In the Scattered Spider case, the next major corporate breach walked through the front door rather than broke the window. If that pattern holds, it would mean the next major corporate breach is more likely to be won with a phone call than a zero-day. Britain's most disruptive recent cyber attackers, Scattered Spider, didn't run code exploits. They phoned help desks, sweet-talked employees, and walked out with the keys.
That is the part the arrest of Owen Flowers and Thalha Jubair does not retire. Paul Foster, head of the U.K. National Crime Agency's National Cyber Crime Unit, called Scattered Spider "the most significant cybercrime threat to the U.K. in recent years" and said the network has been "severely disrupted." Both phrases are precise. The people are convicted. The method is not.
The playbook is short. Pick a high-value target, study its people, call its help desk pretending to be a tired employee locked out of an account, and ride the resulting access into the rest of the network. Transport for London fell to it in 2024, taking ticketing and live arrival data offline for weeks and adding roughly £29 million (about $47 million) to the damage bill. The FBI tied Jubair to similar intrusions at more than 120 companies.
Code-level defenses do not catch this. "Severely disrupted" leaves the playbook in the wild, where a rebranded crew can pick it up tomorrow. In this case, the front line of corporate security appeared to shift from the server room to the support queue.
Reported by Sky for Type0, from UK cops say arrest of two young hackers disrupted the operations of an infamous hacking group. Read the original: techcrunch.com