TL;DR: Aflac confirmed on December 23, 2025 that a June 2025 cyberattack tied to the Scattered Spider campaign exposed personal and health data of 22.65 million people, joining a documented wave of help-desk vishing attacks on insurance, retail, and aviation through 2025 and 2026. Per CrowdStrike's 2026 services telemetry, the group used help-desk voice-based phishing in nearly every observed 2025 incident to compromise Microsoft Entra ID, SSO, and VDI accounts. The single highest-yield control for any NC SMB - especially insurance brokers, RIAs, healthcare offices, and law firms - is a written help-desk identity verification policy paired with phishing-resistant MFA.
Key takeaway: The Aflac breach was not a missing patch. It was a phone call to a help desk that ended with an attacker getting an account back. The control that prevents it is a one-page policy, not a six-figure tool.
Need a Scattered Spider-grade help-desk policy and phishing-resistant MFA? Preferred Data Corporation runs managed cybersecurity and identity hardening for NC small businesses. Call (336) 886-3282 or request a help-desk security assessment.
Who is Scattered Spider and why does it matter to a North Carolina SMB?
Scattered Spider (also tracked as UNC3944, Octo Tempest, and 0ktapus) is a financially motivated cybercrime group that specializes in social engineering to obtain initial access. Per the Wikipedia incident summary and CISA's joint advisory AA23-320A, the group's signature is a phone call to a corporate help desk in which an attacker impersonates a legitimate employee, supplies enough public information to pass identity verification, and asks for an MFA reset or password reset.
In 2025 and 2026, that pattern was used against:
- Insurance giants including Aflac, Erie Indemnity, and Philadelphia Insurance, with Aflac confirming 22.65 million affected individuals in its December 2025 notification.
- Retail chains in the UK and US in 2025 per the Record's coverage.
- Aviation operators per CrowdStrike's 2026 services blog, expanding the target set beyond financial services.
For a North Carolina SMB, the relevance is direct. Any company that runs Microsoft 365 or Google Workspace, federates identity through Okta or Entra ID, and operates a help desk - whether it is two people in an MSP queue or one office manager who handles password resets - is in the addressable target set.
How does a Scattered Spider attack actually unfold in an SMB?
The attack chain compresses to four steps and usually runs in under a business day. Per HYPR's analysis of insurance-sector incidents and ProArch's defense breakdown:
| Step | Tactic | What the attacker says or does |
|---|---|---|
| 1. Recon | OSINT on LinkedIn, company directory, breach data | Builds a target list of finance, IT admin, and exec accounts |
| 2. Help-desk call | Voice impersonation, often AI-cloned | "Hi, this is [CFO]. I lost my phone. Can you reset my MFA?" |
| 3. MFA reset | Help desk re-enrolls attacker device | Attacker now holds the second factor |
| 4. SSO pivot | Authenticate to Entra ID / Okta / VDI | Email, files, payroll, and crown-jewel apps follow |
The Aflac incident pattern is widely reported as following this exact playbook with insurance carrier help desks. Aflac stated in its disclosure that it cut off unauthorized access within hours, but the threat actor had already exfiltrated documents containing claims data, Social Security numbers, and medical information.
Why are insurance brokers and financial SMBs in NC at elevated risk?
Three structural reasons. Per Datos Insights' analysis of the insurance sector, WWT's industry briefing, and Perforce's data-masking guidance:
- Legacy systems from decades of M&A mean help desks support apps that pre-date modern identity controls and rely on knowledge-based authentication (last four of SSN, mother's maiden name, agent code).
- Data crown jewels are universally valuable. A small NC insurance broker holds PII, PHI, and policy data for every client. Per the Verizon DBIR 2026 industry trends, financial services and insurance remain top targets for both data theft and ransomware.
- Help desks are under-trained. Per the Acrisure 2026 SMB cyber threat brief, only 58% of SMBs offer cybersecurity training, and almost none specifically train help-desk staff on voice impersonation scenarios.
The same dynamic applies to NC registered investment advisers (now under SEC Reg S-P's June 3, 2026 breach notification deadline), law firms, healthcare practices, and any benefits administrator.
What does an SMB help-desk identity verification policy look like?
A one-page policy with four required controls. None of these are theoretical; each is enforceable in the next 30 days for any NC SMB:
- Out-of-band callback for every credential reset. Any password reset, MFA reset, hardware-token re-enrollment, or VPN re-auth must be confirmed by calling the requester back at the number stored in the directory, never the number that initiated the request.
- Video verification for Tier 0 accounts. Executive, finance, IT admin, HR, and primary owner accounts require a live video call with the help desk before any credential reset, with the camera on. AI voice clones do not yet defeat camera-on video at the SMB scale.
- Manager approval for high-risk resets. Resets for finance, payroll, or wire-authorized roles require a documented approval from the named manager, not just a text or chat reply.
- Zero-tolerance pretext keywords. Any inbound caller who pressures urgency ("the deal closes today", "I am in a board meeting", "the auditor is waiting") triggers an immediate callback, no exceptions.
Quotable definition: Help-desk vishing is voice-based social engineering in which an attacker impersonates a legitimate user to trick a support agent into resetting authentication factors. It is the dominant initial-access vector for Scattered Spider and a growing class of SMB-scale copycats.
Is MFA enough to stop Scattered Spider?
Not by itself, and not the kind of MFA most SMBs deploy. Per CrowdStrike's services data, the group's standard play is to bypass MFA by convincing the help desk to re-enroll a new device. Conventional MFA (SMS one-time code, push prompt, authenticator-app code) does not block this path because the attacker is enrolling fresh.
The defense is layered:
- Phishing-resistant MFA on Tier 0/1. FIDO2 keys or platform passkeys with attestation, so a re-enrollment requires a physical token in addition to identity proof.
- Conditional access on identity provider. Block new device enrollment outside a defined window, require manager approval for high-risk roles, and alert on Entra ID / Okta admin role assignment.
- Detection on identity events. Stream Entra ID / Okta sign-in and audit logs to an MDR or SIEM, with rules for impossible travel, new-device enrollment on privileged roles, and MFA method changes.
Three numbers frame the urgency. Per Verizon's 2026 DBIR coverage, the human element is involved in 62% of all breaches; per Microsoft's 2026 Digital Defense Report coverage, median time from credential capture to lateral movement is under 30 minutes; and per BlackFog's Q1 2026 ransomware report, 96% of ransomware incidents now involve data exfiltration, meaning a single help-desk failure increasingly translates to a public disclosure event.
Does cyber insurance cover Scattered Spider losses?
Increasingly only if the documented controls were in place at the time of the incident. Per the 2026 cyber insurance environment for SMBs, most carriers' 2026 questionnaires ask about:
- Phishing-resistant MFA on privileged accounts.
- Help-desk identity verification policy with out-of-band callback.
- Identity provider logging into a 24x7 monitored SIEM or MDR.
- Endpoint detection and response (EDR) on all servers and admin workstations.
An NC SMB that cannot answer "yes" on those controls is increasingly likely to see exclusions or sub-limits on the social engineering rider, and may face premium spikes at renewal. Per Acrisure's 2026 brief, only 17% of US small businesses have cyber insurance at all, and premiums are forecast to rise 15-20% in 2026.
What does a 30-day NC SMB rollout look like?
Sequence the controls so the highest-yield protections land first. PDC scopes this as a single sprint inside the managed cybersecurity service:
| Week | Action | Outcome |
|---|---|---|
| 1 | Issue FIDO2 keys / enroll passkeys for exec, finance, IT, HR, primary owner | Tier 0 accounts can no longer be MFA-bypassed via help desk re-enrollment |
| 2 | Write and circulate help-desk identity verification policy | Callback, video, manager approval required for every credential reset |
| 3 | Stream Entra ID / Okta sign-in + audit logs to MDR/SIEM | New device enrollment, MFA method change, and admin role grants alert in minutes |
| 4 | Quarterly help-desk vishing simulation (live phone, AI voice) | Help desk resilience measurable; gaps trained before the real call |
Key takeaway: The Aflac incident shows that an attacker with a phone, a LinkedIn profile, and a believable backstory can extract enterprise-scale data from a Fortune 500 in hours. A 25-person NC insurance broker faces the same playbook with fewer defenders. The one-page policy is the gate.
Ready to harden your help desk against Scattered Spider tactics? Call (336) 886-3282 or request a Scattered Spider readiness review.
How does Preferred Data Corporation help?
PDC supports NC small businesses with the three layers required to close the help-desk attack path:
- Managed cybersecurity with 24x7 monitoring of Entra ID, Okta, and VPN sign-in events; phishing-resistant MFA deployment; and incident response retainer that treats identity-provider compromise as a Tier 1 event.
- Managed IT services with help-desk policy authoring, identity verification training, and AI voice-clone simulation in quarterly exercises.
- Network services for conditional access, device compliance, and zero-trust segmentation so that an SSO compromise does not translate into domain-wide data exfiltration.
PDC has served NC small businesses, manufacturers, distributors, and professional service firms for over 37 years with on-site coverage within 200 miles of High Point. The combination of local NC presence, 20+ year average client retention, and identity-provider-grade tooling is what gets help-desk hardening deployed and verified in 30 days, not 30 weeks.
Frequently Asked Questions
What was the Aflac breach and how big was the impact?
Aflac confirmed on December 23, 2025 that a June 2025 cyberattack exposed personal data of approximately 22.65 million customers, beneficiaries, employees, and agents. Stolen data includes names, dates of birth, addresses, Social Security numbers, driver's license numbers, and medical and health insurance information. Per TechCrunch's reporting, the incident is tied to a wider campaign of attacks against the insurance industry attributed to Scattered Spider.
Who is Scattered Spider and how do they get in?
Scattered Spider is a financially motivated cybercrime collective that specializes in social engineering. Per the CISA joint advisory and CrowdStrike's 2026 services telemetry, the group's primary initial access vector is a voice call to a corporate help desk in which they impersonate a legitimate employee and request an MFA or password reset.
Will phishing-resistant MFA alone stop a help-desk attack?
No. Phishing-resistant MFA (FIDO2, passkeys) defeats the phishing kit, but the help-desk re-enrollment path bypasses MFA entirely if the help desk can be convinced to enroll a new device. The policy layer (callback, video verification, manager approval) is what closes that path. Both controls together are what is required.
How much does this defense cost for a 25-person NC SMB?
For a 25-person NC SMB, expect $1,200-$3,000 in FIDO2 keys plus 2-4 weeks of managed services time for policy authoring, identity provider tuning, and help-desk training. PDC scopes this as a 30-day sprint inside the managed cybersecurity service.
What if my SMB outsources the help desk to an MSP?
The policy still applies. The MSP becomes the gate, and the MSP's help-desk policy must be aligned to your identity verification standard. Many SMBs do not realize that "we use an MSP" is not a defense without a documented MSP help-desk policy that includes callback, video, and manager approval for credential resets.
Related Resources
- Managed Cybersecurity Services for NC Businesses - 24x7 monitoring, identity provider hardening, MDR
- Managed IT Services for NC Businesses - Help-desk policy, training, MFA rollout
- SEC Reg S-P June 2026 Deadline for NC RIA / Broker-Dealer - Breach notification rules
- Smishing & Vishing 40% Higher Success Rate: NC SMB Defense 2026 - Companion mobile-channel guide
- AI Voice Cloning CFO Fraud Defense - AI voice-clone defense
- Contact Preferred Data Corporation - Schedule a help-desk security sprint