{"type":"rich","version":"1.0","provider_name":"Transistor","provider_url":"https://transistor.fm","author_name":"Daily Security Review","title":"Scattered Spider Takes Flight: Inside the Cybercrime Group’s Move into Aviation","html":"<iframe width=\"100%\" height=\"180\" frameborder=\"no\" scrolling=\"no\" seamless src=\"https://share.transistor.fm/e/a1a2d343\"></iframe>","width":"100%","height":180,"duration":2618,"description":"As the aviation industry becomes more digitally interconnected, its exposure to sophisticated cyber threats continues to grow. One of the most dangerous actors in this space—Scattered Spider, a financially motivated and technically skilled cybercrime group—has recently shifted its focus to target the aviation sector. With recent incidents involving Hawaiian Airlines, WestJet, and others, global concern is rising over the safety of airline IT systems, vendor infrastructure, and the broader aviation supply chain.\nThis episode unpacks how Scattered Spider operates, why the aviation industry is increasingly at risk, and what this means for cybersecurity readiness in one of the world’s most critical sectors. Known for its deep social engineering tactics, the group bypasses MFA, exploits IT help desks, abuses third-party vendor trust, and deploys ransomware in record time. As the FBI, CISA, and leading cybersecurity firms like Mandiant and Palo Alto Networks sound the alarm, airlines and their partners are being forced to rethink how they defend against these agile, persistent attackers.\nIn this episode, we cover:\nThe evolving cyber threat landscape facing the aviation industry\nA breakdown of Scattered Spider’s tactics, including phishing, SIM swapping, and help desk impersonation\nHow the group maintains persistent access using federated identity and RMM tools\nSuspected links between Scattered Spider and recent incidents at Hawaiian Airlines and WestJet\nThe aviation supply chain as a prime vulnerability—why low-scoring vendors pose high risks\nWhy airlines face a 2.9x greater breach risk when they fall below an 'A' cybersecurity rating\nICAO's cybersecurity strategy pillars and what global coordination could look like in practice\nCISA’s mitigation guidance: offline backups, phishing-resistant MFA, patching, and more\nThe role of third-party risk management and “security by design” in preventing future breaches\nWhy the FBI discourages ransom payments—and what alternatives...","thumbnail_url":"https://img.transistorcdn.com/pL79_MJFeJHamQ_ztImsGmDSMdl27VMk_30TAkieujE/rs:fill:0:0:1/w:400/h:400/q:60/mb:500000/aHR0cHM6Ly9pbWct/dXBsb2FkLXByb2R1/Y3Rpb24udHJhbnNp/c3Rvci5mbS8yNzg5/ZjlhNzM5Y2M4Njli/NjkxNzgyODA2Nzhi/MDI2ZC5wbmc.webp","thumbnail_width":300,"thumbnail_height":300}