Ex-FBI agent warns insurers: Beware ‘Scattered Spider’ cyber attacks - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Top Stories
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Insurtech
Top Stories RSS Get our newsletter
Order Prints
June 30, 2025 Top Stories
Share
Share
Post
Email

Ex-FBI agent warns insurers: Beware ‘Scattered Spider’ cyber attacks

Robotic spiders crawling over a digial globe. A major international cybercrime organization known as Scattered Spider is setting its sights squarely on the insurance industry.
By Rayne Morgan

As a major international cybercrime organization known as Scattered Spider sets its sights squarely on the insurance industry, a former FBI agent and current head of cyber practice at Kroll is warning insurers to shore up their defenses.

“Awareness is key because oftentimes Scattered Spider is effectively exploiting people who are not security experts, but who are in very important and sensitive positions and help-desk-type environments. Their job is to facilitate access for people, so it’s kind of against their nature to not do that, but awareness is key, getting them trained up,” Adam Malone, global head, acute events in Kroll’s cyber risk practice, said.

Scattered Spider first emerged around 2021, when it began targeting major companies. It later began targeting insurance companies in 2023 but went quiet for about a year after U.S. law enforcement was able to make some arrests and disrupt their operations.

But now, the criminal organization is back. It’s already suspected of being behind a series of cyber attacks on U.S. insurers like AFLAC, Philadelphia Insurance Company, and Erie Insurance — all within just the last two to three weeks.

“Recently, we saw them come back on the scene targeting retailers in Europe, primarily the U.K., a couple of big cases suspected to be Scattered Spider. And now, the industry has started to notice a trend targeting insurance. One thing about Scattered Spider is they typically do stick with the sector for some period of time, for various reasons, before they move on to other victim types,” Malone said.

But the good news is insurers do have methods to protect against potential attacks, such as ensuring they have adequate training and internal cybersecurity plans in place. They can also leverage services like those provided by Kroll to have expert support in making sure their defenses stack up.

Scattered Spider’s unique threat

Scattered Spider poses a unique threat because it’s primarily English-speaking and exceptionally competent in social engineering. There have been signs that some of this group’s perpetrators are American young adults, which Malone described as an “unusual” and “worrisome” trend.

“Scattered Spider essentially was a group of people who formed this criminal group who were primarily English speakers and had very good skills in social engineering. They also had a lot of hands and feet that could do things like use identity theft to gain access to stolen phones and SIM cards, could call and speak with help desks in native English, and were good at impersonating people,” he explained.

The group began with different types of crimes but eventually partnered with ransomware groups to facilitate getting access into companies — and ransomware attacks can “bring a company to its knees for a matter of weeks, if not months.”

What insurers should watch out for

Malone, who also leads Kroll’s global digital forensics, incident response and intelligence functions, cautioned insurers that Scattered Spider’s specialty is in using company technology against itself.

“Their goal is to gain access to corporate assets masquerading as a corporate employee, typically or ideally an IT employee. They’re very good at using social engineering tactics — phone calls, text messages, spoofed domains to act like help desk or IT people in a company and gain access to people’s accounts and multi-factor capabilities to log in with very little difficulty into corporate networks,” he said.

They can even trick a cell phone provider into sending them a SIM device or SIM chip, enrolling a phone onto someone’s account and allowing them to bypass a lot of the legitimate controls companies have deployed.

Once they gain access to a company’s system, they very quickly use generalized IT knowledge that the company has documented against them. For example, they may consume intelligence from internal knowledge bases or ticketing systems, gathering usernames and passwords that are documented in manuals or policies and coding documents to facilitate their access.

“They pivot very quickly to trying to find the most sensitive information in an organization. Oftentimes, that’s regulated information or sensitive financial information that they will take in order to extort the company to increase their chances of being paid. And then, the last thing they’ll do is deploy ransomware,” Malone said.

Preparation is the best defense

To ensure they’re best prepared to rebuff a cyber attack, insurers should work with cyber experts within companies or through vendor relationships and empower them to develop a robust security plan.

Malone suggested insurers:

  • Think about what a cyber attack would look like and what bad actors would do
  • Assess and test their internal controls to see how effective those are
  • Plan out how they would respond to an attack (whether to pay ransom, how much to pay, who signs off, etc.)

“But all that comes second to education, having good policy, making sure people understand the controls that are in place and follow procedures appropriately and if they see something, say something,” Malone said.

Insurers can also work with companies like Kroll, which can help test their defenses, understand how to protect their most sensitive data and prepare overall.

Kroll is an international financial advisory services and risk management firm founded in 1932 and based out of New York, NY. It ventured into the cyber aspect of business in the early 2000s and currently sits on over 80 cyber insurance panels to provide specialized services and advice.

 

© Entire contents copyright 2025 by InsuranceNewsNet.com Inc. All rights reserved. No part of this article may be reprinted without the expressed written consent from InsuranceNewsNet.com.

Rayne Morgan

Rayne Morgan is a journalist, copywriter, and editor with over 10 years' combined experience in digital content and print media. You can reach her at [email protected].

Older

Actuaries seek better data on troubling age 80+ mortality trend

Newer

The reshaping of the Medicare Advantage market

Advisor News

  • NAIFA: Financial professionals are essential to the success of Trump Accounts
  • Changes, personalization impacting retirement plans for 2026
  • Study asks: How do different generations approach retirement?
  • LTC: A critical component of retirement planning
  • Middle-class households face worsening cost pressures
More Advisor News

Annuity News

  • Ancient Financial Launches as a Strategic Asset Management and Reinsurance Holding Company, Announces Agreement to Acquire F&G Life Re Ltd.
  • FIAs are growing as the primary retirement planning tool
  • Edward Wilson Joins SEDA, Bringing Deep Expertise in Risk Management, Derivatives Trading and Institutional Prime Brokerage
  • Trademark Application for “INSPIRING YOUR FINANCIAL FUTURE” Filed by Great-West Life & Annuity Insurance Company: Great-West Life & Annuity Insurance Company
  • Jackson Financial ramps up reinsurance strategy to grow annuity sales
More Annuity News

Health/Employee Benefits News

  • 'Welcome to the movement': Whitman College staff seek to form union
  • Red and blue states want to limit AI in insurance. Trump wants to limit the states
  • NABIP asks Congress to stabilize ACA market, address affordability
  • Expired federal subsidies leave fewer Walla Walla residents with health insurance
  • Red and blue states alike want to limit AI in insurance. Trump wants to limit the states.
More Health/Employee Benefits News

Life Insurance News

  • Corporate PACs vs. Silicon Valley
  • IUL tax strategy at center of new lawsuit filed in South Carolina
  • National Life Group Announces 2025-2026 LifeChanger of the Year Grand Prize Winner
  • International life insurer Talcott to lay off more than 100 in Hartford office
  • International life insurer to lay off over 100 in Hartford office
Sponsor
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Elevate Your Practice with Pacific Life
Taking your business to the next level is easier when you have experienced support.

LIMRA’s Distribution and Marketing Conference
Attend the premier event for industry sales and marketing professionals

Get up to 1,000 turning 65 leads
Access your leads, plus engagement results most agents don’t see.

What if Your FIA Cap Didn’t Reset?
CapLock™ removes annual cap resets for clearer planning and fewer surprises.

Press Releases

  • ICMG Announces 2026 Don Kampe Lifetime Achievement Award Recipient
  • RFP #T22521
  • Hexure Launches First Fully Digital NIGO Resubmission Workflow to Accelerate Time to Issue
  • RFP #T25221
  • LIDP Named Top Digital-First Insurance Solution 2026 by Insurance CIO Outlook
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2026 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet