How the Retail Industry Joins Forces Against Cybercrime: Industry Collaboration in the Wake of the Scattered Spider Attacks
Earlier this year, the Scattered Spider hacker group breached the networks of several major U.S. retailers and their suppliers, testing the low-key cybersecurity collaboration mechanisms within the retail industry. The Retail & Hospitality Information Sharing and Analysis Center (RH-ISAC) played a key role in coordinating the industry's response. Based on interviews with RH-ISAC Chief Security Officer Pam Lindemoen and others, this article analyzes how the industry addresses attacks targeting 'human weaknesses' through shared intelligence, strategies, and resources, and explores the challenges it faces and the progress it has made.

Earlier this year, a group of cunning young hackersbroke into the computer networks of several large U.S. retailers and their suppliers. The incident put to a major test the low-key cybersecurity collaboration between some of America's most recognizable brands and their numerous lesser-known partners.
At a time when life-and-safety-critical industries such as energy, water, and healthcare face increasingly alarming attacks, the cyber threats confronting the retail and hospitality sectors often receive far less attention. Yet retail is the largest private-sector employer in the United States, and its resilience is crucial to the American economy. Over the years,the Retail & Hospitality Information Sharing and Analysis Center(RH-ISAC) has played an increasingly important role in protecting retailers of all sizes, from household names to obscure but critical links in the supply chain.
Experts attribute the recent retail hacks to the cybercrime group Scattered Spider. Pam Lindemoen, Chief Security Officer and Vice President of Strategy at RH-ISAC, told Cybersecurity Dive that these incidents demonstrated how companies can unite to defend themselves and protect one another.
"The retail industry has leaned into collaboration, sharing intelligence, best practices, and response strategies," Lindemoen said.
The intrusions linked to Scattered Spider—a notorious and loosely organized groupcomprised mainly of teenagers and young adults in the U.S. and U.K.—struck several retail giants in May and June, includingVictoria's Secret, United Natural Foods, a distributor for Whole Foods, and department store chain Belk. As other retailers took note of these intrusions and tried to avoid becoming the hackers' next victim, RH-ISAC ramped up its support for its industry's security efforts.
"We played a key role in coordinating the response to this threat," Lindemoen said.
RH-ISAC was able to rely on allies across the Atlantic who had just dealt with their own Scattered Spider attacks, which proved helpful. Throughout April, hackers aligned with Scattered Spider breached department store chainHarrodsandMarks & Spenceras well as food retailerCo-op, prompting anurgent warning。
from U.K. authorities. Lindemoen said that shortly after these attacks, RH-ISAC organized a briefing for its members, featuring threat intelligence experts from Google's Mandiant division. The ISAC also coordinated with U.K. companies to better understand threat activity within the U.K., which prepared the organization for when hackers turned their attention to U.S. retailers.
Although Scattered Spider may be a group of young cybercriminals, it poses a serious threat. The group eschews traditional exploitation methods, relying heavily instead on social engineering techniques, such as tricking help desk workers into resetting account passwords. Because they sometimes gain deep access into target companies' networks, these hackers have even become known for secretly joining the virtual meetings companies convene in response to intrusions.
The group's tactics serve as a "stark reminder that even with advanced technical defenses, the human element can still be the weakest link," Lindemoen said. "Because they rely so heavily on social engineering to bypass security controls, it really underscores the need for us to focus on layered defenses."
A suite of cyber defense services
Promoting layered cyber defenses is one of RH-ISAC's primary missions. The organization was founded in 2014, in the wake ofa wave of cyberattacks against retailers such as Target. (At its inception, it had about 30 members; it now boasts over 290 "core members," including hotels, restaurants, retailers, and consumer goods manufacturers). The organization facilitates conversations among members about the threat activity they are seeing, but Lindemoen said itdoes far more thanhelp companies exchange indicators of compromise.
"Our members are actually sharing playbooks, response strategies, and lessons learned in real time," she said.
In July, RH-ISAC collaborated with ISACs from other industries topublish guidance on countering Scattered Spider. The report stated that the hacker group poses "a real threat" and "a significant risk to organizations."
The ISAC also partners withGoogle, Microsoft, Palo Alto Networks, and Akamai to provide ISAC members with access to these companies' services and expertise. Microsoft provided threat briefings and advice on integrating AI into security operations; Google offered in-person training and shared threat intelligence. Akamai hosted roundtable discussions on operational technology security and assisted in tracking cyber fraud activity; Palo Alto Networks helped company leaders improve how they report threats to their boards.
Last October, the ISAClaunched a programaimed at helping elevate the cybersecurity posture of its members' suppliers, reflecting deep concerns among retailers and hospitality companies about supply chain vulnerabilities.
Christian Beckner, Vice President of Retail Technology and Cybersecurity at the National Retail Federation, said RH-ISAC is "very effective," as evidenced by its "continued growth over the past few years." Beckner said the ISAC's increasing maturity was a "key factor" in NRF's decision topartner with the organizationon activities such as information sharing and anti-fraud resource development.
The ISAC is committed to "helping members learn from each other and collectively strengthen their defenses," Lindemoen said.
Like similar organizations in other industries, RH-ISAC's member companies compete fiercely in the marketplace. But Lindemoen said she is impressed by how companies can set aside business competition when hackers strike.
"In our industry, competitiveness goes away and collaboration comes in," she said. "I've literally received phone calls saying, 'I heard about this. Tell them I'm willing to help.' It's truly awe-inspiring to see that happen."
Securing the 'human element'
This collaboration is crucial for an industry that is particularly susceptible to cyberattacks due to its very nature.
Employees at RH-ISAC member companies—who serve as the first line of defense against criminals like Scattered Spider—are trained to be friendly, helpful, and trustworthy. But this corporate culture, which even employees who do not interact directly with customers or guests are expected to uphold, is precisely the environment where social engineering thrives. Hackers especially like to strike during thebusy holiday sales season, when overworked retail employees are more likely to let their guard down.
"If you think about who they are as an industry, they are hospitable people," Lindemoen said of her organization's members. "So, exploiting that is what makes attacks against this industry unique. They are taking advantage of people's kindness."
The challenge for cyber professionals focused on protecting retail and hospitality businesses is striking a balance between warmth and vigilance. "How do you educate your employees... to ask enough questions to ensure you're not being taken advantage of, while still remaining warm and welcoming?" Lindemoen said. "For me, that's a hard thing for our industry to get right when facing these threats that really attack the human nature of businesses."
RH-ISAC itself also faces challenges. As a voluntary information-sharing organization, it has limited influence over member companies' cybersecurity programs. It can encourage best practices but cannot enforce them. Some of its members may be less diligent than others in implementing its recommendations, which could lead to fragmentation in the industry's overall security posture.
The diversity of the ISAC's membership will also play a significant role in whether it can comprehensively help the industry.
According to the organization'slatest annual report, nearly 70% of RH-ISAC's core members have annual revenues of at least $1 billion, with 13% of members reporting revenues exceeding $20 billion. In ISACs disproportionately composed of the largest companies in an industry, smaller players can sometimes feel they have less influence over the organization's work, and smaller companies that are excluded have less access to cyber guidance. RH-ISAC is also dominated by retail companies (48% of core members), with lower representation from hospitality sectors such as hotels and casinos (18%) and restaurants (9%).
Particularly in complex industries like retail and hospitality, building a diverse membership base is essential to ensuring that the ISAC's work products reflect the variety of business considerations and security concerns that exist across the industry.
"The less regulated and more diverse an industry is, the harder it is to reach everyone," said Michael Daniel, President of the Cyber Threat Alliance, a network of information-sharing organizations. "Retail is almost uncountable. While the size of individual companies in the industry matters, the number of companies in the industry matters just as much."
Growing cyber resilience
Despite this,a recent RH-ISAC reportstill offers reasons for optimism. Nearly 20% of chief information security officers in the retail and hospitality industries now report directly to business executives, up 12 percentage points from last year. "We are being integrated into business decisions," Lindemoen said. "The CISO's influence in this space is growing."
Additionally, business continuity, a key consideration for cyber resilience, jumped to the top of the priority list for about half of respondents. Lindemoen welcomed the "increased attention and focus not just on preventing attacks, but also on recovering quickly from them," which "is critical in this industry."
Cyber defenders in the industry still face significant challenges—including budget constraints and the ongoing tension between speed and security—but RH-ISAC's leadership is pleased with how companies are responding to the growing threat.
"Even though you see all these high-profile attacks, they are showing resilience," Lindemoen said.