{"id":40712,"date":"2025-08-02T14:57:12","date_gmt":"2025-08-02T14:57:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/40712\/"},"modified":"2025-08-02T14:57:12","modified_gmt":"2025-08-02T14:57:12","slug":"do-not-reset-your-password-fbi-issues-critical-new-warning-2","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/40712\/","title":{"rendered":"Do Not Reset Your Password \u2014 FBI Issues Critical New Warning"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/www.newsbeep.com\/uk\/wp-content\/uploads\/2025\/08\/1754054230_221_960x0.jpg\" alt=\"Federal Bureau of Investigation (FBI) logo is seen displayed on a smartphone screen. \" data-height=\"1949\" data-width=\"2925\" style=\"position:absolute;top:0\"\/><\/p>\n<p>FBI updates Scattered Spider warning \u2014 do not reset your password.<\/p>\n<p>SOPA Images\/LightRocket via Getty Images<\/p>\n<p>Update, August 2, 2025: This story, originally published on July 31, has been updated with the latest news concerning the Scattered Spider involvement, or not, in recent ransomware attacks, as well as another warning from the FBI regarding a new cyberattack. Do not reset your passwords, the FBI said, and now has added advice not to get caught in a code-scanning hacker campaign.<\/p>\n<p><a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/05\/fbi-confirms-2fa-bypass-warning---now-stop-using-these-passwords\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/05\/fbi-confirms-2fa-bypass-warning---now-stop-using-these-passwords\/\" target=\"_self\" aria-label=\"Scattered Spider\" rel=\"nofollow noopener\">Scattered Spider<\/a> is the somewhat too cutesy name applied to one of the most dangerous threats facing organizations today. The ransomware threat actors, thought to behind devastating attacks on <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/30\/fbi-warning-issued-as-2fa-bypass-attacks-surge---act-now\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/06\/30\/fbi-warning-issued-as-2fa-bypass-attacks-surge---act-now\/\" target=\"_self\" aria-label=\"retail\" rel=\"nofollow noopener\">retail<\/a> and <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/04\/fbi-2fa-bypass-warning-issued---the-attacks-have-started\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/04\/fbi-2fa-bypass-warning-issued---the-attacks-have-started\/\" target=\"_self\" aria-label=\"aviation\" rel=\"nofollow noopener\">aviation<\/a> targets, among others, show no signs of going away. That said, it has now been reported that the group might not be the ones responsible for many of the attacks after all. More on that shortly, but for now, the Federal Bureau of Investigation and the Cybersecurity and Infrastructure Security Agency have now updated a joint cybersecurity advisory with a critical new warning: don\u2019t reset your passwords. Here\u2019s what you need to know about the latest FBI warning and the ongoing Scattered Spider threat, and that posed by other dangerous ransomware groups.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-6\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/02\/new-vpn-attack-warning---what-you-need-to-know\/\" target=\"_blank\" aria-label=\"New VPN Attack Warning \u2014 What You Need To Know\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/02\/new-vpn-attack-warning---what-you-need-to-know\/\">ForbesNew VPN Attack Warning \u2014 What You Need To KnowBy Davey Winder<\/a><\/p>\n<p>The FBI Password Reset Warning \u2014 Why It Makes Sense<\/p>\n<p>At first glance, being told not to reset your password in the face of an attack that compromises passwords appears somewhat counterintuitive, to say the least. After all, Google has been advising Gmail users to <a class=\"color-link\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/gmail-warns-25-billion-users---update-accounts-now-as-attacks-surge\/\" data-ga-track=\"InternalLink:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/gmail-warns-25-billion-users---update-accounts-now-as-attacks-surge\/\" target=\"_self\" aria-label=\"change their passwords\" rel=\"nofollow noopener\">change their passwords<\/a>, along with other cybersecurity warnings recommending the same, for the longest time now. But, as with most everything cyber, context is critical. Changing a password to prevent an attack, as in the advice to switch to a more secure technology such as passkeys, makes sense. Not using weak or previously compromised passwords, ditto. But this advice is different; it addresses the specific methodology employed by the Scattered Spider group in attacks.<\/p>\n<p>The July 29 update to the FBI and CISA cybersecurity advisory, <a class=\"color-link\" href=\"https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-320a\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-320a\" aria-label=\"alert code AA23-320A\">alert code AA23-320A<\/a>, warns that Scattered Spider has \u201cposed as employees to convince IT and\/or helpdesk staff to provide sensitive information, reset the employee\u2019s password, and transfer the employee\u2019s MFA to a device they control on separate devices.\u201d<\/p>\n<p>Scattered Spider is using \u201clayered social engineering techniques,\u201d the FBI warned, often comprising multiple calls and contacts. These are made to ascertain the steps required to conduct password reset requests from support staff. \u201cOnce that information is identified,\u201d the FBI said, \u201cthe threat actors continue to conduct phone calls to employees and help desks to gather password reset-specific information of a targeted employee.\u201d This all culminates in a highly-targeted spearphishing call to the help desk in question to convince staff to \u201creset passwords and\/or transfer MFA tokens.\u201d<\/p>\n<p>The FBI recommended that organizations use phishing-resistant multifactor authentication for all services and accounts that access critical systems. \u201cOrganizations should continue to perform diligent employee training against vishing and spearphishing,\u201d the alert said, and advised that <a class=\"color-link\" href=\"https:\/\/www.ncsc.gov.uk\/blog-post\/incidents-impacting-retailers\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.ncsc.gov.uk\/blog-post\/incidents-impacting-retailers\" aria-label=\"updated mitigation recommendations\">updated mitigation recommendations<\/a> from the U.K. National Cyber Security Centre be followed, including to \u201creview helpdesk password reset processes, including how the helpdesk authenticates staff members credentials before resetting passwords, especially those with escalated privileges.\u201d<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-7\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/02\/google-issues-3-gmail-security-warnings---fast-action-needed\/\" target=\"_blank\" aria-label=\"Google Issues 3 Gmail Security Warnings \u2014 Fast Action Needed\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/08\/02\/google-issues-3-gmail-security-warnings---fast-action-needed\/\">ForbesGoogle Issues 3 Gmail Security Warnings \u2014 Fast Action NeededBy Davey Winder<\/a><\/p>\n<p>Following The FBI Warning, Doubts Cast On Scattered Spider Involvement In Recent Ransomware Attacks<\/p>\n<p>The shockwave, and that\u2019s the correct term I think, of ransomware attacks this year attributed to the Scattered Spider group specifically, and more broadly a criminal collective, consisting mainly of teenagers, called The Com, might have been carried out by a different threat actor entirely. That group is known as ShinyHunters, an extortion gang that is also thought to be behind the recently confirmed data breach at insurance company Allianz Life. The confusion is unsurprising, not least as ShinyHunters appear to use the same tactical playbook as Scattered Spider. A number of security specialists have now pointed the finger at ShinyHunters for attacks involving Quantas, LVMH and Adidas, to name but a few.<\/p>\n<p>\u201cThis new update will mitigate any confusion that has been circulating over the last few months around which attacks can be attributed to Scattered Spider,\u201d Juliette Hudson, chief technical officer at CybaVerse, said. There has also been plenty of speculation that both the Scattered Spider and ShinyHunters criminal groups share members, which is more commonplace in such ransomware circles than you might imagine, especially when taking associates into account. The latest intelligence suggests, Hudson said, adds further weight to the theory and \u201chighlights how threat actors collaborate, work together and share tactics, techniques and procedures to support each other.\u201d<\/p>\n<p>This only goes to support the FBI warning and mitigation advice, though, bringing &#8220;vishing,&#8221; more formally known as voice-based phishing, into the picture front and center.<\/p>\n<p>\u201cConsidering these calls then direct victims to a spoofed domain to enter their login details,\u201d Hudson concluded, \u201cthis will undoubtedly trick a large volume of people. It\u2019s likely the spoofed domain will have been created using AI, so it will be highly realistic.\u201d So, please do not ignore the FBI warning, apply the mitigations it has suggested, and protect yourself from threats posed by Scattered Spider, ShinyHunters or any of the other myriad cybercriminal groups out there.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-8\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/31\/hackers-threaten-to-publish-35-tb-of-stolen-data-in-24-hours\/\" target=\"_blank\" aria-label=\"Hackers Threaten To Publish 3.5 TB Of Stolen Data Today\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/31\/hackers-threaten-to-publish-35-tb-of-stolen-data-in-24-hours\/\">ForbesHackers Threaten To Publish 3.5 TB Of Stolen Data TodayBy Davey Winder<\/a><br \/>\nDo Not Scan These Codes \u2014 The FBI Has Warned<\/p>\n<p>Critical FBI cybersecurity warnings are starting to be a little like London buses: you wait a while, and then a whole bunch turn up at once. Just days after the FBI issued the Scattered Spider cybersecurity alert update, the Bureau has now published <a class=\"color-link\" href=\"https:\/\/www.ic3.gov\/PSA\/2025\/PSA250731\" target=\"_blank\" rel=\"nofollow noopener noreferrer\" data-ga-track=\"ExternalLink:https:\/\/www.ic3.gov\/PSA\/2025\/PSA250731\" aria-label=\"alert number I-073125-PSA\">alert number I-073125-PSA<\/a> warning the public of a new twist to an old threat: the brushing scam.<\/p>\n<p>Brushing scams involve vendors fraudulently increasing their product ratings online by sending unsolicited items to unsuspecting recipients and using their information to post positive reviews. This latest scam, the FBI has warned, operates along a similar theme but is now using QR codes on such packages as a means to facilitate financial fraud.<\/p>\n<p>The packages contain a QR code that \u201cprompts the recipient to provide personal and financial information or unwittingly download malicious software that steals data from their phone,\u201d the FBI said. Such parcels are often sent without any information as to their origin as a means to encourage recipients to scan the malicious code.<\/p>\n<p>If you receive an unexpected package from an unknown sender, the FBI advises that you should not scan any QR codes contained within it or on the packaging itself. The FBI requests that the public report these fraudulent or suspicious activities to the FBI IC3 at www.ic3.gov.<\/p>\n<p><a class=\"embed-base color-body color-body-border link-embed embed-5\" href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/141-million-file-data-breach-reveals-bank-statements-and-crypto-keys\/\" target=\"_blank\" aria-label=\"141 Million Data Breach Files Reveal Bank Statements And Crypto Keys\" rel=\"noopener noreferrer nofollow\" data-ga-track=\"forbesEmbedly:https:\/\/www.forbes.com\/sites\/daveywinder\/2025\/07\/30\/141-million-file-data-breach-reveals-bank-statements-and-crypto-keys\/\">Forbes141 Million Data Breach Files Reveal Bank Statements And Crypto KeysBy Davey Winder<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"FBI updates Scattered Spider warning \u2014 do not reset your password. SOPA Images\/LightRocket via Getty Images Update, August&hellip;\n","protected":false},"author":2,"featured_media":38182,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[84,16219,22219,22217,22220,22215,22218,22216,59,11181,2477,56,54,55],"class_list":{"0":"post-40712","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-business","8":"tag-business","9":"tag-cisa","10":"tag-cisa-warning","11":"tag-fbi-advice","12":"tag-fbi-cybersecurity-advisory","13":"tag-fbi-password","14":"tag-fbi-password-warning","15":"tag-fby-cybersecurity-warning","16":"tag-gb","17":"tag-ransomware","18":"tag-scattered-spider","19":"tag-uk","20":"tag-united-kingdom","21":"tag-unitedkingdom"},"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/40712","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=40712"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/40712\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/38182"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=40712"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=40712"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=40712"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}