Cyber Security News

Google Details Hackers Behind UK Retailers Attack Now Targeting US

A sophisticated hacking group known as UNC3944, which previously targeted major UK retail organizations, has pivoted its operations toward US-based companies, according to newly published research from Google Cloud.

The threat actor, which overlaps with public reporting on the group known as Scattered Spider, has demonstrated persistent use of social engineering tactics and brazen communications with victims, making them particularly dangerous to organizations with large help desk and outsourced IT functions.

The group initially gained notoriety for targeting telecommunications-related organizations to support SIM swap operations but shifted to ransomware and data theft extortion in early 2023.

Recent reporting suggested that threat actors using tactics consistent with Scattered Spider targeted a UK retail organization and deployed DragonForce ransomware, with BBC News indicating that actors associated with DragonForce claimed responsibility for attempted attacks at multiple UK retailers.

Google’s Mandiant researchers identified that retail organizations have become increasingly attractive targets for these threat actors, noting that retail victims now comprise approximately 11.4% of data leak site victims in 2025 thus far, up from about 8.5% in 2024.

Analysts believe these organizations are targeted due to their possession of large quantities of personally identifiable information and financial data, along with their vulnerability to ransomware attacks that could impact financial transactions.

The threat actor primarily targets English-speaking countries, including the United States, Canada, the United Kingdom, and Australia, with more recent campaigns extending to Singapore and India.

UNC3944 specifically focuses on large enterprise organizations with sizable help desk and outsourced IT functions that are particularly susceptible to their social engineering tactics.

According to the report, UNC3944 experienced a decline in activity following law enforcement actions against individuals allegedly associated with the group in 2024.

However, their existing ties to a broader community of threat actors could potentially help them recover more quickly than isolated groups.

Social Engineering Masterclass: UNC3944’s Primary Attack Vector

The group’s most effective tactic involves sophisticated social engineering techniques that manipulate employees and IT staff.

UNC3944 conducts SMS phishing campaigns with messages claiming to be from IT departments, requesting users download software under the pretense that their machines are out of compliance.

They make phone calls to help desks, impersonating legitimate users to initiate password resets or MFA changes.

Security teams can detect these impersonation attempts using monitoring tools.

For example, Google SecOps provides this detection query for Microsoft Teams impersonation:-

metadata.vendor_name = "Microsoft"
metadata.product_name = "Office 365"
metadata.product_event_type = "ChatCreated"
security_result.detection_fields["ParticipantInfo"] = "true"
(
principal.user.userid = /help/ OR
principal.user.email_addresses = /help/ OR
about.user.user_display_name = /help/
)
UNC3944 attack lifecycle (Source – Google Cloud)

The group employs MFA fatigue attacks where they repeatedly send authentication prompts until users accept out of frustration.

They also leverage collaboration platforms like Microsoft Teams to pose as internal IT support personnel, creating convincing scenarios that lead victims to share credentials or approve authentication requests.

In some documented cases, attackers have even resorted to doxxing threats or aggressive language to intimidate users into compliance.

Security experts recommend organizations implement positive identity verification processes requiring on-camera verification, ID checks, or challenge/response questions before any security information changes.

Additionally, removing SMS and email as authentication factors in favor of phishing-resistant MFA and FIDO2 security keys can significantly reduce the risk of compromise from these increasingly prevalent social engineering attacks targeting both UK and US organizations.

How SOC Teams Save Time and Effort with ANY.RUN - Live webinar for SOC teams and managers

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago