Reporting attributes the 2025 retail intrusions to the loose cluster tracked as Scattered Spider, and describes a consistent shape: UK retailers from April, US retailers from late May, other sectors after that.
Sector Rotation Is A Research Artefact, Not A Preference
A group that works one industry at a time is not expressing an interest in groceries or jewellery. It is reusing research.
Social engineering against a service desk requires knowing what that desk expects: the identity-verification script, the vocabulary, the outsourcing arrangement, the name of the ticketing system. Within a sector those details repeat, because the same handful of vendors and the same handful of outsourcers serve everybody.
Learn one retailer’s help desk and you have substantially learned the sector’s. That is why the campaign moves in blocks and then jumps.
Which Means The Warning Is Legible In Advance
This is unusually actionable. Most of the threat intelligence in this database tells organisations what happened elsewhere without telling them what to do differently. Sector rotation says something narrower and more useful: when a peer in your industry is compromised through its service desk, you are inside the research window.
A Caution About The Label
"Scattered Spider" names a fluid set of individuals, not an organisation with a membership list. Techniques and infrastructure are shared across overlapping groups, and attributing a given intrusion to the name is a judgement about tradecraft resemblance rather than an identification.
This desk’s position, filed at 26-0429 and 26-0322, is that the label is useful for describing method and unreliable for counting incidents. Graded medium for that reason: the pattern is well evidenced, the boundary of the group is not.
Built on published reporting of the 2025 retail campaign, listed below, read against the incident files in this database. Attribution is as reported; we have not independently established it. Corrections: corrections@forensicpost.com.