and encouraged users not to set up this downgrade process in order to avoid exploitation. Yeah, I was curious about this, you know, the fact that it had a downgrade option. I suppose that is to kind of, you know, if something breaks, like to roll back, right? To prioritize availability, probably. Yeah, that old availability versus the rest of security trick. Now, what's going on with Coinbase? Well, Coinbase, this is kind of an interesting one. I think it's, you know, security seems worst nightmare, right? You've got an insider that, you know, turns threat, right? An employee that gets bribed, and this happened. Attackers bribed support staff that were hosted in India to get customer data. And they were able to get addresses, government ID images, partial banks, social security numbers, and give it to the attackers who then use this to socially engineer Coinbase clients to potentially get their credentials and actually, you know, steal their Bitcoin. First, they asked for a ransom of $20 million to not use this information or to get it back. When Coinbase refused, they went ahead and did it for the social engineering, if I understand the sequence correctly. They've discovered this, they fired the compromised staff. They offered to make any customers that lost their coin, they'd make them whole. And of course, reminded users that it won't contact them and ask for passwords or things and or ask them to transfer to a different wallet, things like that. But the interesting twist on this one is they kind of took matters into their own hands. They offered a $20 million bounty for whoever turns them in. And I'm assuming that that is not dead or alive. But it is just sort of start to seem like the Wild West there. And I think when you know, Dave, when you think about like the all the crypto millionaires or crypto billionaires that exist, having access to, you know, a list of Coinbase customers and what their ledgers were with all the data that's available on social media, you can imagine that that's pretty valuable in the hands of criminals that are trying to commit crimes where, you know, the can cross geographic boundaries or where if they send the Bitcoin to certain places, it might be untraceable or unreceivable. Yeah, I mean, there's been a lot of efforts to kind of make it more traceable and kind of mitigate some of that. But I think it still is something that at least it's perceived as it's a little bit of a different thing. It's like stealing somebody's gold, right, that they had in their closet. It's less traceable than that. So, yeah, I could understand why attackers would go after this. It's kind of, you know, this is where the money is in many ways. Now for the story that I personally have been getting asked a ton about in the last couple of weeks, there's been a rise in attacks on companies in the UK retail sector. They've been hit by a wave of ransomware attacks that have done things like disrupt operations, expose customer data. And a lot of organizations are scrambling their defenses in order to try to repel off attacks from either Scattered Spider or Dragon Force, which I'll talk more about in a minute. These attacks have been carried on a major British retailers like Co-op UK, Harrods, Marks & Spencers, causing widespread outages. Specifically, of notable Marks & Spencers, their breach was so bad that the company's online purchasing system still isn't processing orders. And they're seeking a 100 million pound cyber insurance payout, the largest in the UK's history. Now, Google's Mandiant's threat intelligence arm is claiming that these attacks do follow a typical pattern from Scattered Spider, though Dragon Force is claiming that they may also be responsible. For those of you unfamiliar with Dragon Force, they're known for leveraging customized malware payloads, advanced social engineering, and they do have a particular focus on high value retail targets. Now, it's important to note, though, that this isn't over yet. What started as a UK pocket of cybercrime activity is now going global, also according to Google and Mandiant and other threat intelligence sources, starting with attacks on US retail chains. Now, I'm sure many of you are wondering, like, well, what can we do? How can we help our organization be prepared for some type of attack, especially if you're in the retail or, you know, customer service type industry? Well, the Varonis forensics team has prepared some recommendations, which David and I are going to go through next. It's interesting. You know, it sort of seems to be retail's turn, right, to be targeted by these actors. And I guess if you're in retail, Mandiant, I think, said shields up. I don't know why in cybersecurity your shields wouldn't ever be up, but, you know, it's good to be good to be. If you have discretionary to apply, now would be the time to do it. Yeah, exactly. So what are we supposed to do against against these attacks? I guess, you know, MFA is always a good thing. Right, Matt? Yeah. And I also think it's important to note now a big part of the scattered spider dragon force tactics is to impersonate your help desk. So this would be a great time to make sure that your employees know how to validate that they're talking with the actual help desk and that your help desk knows how to assure the people that they're working with that they are the actual help desk and that you're leveraging some type of multifactor authentication and maybe even logging and monitoring when password changes occurs or new device registration occurs. As you know, taking over phones, re-registering them for MFA to bypass MFA, or even just impersonating help desk users is a big part of the MO of both groups. Yeah, and it seems like the profile of, I guess, the employee pool at retailers, right? There are usually a lot of employees that may not be as, I mean, they may be using computers for email, right, and some other, you know, functions and things. Like store computers. And so probably a lot of employees that may not have as much experience using computers for a lot of different things, right, and might be a little bit more vulnerable with some of these attacks as well. Yeah, also just stuff like, you know, making sure that, you know, you have coverage of the endpoint antivirus. You know, you're trying to block traffic to malicious or suspicious websites. You've done things like security awareness training. One person in our chat suggested red teaming the help desk. I think that's a great idea. Also red teaming stuff like your active directory and being able to make sure you can detect attacks on AD is, you know, the entry point might be some end user that you have, whether it's a retail employee or a back office employee. But what are these attackers going to do? They're going to try to get access to information, escalate privileges, take over your domain, unleash ransomware. Also just, you know, basic stuff like denying internet traffic from like your server zones, patching your systems from all the vulnerabilities that David and I talked about, but also all other vulnerabilities, you know, having good backups. These are all things that you can do to be more resilient against cyber attack. Yeah, I think some of the identity, you know, red teaming here is interesting, right? Because an account is an account, right? And even though some of these accounts may not have much access, right, they're still connected in and then can be used to maybe exploit any vulnerability in there. You know, we've seen that once you have one account, right, there's a lot you can do once you're in a network and connected in. That'll wrap it up for us. We super appreciate you being here and we look forward to catching you on the next episode of State of Cybercrime. Thank you.

TL;DR

  • TikTok fined €530 million by Irish regulators for allowing Chinese employees to remotely access EU user data, demonstrating stricter enforcement of data residency versus data access distinctions.
  • Critical vulnerabilities in SAP NetWeaver, Commvault Command Center, and multiple Fortinet products are being actively exploited, with federal agencies facing imminent patching deadlines.
  • UK retailers Marks & Spencer, Co-op, and Harrods suffered major ransomware attacks from Scattered Spider and Dragon Force, with M&S seeking a record £100 million insurance payout.
  • Coinbase experienced an insider threat when support staff in India were bribed to steal customer data including government IDs and partial financial information for social engineering attacks.
  • Defense recommendations include strengthening help desk verification procedures, red teaming Active Directory, implementing network segmentation, and ensuring comprehensive endpoint protection coverage.

Cybersecurity Wins and Regulatory Actions

The episode opens with positive developments in cybersecurity enforcement and international cooperation. TikTok received a €530 million GDPR fine from the Irish Data Protection Commission for allowing Chinese employees to access EU user data remotely, highlighting the distinction between data storage and data access in privacy regulations. The European Union Agency for Cybersecurity (ENISA) launched a new vulnerability database that complements MITRE's CVE system, providing redundancy for critical vulnerability tracking. Europol's Operation Power Off dismantled a DDoS-for-hire service that enabled attacks for as little as 10 euros, while Operation Moonlander took down proxy networks that had been operating since 2004, collecting over $46 million by exploiting end-of-life routers.

Critical Vulnerabilities Requiring Immediate Attention

Several high-severity vulnerabilities demand urgent patching across enterprise environments. SAP NetWeaver's Visual Composer component contains CVE-2025-31324, allowing unauthenticated attackers to upload files and gain full system control, with Chinese threat actors and ransomware groups already exploiting unpatched servers. Commvault Command Center has a maximum-severity remote code execution flaw (CVE-2025-03408) exploitable via malicious zip file uploads. Fortinet released patches for CVE-2025-32756, a stack overflow vulnerability affecting FortiVoice, FortiMail, FortiNDR, FortiQuarter, and FortiCamera products, with active exploitation already observed. The Langflow AI development platform also has a critical RCE vulnerability with over 500 exposed instances discovered online.

UK Retail Sector Under Coordinated Attack

A wave of ransomware attacks attributed to Scattered Spider and Dragon Force has severely impacted major UK retailers including Marks & Spencer, Co-op UK, and Harrods. Marks & Spencer's breach was particularly devastating, with online purchasing systems still non-functional and the company seeking a £100 million cyber insurance payout—the largest in UK history. Google Mandiant confirms these attacks follow Scattered Spider's typical patterns, which rely heavily on social engineering, help desk impersonation, and MFA bypass techniques. The threat is expanding globally, with US retail chains now being targeted. The Varonis forensics team recommends strengthening help desk verification procedures, implementing robust MFA, conducting red team exercises against identity systems, and ensuring comprehensive endpoint coverage and network segmentation.

Chapters

0:00 - Introduction
1:10 - Good News: TikTok GDPR Fine
2:29 - ENISA Vulnerability Database Launch
3:54 - Europol Operations Power Off and Moonlander
6:17 - AI-Powered Influencer Botnet
8:27 - Langflow AI Platform Vulnerability
10:01 - SAP NetWeaver and Commvault Vulnerabilities
13:00 - Fortinet Stack Overflow Vulnerability
13:38 - SentinelOne EDR Bypass Flaw
14:49 - Coinbase Insider Threat Incident
17:15 - UK Retail Ransomware Attacks
18:55 - Defense Recommendations

Key Quotes

1:43 "TikTok failed to prevent remote access by employees in China to European user data."
2:06 "No, we don't store data outside of the EU. We just read it from outside the EU. You know, it's an interesting distinction there."
15:01 "An employee that gets bribed, and this happened. Attackers bribed support staff that were hosted in India to get customer data."
17:54 "They're seeking a 100 million pound cyber insurance payout, the largest in the UK's history."
19:03 "It sort of seems to be retail's turn, right, to be targeted by these actors."

FAQ

What should organizations do to protect against Scattered Spider and Dragon Force attacks?

Implement robust help desk verification procedures so employees can validate they're speaking with legitimate IT staff. Enable comprehensive MFA and monitor for password changes and new device registrations. Conduct red team exercises against your help desk and Active Directory. Ensure endpoint antivirus coverage, block traffic to suspicious websites, segment server zones from internet traffic, and maintain tested backups.

Why are retail organizations particularly vulnerable to these social engineering attacks?

Retail environments typically have large employee pools with varying levels of technical experience, many using computers primarily for email and basic functions on store computers. This makes them more susceptible to social engineering tactics like help desk impersonation. Once attackers compromise any account, they can exploit network access to escalate privileges and move laterally toward domain takeover.


Categories:
  • » Webinar Library » Varonis
  • » Cybersecurity » Data Security
  • » Cybersecurity » Identity & Access Management (IAM)
  • » Data Protection
Channels:
News:
Events:
Tags:
  • Threat Intelligence
  • Data Privacy
  • Vulnerability Management
  • Security Operations
  • Identity & Access
  • GDPR enforcement
  • vulnerability management
  • ransomware attacks
  • social engineering
  • insider threats
  • retail cybersecurity
  • AI-powered threats
  • identity security
Show more Show less

Browse videos

  • Related
  • Featured
  • By date
  • Most viewed
  • Top rated
  •  

              Video's comments: Varonis: UK Retail Cyberattacks: Scattered Spider, Dragon Force & Defense

              XStreaminars (watch here)

              • Aug
                27

                Becoming Agent Ready with Cyera: Essential Strategies and Insights

                08/27/202601:00 PM ET
                • Sep
                  03

                  Verge.io: Can You Afford Your Next Storage Refresh?

                  09/03/202601:00 PM ET
                  More events

                  Industry Events (Sponsor Hosted)

                  • Aug
                    27

                    Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration

                    08/27/202601:00 PM ET
                    More events

                    Upcoming Webinar Calendar

                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Becoming Agent Ready with Cyera: Essential Strategies and Insights
                      https://www.truthinit.com/index.php/channel/2081/becoming-agent-ready-with-cyera-essential-strategies-and-insights/
                    • 08/27/2026
                      01:00 PM
                      08/27/2026
                      Summer of Satori: FunFoneFarm's Transformation of Fraud into Seamless Integration
                      https://www.truthinit.com/index.php/channel/2086/summer-of-satori-funfonefarms-transformation-of-fraud-into-seamless-integration/
                    • 09/02/2026
                      12:00 PM
                      09/02/2026
                      Unified Data Security in Action: Uncover, Analyze, and Resolve Threats
                      https://www.truthinit.com/index.php/channel/2045/unified-data-security-in-action-uncover-analyze-and-resolve-threats/
                    • 09/03/2026
                      01:00 PM
                      09/03/2026
                      Verge.io: Can You Afford Your Next Storage Refresh?
                      https://www.truthinit.com/index.php/channel/2082/verge-io-can-you-afford-your-next-storage-refresh/
                    • 09/30/2026
                      04:00 AM
                      09/30/2026
                      AI Command Center: Optimizing Visibility and Control in Your Operations
                      https://www.truthinit.com/index.php/channel/2024/ai-command-center-optimizing-visibility-and-control-in-your-operations/
                    • 11/19/2026
                      01:00 PM
                      11/19/2026
                      360View: Govern, Secure & Recover Your Microsoft 365 Environment
                      https://www.truthinit.com/index.php/channel/2076/360view-govern-secure-recover-your-microsoft-365-environment/
                    Truth in IT
                    • Sponsor
                    • About Us
                    • Terms of Service
                    • Privacy Policy
                    • Contact Us
                    • Preference Management
                    Desktop version
                    Standard version