Between July 1, 2024, and December 31, 2024, 50% of Scattered Spider’s phishing domains targeted the finance & insurance sector. This exposes the group’s clear focus on industries it believes to have high monetization potential, likely exploiting the sector’s critical need to avoid operational downtime and its management of vast stores of data.
The most prevalent attack types targeting the sector, which we’ll examine further in the report, include:
*Business email required.