Scattered Spider Targets Airlines with Ransomware Attacks
Cybercriminal group Scattered Spider has shifted its focus to targeting airline companies after months of disrupting other major sectors, according to Microsoft's Defender Security Research Team.
This marks a change in tactics for Scattered Spider, which had previously targeted retail, food services, hospitality, and insurance sectors between April and July 2025.
The group is well-known for its aggressive social engineering tactics, often posing as legitimate users to deceive service desk staff into handing over access credentials. Microsoft reports that Scattered Spider has now begun targeting on-premises infrastructure first before moving into the cloud, a reversal from their previous cloud-first strategy.
The cybercriminals are using SMS phishing and adversary-in-the-middle (AiTM) tactics, and have recently been observed deploying DragonForce ransomware, particularly targeting VMware ESX hypervisor environments. Microsoft has beefed up protections across its Defender and Sentinel platforms to combat these attacks, including automated tools that can detect suspicious behavior and disable compromised accounts.