Exclusive: Ransomware gang Scattered Spider likely to have caused PHLY disruption, cyber sources say

Reuters
2025/06/13
Exclusive: Ransomware gang Scattered Spider likely to have caused PHLY disruption, cyber sources say

By James Thaler

June 12 - (The Insurer) - A cyberattack on Philadelphia Insurance Companies (PHLY) is likely to have been carried out by the Scattered Spider group, cyber sources told Cyber Risk Insurer on Thursday.

On Thursday, as the company faced an ongoing outage it initially told staff to report to its New York-area offices, before postponing their arrival time, and then canceling in-office attendance entirely, sources familiar with the situation said.

A spokesperson for PHLY did not immediately respond to a request for comment.

The company on Thursday sent at least three missives to employees, seen by Cyber Risk Insurer, initially requesting that underwriting, claims, insurance operations and marketing staff report to the firm’s Bala Cynwyd, Pennsylvania; Ewing, New Jersey; and Jersey City offices at 1 p.m. local time.

The company said in the communication that it was planning to grant limited access to “specific employees” in the office.

“Not everyone may get access today, but we need to be ready to resume operations from the office. Please do NOT access the network in the office until you receive specific instructions to do so,” the company said in its initial message to staff.

PHLY then told staff it was pushing back its expected arrival time to 3 p.m. EST, and would notify employees by 2 p.m. EST if there would be any changes to those plans.

It then asked those staff who received the memorandum to click a link acknowledging their receipt of the message.

Senior cyber industry sources said they were surprised by PHLY’s request that staff click a link to indicate whether they planned to return to the office in the immediate aftermath of a ransomware episode.

Shortly thereafter staff received a third message instructing them not to come into the office.

“Due to our continued network outage, we are asking employees NOT to report to any offices today, June 12th, UNLESS you are individually contacted,” the company wrote.

“If you came into the office today, thank you for your cooperation. We are doing our best to keep up with this fluid situation,” the note concluded.

Multiple senior cybersecurity and cyber (re)insurance industry sources pointed to the threat actor group Scattered Spider as the most likely culprit behind the ransomware attack affecting PHLY, and the similar, ongoing event affecting fellow Pennsylvania-based insurer Erie Indemnity.

Scattered Spider is a hacking group that has been around since May 2022. The ransomware gang has established a reputation for targeting multiple companies in a single industry in waves.

應版權方要求,你需要登入查看該內容

免責聲明:投資有風險,本文並非投資建議,以上內容不應被視為任何金融產品的購買或出售要約、建議或邀請,作者或其他用戶的任何相關討論、評論或帖子也不應被視為此類內容。本文僅供一般參考,不考慮您的個人投資目標、財務狀況或需求。TTM對信息的準確性和完整性不承擔任何責任或保證,投資者應自行研究並在投資前尋求專業建議。

熱議股票

  1. 1
     
     
     
     
  2. 2
     
     
     
     
  3. 3
     
     
     
     
  4. 4
     
     
     
     
  5. 5
     
     
     
     
  6. 6
     
     
     
     
  7. 7
     
     
     
     
  8. 8
     
     
     
     
  9. 9
     
     
     
     
  10. 10