[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f7zyxQpRkanBwZlS1Kv6K6rGY8KfYnyo5q2gVpJo0dfU":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":18,"created_at":19,"published_at":20,"article":21,"tags":25,"podcasts":38},"bbaafe78-e1ce-49bd-9f1b-ff1a80b24a26","sms-phishing-campaign-targets-tech-companies-via-social-engineering","f106e8f0-ddd1-41c2-aa21-069388880702","SMS Phishing Campaign Targets Tech Companies via Social Engineering","The Scattered Spider group successfully breached major technology companies through sophisticated SMS phishing attacks that exploited human vulnerabilities rather than technical flaws. By impersonating legitimate IT support and using social engineering tactics, attackers convinced employees to provide credentials and access, which then enabled devastating SIM-swap attacks against cryptocurrency investors. This case demonstrates how cybercriminals increasingly target the human element as the weakest link in security chains, bypassing technical controls through manipulation and deception. The attacks resulted in millions in losses and compromised sensitive customer data at multiple high-profile organizations.","**Immediate actions:**\n- Implement mandatory security awareness training focused on SMS phishing and social engineering tactics\n- Establish strict verification procedures for IT support requests received via phone or SMS\n- Deploy multi-factor authentication that doesn't rely solely on SMS-based verification\n\n**Long-term improvements:**\n- Develop and regularly test incident response procedures for suspected social engineering attacks\n- Create employee reporting mechanisms for suspicious communications with clear escalation paths\n- Implement zero-trust access controls that require multiple verification steps for sensitive operations\n\n**Detection measures:**\n- Monitor for unusual authentication patterns and access requests from employee accounts\n- Set up alerts for rapid changes to user privileges or security settings",[12,13,14,15,16,17],"CIS Control 14","NIST SP 800-50","NIST AC-2","NIST IA-2","ISO 27001 A.7.2.2","GDPR Article 32","published","2026-04-22T05:09:58.30608+00:00","2026-04-22T05:09:57.919+00:00",{"id":7,"url":22,"slug":23,"title":24},"https:\u002F\u002Fkrebsonsecurity.com\u002F2026\u002F04\u002Fscattered-spider-member-tylerb-pleads-guilty\u002F","scattered-spider-member-tylerb-pleads-guilty-ed95ee","‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty",[26,32],{"id":27,"name":28,"slug":29,"description":30,"color":31},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":33,"name":34,"slug":35,"description":36,"color":37},"7261eb8f-acd4-4d93-a489-7fdd652ec0ea","Security Awareness","security-awareness","Phishing, social engineering, human error","#22c55e",[]]