London, UK: Cyber risk analytics firm CyberCube has flagged Manufacturing, Education, IT, and Retail as the industries most vulnerable to cyberattacks by Scattered Spider, the prolific extortion group behind a wave of high-profile breaches this year.
Once a relatively obscure social engineering crew, Scattered Spider has quickly evolved into one of the most dangerous ransomware-and-extortion actors on the global threat landscape.
Since April 2025, the group has accelerated its activities, targeting large enterprises across diverse sectors — including retail, insurance, and aviation — often using impersonation tactics and bypassing authentication controls to penetrate secure networks.
CyberCube’s analysis, based on a portfolio of 15,000 companies across eight major cyber insurance markets (USA, UK, Canada, Australia, Germany, France, Japan, and Singapore), found that 2% of firms with revenues over $500 million are in the highest risk category.
“These companies exhibit a dangerous combination of technologies frequently exploited by Scattered Spider and systemic security weaknesses,” said CyberCube in its latest threat update. “These conditions significantly increase the likelihood that attackers could complete the full lifecycle of a ransomware campaign.”
The report identified 287 companies as high risk, with a further 1,037 (7%) falling into a medium-risk category. These medium-risk firms were found to use at least one of the technologies frequently targeted by the group, though their network configurations would only allow for partial attack progression.
CyberCube’s findings are powered by its Portfolio Threat Actor Intelligence (PTI) platform, which uses AI to analyze threat actor behaviour, targeted technologies, and known vulnerabilities. The tool is part of CyberCube’s broader Concierge Threat Intelligence service, tailored for cyber insurers and reinsurers seeking to model aggregated risk exposure across portfolios.
Scattered Spider is known for its aggressive social engineering techniques, including help desk impersonation and targeted credential phishing, enabling it to infiltrate enterprise environments with speed and stealth. The group’s shift toward large-scale extortion has put insurers and portfolio managers on high alert.
CyberCube has also published a detailed industry breakdown of risk exposure on its website to help insurers and underwriters make informed coverage and mitigation decisions.
“CyberCube’s analysis reveals both a current cluster of elevated risk in the market and a strategic opportunity for cyber (re)insurers to act preemptively by managing exposure and incentivising better security before Scattered Spider strikes again,” said William Altman, Head of Cyber Threat Intelligence Services, CyberCube.
“For portfolio managers, our findings reinforce the need to move beyond broad sector assumptions and focus on mapping technological and security posture overlaps across seemingly unrelated sectors and insureds,” added Altman.
