Threat actors such as Punk Spider, the group behind Akira ransomware, have significantly increased their activity and are targeting SMBs, according to CrowdStrike’s Justin Bradley.
Prolific cybercrime groups represent a growing threat facing MSPs and their customers, with major attackers specifically targeting the SMBs served by IT service providers, CrowdStrike’s Justin Bradley told MSP executives Tuesday.
During a session at XChange August 2026, Bradley said that nearly “everybody that I end up talking about here is specifically attacking MSPs and your SMB customers.”
As one major example, the group behind Akira ransomware—referred to as Punk Spider by CrowdStrike—has significantly boosted its activity with an emphasis on targeting SMBs, he said.
Over the past year, in fact, Punk Spider has increased its attacks by 134 percent senior alliances manager for MSSP aggregators at CrowdStrike
“When it comes to MSPs, this is the biggest attacker of your customers,” he said during the session at XChange August 2026, which was hosted by CRN parent The Channel Company and held this week in National Harbor, Md.
Bradley said he’s been alerted to numerous Punk Spider attacks involving MSPs during the past year—more than 10 in total—
In all of those cases, the attacker had passed through the first step of an intrusion by managing to overcome MFA (multifactor authentication) and had begun to move laterally within the victim’s environment, he said.
Punk Spider’s go-to strategy is to start by trying to buy VPN credentials on the dark web, Bradley said.
To thwart any resulting MFA challenges, he said, the group’s attackers will repeatedly trigger MFA requests until a user approves it—simply to make the notifications stop—a tactic known as MFA fatigue.
“Once they get in there, then they escalate their privileges. They move laterally to find all of the Entra IDs. They dump them all out. And then of course they do an Akira ransomware deployment,” Bradley said.
Thus, in addition to the ransomware itself, “now they’ve stolen all your IDs. They’re already selling them online,” he said—noting that a legitimate credential for a midsize credential can now fetch thousands of dollars on the dark web.
Partner Perspective
Without a doubt, getting an in-depth look at individual threat groups such as Punk Spider is highly valuable for MSPs—since it goes beyond the broad, general warnings MSPs and their customers hear on a daily basis, said Michael Pfaff, director of operations at Richmond, Va.-based Network Data Security Experts.
“We are hearing ‘threat’ all the time,” Pfaff said. “This brings it to life.”
Understanding the workings of a threat group can also help MSPs put together a stronger security strategy for protecting their customers and bolster the MSP’s discussions with prospects, he said.
Tapping into current threat information such as this “could give us more of a value-add when we’re talking to our prospects and talking to our customers,” Pfaff said.
Ultimately, “a trusted adviser needs to be knowledgeable about the threat, but also the history,” he said. “‘Where did it come from? What else are these people doing that we don’t know about?’ Business owners want to know that.”
‘Keys To The Castle’
Scattered Spider is another major e-crime group that has been known for having a particular interest in targeting MSP customers, often using social engineering tactics, Bradley said.
Scattered Spider has operated as a large, loosely connected community with more than 1,000 members, many of them young people, he noted. The group was behind the hugely disruptive 2023 attack against casino operator MGM, as well as the 2024 attack against Transport for London.
While law enforcement actions have disrupted the group’s ability to operate as a coherent outfit, CrowdStrike is now tracking two break-off groups, dubbed Cordial Spider and Snarky Spider, Bradley said.
One tactic favored by Scattered Spider has been to impersonate an MSP while reaching out to a customer of the service provider, he said.
In one scenario, an attacker first floods a user’s inbox with spam, then calls the user—posing as a technician at the MSP—with an offer to fix the issue, Bradley said. The goal is to convince the user to launch a remote monitoring and management tool, making it possible for the attacker to gain access.
The reality is that “they love to go after MSPs,” Bradley said. “You guys hold the keys to the castle.”
