Closing the door to Scattered Spider threats with the YubiKey and identity proofing

How to block Scattered Spider attacks with phishing-resistant MFA and identity proofing

Legacy MFA tools like push-based apps and one-time passcodes (OTPs) are far more common than they were five years ago, but Scattered Spider has built an entire playbook around defeating these MFA methods that most organizations have deployed. CISA’s updated advisory on the group, issued jointly with the FBI in mid-2025, outlines the recommended actions to mitigate these threats.

The group’s most recent confirmed spree against Marks & Spencer, Harrods, and Co-op in the UK starting June 2025, is estimated at £440 million in damage by the UK’s Cyber Monitoring Centre. Scattered Spider (also tracked as UNC3944, Octo Tempest, and Muddled Libra) relies on people more specifically, help desk agents, call centers, and the everyday MFA prompt on your phone.

Per the CISA advisory, their known techniques include repeatedly sending push notifications until a target approves out of fatigue, SIM-swapping a victim’s phone number to intercept SMS codes, and posing as an employee to convince IT staff to reset a password and transfer MFA to a device the attacker controls. None of these social engineering tactics require breaking cryptography – they only require a human to be tricked into sharing a secret, reassigning a phone number, or being willing to help.

Why phishing-resistant MFA helps stop Scattered Spider

The advisory’s core recommendation is direct: implement FIDO2/WebAuthn or PKI-based authentication, because these methods “are resistant to phishing and not susceptible to push bombing or SIM swap attacks.” NIST draws the same line: Only PIV/Smart Card and FIDO2/WebAuthn clear the bar for phishing-resistant MFA. Push apps with number matching and SMS codes, however widely deployed, do not.

The reason comes down to what each factor actually is:

  • SMS Codes: Interceptable numbers tied to phone control.
  • Push Notifications: Service-driven, portable yes/no decisions susceptible to fatigue and human error.
  • FIDO2 Security Keys: Hardware-bound cryptographic keys that sign challenges issued exclusively by the legitimate origin.

An adversary-in-the-middle (AiTM) kit quietly relays shared secrets into lookalike sites. However, FIDO2 binds cryptographic responses strictly to the registered origin. A lookalike domain can fool a person, but it cannot fool the protocol. This origin-binding systematically eliminates AiTM phishing, SIM swapping, and lookalike domain harvesting at the protocol level. For sign-ins that require a FIDO2 security key, there is no push notification to approve, the authentication is triggered by the user at login, not by the service and pushed to the user.. Repeated approval requests therefore cannot complete that sign-in .

However, one of Scattered Spider’s most effective techniques targets help desks – not your authenticator. Attackers call in using scraped OSINT (Open Source Intelligence) or stolen personal information data to sound legitimate, talking agents into resetting passwords or enrolling new MFA devices on their behalf. Attackers do not break FIDO2 encryption; instead, they exploit help desk social engineering to trigger unverified credential re-enrollment.No authenticator changes what happens when credential issuance relies on a phone script and human judgment. Current AI tools make these attacks even more effective, automating the impersonation of a legitimate user based on publicly available data.

That’s a different kind of problem, and it needs a different kind of fix: identity proofing at the point of credential recovery:

  • Require verified government ID alongside a live biometric or liveness check before any MFA device is reset or re-enrolled.
  • Treat MFA resets as privileged actions requiring privileged verification rather than routine help desk favors.


Deploying YubiKeys as primary and step-up authentication strips away push bombing, SIM swapping, AiTM phishing, and lookalike domains as attacker options. Adding verified identity proofing closes the final door at the help desk.


If you want to map the fastest path to phishing-resistant authentication and verified credential recovery across your organization, contact our team.

The post appeared first on Yubico.

添加评论
点赞收藏
点踩分享查看原文
评论
?
参与讨论