Desk live·
ForensicPost
Breaches/Analysis/File 25-0702

One Scattered Spider Campaign Moved Through Four Sectors in Eight Months

Traced across 2025, one campaign moved through four sectors in eight months. The sequence is the most complete rotation the corpus has recorded.

Constructed geometry · not a chart of case data
TargetMultiple sectors
ActorScattered Spider
D. Kennedy & S. Rosler12 min readConfidence: medium3 sources reviewed

Assembled from the files in this database, the 2025 campaign sequence runs: UK retail from April, US retail from late May, insurance through June, aviation in June and July, and enterprise SaaS tenants across sectors from mid-year.

Eight Months, Four Sectors, One Technique

Marks & Spencer, Co-op and Harrods at 25-0430, 25-0501 and 25-0929. Farmers, Aflac, Erie, Philadelphia and Allianz Life at 25-0529, 25-0618, 25-0622 and 25-0717. Hawaiian, WestJet and Qantas at 25-0627 and 25-0701. Then the platform campaign at 25-0923 and its named victims at 25-0830.

The technique did not change. A caller, a service desk, and an authorisation granted to the wrong person.

The Rotation Accelerated

UK retail occupied roughly two months. Insurance and aviation overlapped within one. The corpus filed at 25-0627 that the warning window narrowed to days.

That is consistent with the capability-pooling argument at 25-0905 — several experienced actors combining removes the weakest link in each and increases throughput — and with the affiliate model at 25-1108, where growth comes from recruitment rather than innovation.

And It Ended By Abandoning Sectors Entirely

The final phase targeted users of a widely-adopted SaaS platform regardless of industry. That is a more efficient version of the same insight: if research is reusable because interfaces repeat, a single platform used across every sector is better than any one industry.

The corpus recorded that at 25-0923 as concentration without a shared compromise — the platform was never breached, and what concentrated was the method.

What A Defender Can Take From It

The sector-warning value this desk described as unusually actionable at 25-0512 degraded through the year, and by the final phase it was gone: there was no peer sector to watch, because the target was defined by a product rather than an industry.

What remains is technique-based defence — administrative consent, enrolment controls, out-of-band verification of anything that changes authorisation. Graded medium: the sequence is assembled by this desk from separately attributed incidents, and campaign membership is a research judgement.

This is an analysis file

It assembles a sequence from incidents recorded in this database whose campaign attribution follows published research. This desk has not independently established that all belong to one campaign. Corrections: corrections@forensicpost.com.

Sources
  1. Rampant cybercriminal group targets US airlinesCNN Business
  2. Key takeaways from the Scattered Spider attacks on insurance firmsPush Security
  3. Aviation under siege: the 2025 airline and airport cyberattack crisisBreached.Company
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary