According to the CISA/FBI joint advisory AA23-320A published 16 November 2023, Scattered Spider targets large companies and their contracted IT help desks. Actors posed as employees to get password resets and MFA enrollment moved onto devices they controlled, spammed push prompts until someone accepted, SIM-swapped phone numbers to intercept SMS or voice MFA, and coached staff to read out one-time codes under an IT pretext. Public reporting does not name a single victim organization, a total org count, or specific ransom figures. Helpdesk recovery social engineering and coached live codes are the same attack class: someone is talked into handing over a transferable factor. A fix for that class exists; this post stays on what the advisory actually documents.
If you want the prevention angle, read the related article on mfa2point0.com.
FAQ
What does CISA AA23-320A say Scattered Spider actually did?
Scattered Spider, per CISA advisory AA23-320A, is a cybercriminal group that targets large companies and their contracted IT help desks. The advisory describes actors posing as employees to convince helpdesk staff to reset passwords and transfer MFA to attacker-controlled devices, posing as IT to collect OTPs or push employees into commercial remote-access tools, MFA fatigue via repeated push prompts, SIM swapping at carriers, org-themed phishing and smishing domains, and purchased employee or contractor credentials from illicit markets. Later updates add post-foothold RMM abuse, stealers, data theft for extortion, and ransomware variants including DragonForce. Public reporting in the advisory does not establish one named household victim or a quantified breach total.
How did the helpdesk password and MFA resets work?
The helpdesk path in Scattered Spider operations worked because actors impersonated legitimate employees well enough that IT or a contracted service desk reset the password and moved MFA enrollment onto hardware the attacker held. CISA’s July 2025 update language is explicit: they posed as employees to convince IT and helpdesk staff to provide sensitive information, reset the employee’s password, and transfer the employee’s MFA to a device they control. That is credential-phase access at recovery and re-enrollment, not magic after a finished login. Once the attacker owned the password path and the second factor binding, normal workforce SSO and admin routes opened under a legitimate-looking identity.
Did push fatigue and SIM swapping beat the MFA enterprises already had?
Yes, against legacy push and SMS-style factors. CISA documents repeated MFA notification prompts until employees pressed Accept, classic MFA fatigue, and separate cases where carriers transferred a target user’s number to an attacker SIM so MFA prompts and recovery traffic followed the new card. Those methods abuse transferable, channel-bound factors. They are not proof that “MFA is useless.” They are proof that approve-deny spam and phone-number control still complete many enterprise second factors. Public reporting in AA23-320A does not attribute these wins to an adversary-in-the-middle reverse proxy or to a named Temporary Access Pass flow.
After the identity foothold, what else does the advisory describe?
After sign-in succeeded, Scattered Spider activity in the advisory moves into legitimate remote tools such as AnyDesk, TeamViewer, ScreenConnect, and Ngrok, plus credential and cookie theft with tools including Mimikatz, Raccoon, and VIDAR, then data theft for extortion and, in later updates, ransomware encryption including DragonForce-linked activity. That phase steals sessions and secrets from machines that already hold access. No login MFA undoes cookies, memory dumps, or RMM sessions already in attacker hands. Closing the helpdesk reset, fatigue, SIM, and OTP-coaching paths is the upstream story; stealer and extortion work is containment, EDR, and session hygiene after the fact.
Is helpdesk vishing a different MFA failure than coaching a user on a call?
No. In Scattered Spider reporting, talking helpdesk into a password reset and MFA transfer is the same social-engineering class as talking an employee into reading an OTP, approving a push, or following fake-IT instructions on the phone or SMS. Both coach a human into releasing or rebinding a transferable factor. Org-lookalike SSO, helpdesk, and Okta-themed domains in the advisory feed the same weak password-plus-legacy-MFA surface. Public reporting does not establish a single universal victim playbook for every intrusion, but the advisory’s identity TTPs cluster on enrollment, recovery, and phishable second factors before the later malware and extortion stages.