[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fd270uRk5uCvaFETeyJuA54-tVqZwN1kE8NUuRO544_k":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":17,"created_at":18,"published_at":19,"article":20,"tags":24,"podcasts":37},"234b4f78-cf12-4841-9aec-332ba1757cad","scattered-spider-leaders-multi-million-dollar-phishing-and-sim-swapping-scheme","60919f84-065e-4428-894b-d6706fb019b3","Scattered Spider Leader's Multi-Million Dollar Phishing and SIM-Swapping Scheme","Tyler Buchanan's guilty plea highlights how sophisticated social engineering attacks can bypass technical security controls to steal millions. The Scattered Spider group used phishing to harvest credentials and SIM-swapping to circumvent multi-factor authentication, specifically targeting high-net-worth individuals and businesses. This case demonstrates that even well-funded targets remain vulnerable when attackers combine social engineering with technical exploits. The $8 million in stolen cryptocurrency over 18 months shows how quickly these attacks can scale and cause significant financial damage.","**Immediate actions:**\n- Implement comprehensive phishing awareness training for all employees with regular testing\n- Deploy anti-phishing email security solutions with URL sandboxing and attachment analysis\n- Enable account lockout policies and anomalous login detection for all user accounts\n\n**Long-term improvements:**\n- Establish hardware-based authentication tokens instead of SMS-based 2FA for privileged accounts\n- Create incident response procedures specifically for social engineering and account takeover scenarios\n- Implement privileged access management with just-in-time access controls\n\n**Detection measures:**\n- Monitor for unusual login patterns, device changes, and geographic anomalies\n- Set up alerts for password resets and authentication method changes\n- Deploy user behavior analytics to detect compromised account activity",[12,13,14,15,16],"CIS Control 14 (Security Awareness and Training)","CIS Control 6 (Access Control Management)","NIST SP 800-63B (Authentication Guidelines)","NIST IR-7621 (Small Business Information Security)","ISO 27001 A.7.2.2 (Information Security Awareness)","published","2026-04-22T02:09:51.051083+00:00","2026-04-22T02:09:50.758+00:00",{"id":7,"url":21,"slug":22,"title":23},"https:\u002F\u002Fcyberscoop.com\u002Fthe-com-scattered-spider-hacker-tyler-robert-buchanan-guilty-plea\u002F","scottish-man-pleads-guilty-to-attack-spree-that-created-scattered-spider-s-notor-519b84","Scottish man pleads guilty to attack spree that created Scattered Spider’s notoriety",[25,31],{"id":26,"name":27,"slug":28,"description":29,"color":30},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":32,"name":33,"slug":34,"description":35,"color":36},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]