A sophisticated hacking group known as UNC3944, which previously targeted major UK retail organizations, has pivoted its operations toward US-based companies, according to newly published research from Google Cloud.
The threat actor, which overlaps with public reporting on the group known as Scattered Spider, has demonstrated persistent use of social engineering tactics and brazen communications with victims, making them particularly dangerous to organizations with large help desk and outsourced IT functions.
The group initially gained notoriety for targeting telecommunications-related organizations to support SIM swap operations but shifted to ransomware and data theft extortion in early 2023.
Recent reporting suggested that threat actors using tactics consistent with Scattered Spider targeted a UK retail organization and deployed DragonForce ransomware, with BBC News indicating that actors associated with DragonForce claimed responsibility for attempted attacks at multiple UK retailers.
Google’s Mandiant researchers identified that retail organizations have become increasingly attractive targets for these threat actors, noting that retail victims now comprise approximately 11.4% of data leak site victims in 2025 thus far, up from about 8.5% in 2024.
Analysts believe these organizations are targeted due to their possession of large quantities of personally identifiable information and financial data, along with their vulnerability to ransomware attacks that could impact financial transactions.
The threat actor primarily targets English-speaking countries, including the United States, Canada, the United Kingdom, and Australia, with more recent campaigns extending to Singapore and India.
UNC3944 specifically focuses on large enterprise organizations with sizable help desk and outsourced IT functions that are particularly susceptible to their social engineering tactics.
According to the report, UNC3944 experienced a decline in activity following law enforcement actions against individuals allegedly associated with the group in 2024.
However, their existing ties to a broader community of threat actors could potentially help them recover more quickly than isolated groups.
The group’s most effective tactic involves sophisticated social engineering techniques that manipulate employees and IT staff.
UNC3944 conducts SMS phishing campaigns with messages claiming to be from IT departments, requesting users download software under the pretense that their machines are out of compliance.
They make phone calls to help desks, impersonating legitimate users to initiate password resets or MFA changes.
Security teams can detect these impersonation attempts using monitoring tools.
For example, Google SecOps provides this detection query for Microsoft Teams impersonation:-
metadata.vendor_name = "Microsoft"
metadata.product_name = "Office 365"
metadata.product_event_type = "ChatCreated"
security_result.detection_fields["ParticipantInfo"] = "true"
(
principal.user.userid = /help/ OR
principal.user.email_addresses = /help/ OR
about.user.user_display_name = /help/
) The group employs MFA fatigue attacks where they repeatedly send authentication prompts until users accept out of frustration.
They also leverage collaboration platforms like Microsoft Teams to pose as internal IT support personnel, creating convincing scenarios that lead victims to share credentials or approve authentication requests.
In some documented cases, attackers have even resorted to doxxing threats or aggressive language to intimidate users into compliance.
Security experts recommend organizations implement positive identity verification processes requiring on-camera verification, ID checks, or challenge/response questions before any security information changes.
Additionally, removing SMS and email as authentication factors in favor of phishing-resistant MFA and FIDO2 security keys can significantly reduce the risk of compromise from these increasingly prevalent social engineering attacks targeting both UK and US organizations.
How SOC Teams Save Time and Effort with ANY.RUN - Live webinar for SOC teams and managers
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…