ShinyHunters and Scattered Spider Collaboration
Summary
Hide ▲
Show ▼
The **ShinyHunters and Scattered Spider collaboration**, operating under the **Scattered Lapsus$ Hunters (SLH) alliance**, has escalated its extortion and social engineering tactics in **early 2026** by **recruiting women for vishing attacks** targeting IT help desks, offering **$500–$1,000 per successful call** alongside pre-written scripts. This calculated evolution aims to exploit psychological biases and bypass traditional attacker profiles, increasing the success rate of impersonation and credential harvesting. The group continues to combine **technical intrusions** with **psychological harassment, swatting, and media manipulation** to coerce payments, while leveraging **legitimate services, residential proxies, and tunneling tools** (e.g., Ngrok, Luminati) to evade detection. The alliance’s latest developments include the **ShinySp1d3r RaaS platform**, **Zendesk phishing campaigns**, and **targeted intrusions against financial sectors**, demonstrating a **multi-pronged expansion** in both **technical sophistication** and **psychological warfare**. Their tactics now involve **recruiting diverse social engineering operatives**, deploying **virtual machines for post-exploitation reconnaissance**, and exploiting **cloud APIs (e.g., Microsoft Graph)** to access Azure environments. Despite law enforcement arrests and shutdown claims, SLH remains a **high-risk, low-trust threat actor**, with **no guarantee of data deletion** post-payment and a pattern of **rebranding to evade pressure**. Victims are advised to **refuse engagement** beyond a firm "no payment" stance, as compliance only fuels further escalation and harassment.
Timeline
-
31.01.2026 09:58 3 articles · 26d ago
ShinyHunters Expands Vishing and SaaS Extortion Tactics in January 2026
In **January 2026**, Mandiant and **Allison Nixon (Unit 221B)** documented a **new wave of vishing and credential-harvesting attacks** by **ShinyHunters and associated clusters (UNC6661, UNC6671, UNC6240)**, targeting **SaaS platforms** (Okta, SharePoint, OneDrive) and **cryptocurrency firms** for extortion. Attackers **impersonated IT staff**, directing employees to **fake credential-harvesting sites** to steal **SSO credentials and MFA codes**, then **registered their own MFA devices** to maintain persistent access. UNC6661 sent phishing emails from compromised accounts, deleting them post-delivery to evade detection, while UNC6671 used **PowerShell scripts** to exfiltrate data from SharePoint/OneDrive after gaining access via **victim-branded harvesting pages**. The groups differ in **domain registrars (NICENIC for UNC6661, Tucows for UNC6671)** and extortion email patterns, suggesting **multiple but interlinked threat actors**. **New insights from Unit 221B** reveal SLSH’s extortion model **mirrors violent sextortion schemes**, where victims are **harassed via swatting, DDoS, and threats of physical violence**—including against **executives’ families**—while the group **manipulates media coverage** to amplify pressure. Nixon warns that **negotiation incentivizes further harassment** and provides SLSH with intelligence on data value for future fraud, advising victims to **refuse payment** and treat extortion demands as a **separate issue from harassment**. The campaign highlights the group’s **escalation from technical intrusion to psychological coercion**, with **no guarantee of data deletion** post-payment. Google’s mitigation recommendations—**phishing-resistant MFA (FIDO2/passkeys), egress restrictions, and help desk verification reforms**—remain critical as SLSH continues to **exploit SaaS vulnerabilities** and **third-party trust relationships**. **February 2026 Update:** SLH is now **recruiting women for vishing attacks**, offering **$500–$1,000 per call** to IT help desks, alongside pre-written scripts. This tactical shift aims to **bypass traditional attacker profiles** by diversifying voices, increasing impersonation success rates. The group also **creates virtual machines post-access** for reconnaissance (e.g., Active Directory enumeration) and **exploits the Microsoft Graph API** to target Azure cloud resources, demonstrating a **deepening focus on identity and cloud infrastructure weaknesses**.
Show sources
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
15.12.2025 23:27 2 articles · 2mo ago
ShinyHunters Extorts PornHub via Mixpanel Analytics Breach
On **November 8, 2025**, ShinyHunters compromised **Mixpanel**, a third-party analytics vendor, via an **SMS phishing (smishing) attack**, stealing **94GB of data** containing **201,211,943 records** of **PornHub Premium members’ historical search, watch, and download activity** from 2021 or earlier. The stolen data includes **email addresses, activity types (watched, downloaded, searched), video URLs, video names, associated keywords, locations, and timestamps**—highly sensitive information the group is now using to **extort Mixpanel customers**, including PornHub. ShinyHunters sent extortion emails beginning with **"We are ShinyHunters"**, demanding ransom payments to prevent public disclosure of the data. PornHub confirmed the breach impacted **select Premium users** but clarified that **no passwords, payment details, or financial information were exposed**, as the compromise originated from Mixpanel’s systems. **Mixpanel disputed the claim**, stating the data was last accessed by a legitimate PornHub employee account in 2023 and that there is **no evidence it was stolen during their November 2025 security incident**. This discrepancy raises questions about the data's origin, including potential **earlier breaches or insider involvement**. The incident marks a **significant expansion of ShinyHunters’ targeting**, moving beyond **Salesforce and CRM platforms** to exploit **analytics vendors** and **consumer-facing services**, further demonstrating the group's ability to **leverage third-party providers for high-impact extortion campaigns**.
Show sources
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
-
27.11.2025 11:30 1 articles · 3mo ago
Scattered Lapsus$ Hunters Launches Zendesk Phishing Campaign
The **Scattered Lapsus$ Hunters (SLSH) alliance** has initiated a **new phishing campaign targeting Zendesk users**, deploying **over 40 typosquatted domains** (e.g., *znedesk[.]com*, *vpn-zendesk[.]com*) and **fraudulent helpdesk tickets** to harvest credentials and deploy **remote access trojans (RATs)**. The domains, registered via **NiceNic** with **US/UK registrant details** and **Cloudflare-masked nameservers**, mirror tactics used in the **August 2025 Salesforce campaign**, including **deceptive SSO portals** and **social engineering lures** aimed at support staff. ReliaQuest reports that **Discord** has already fallen victim, confirming a breach via its **Zendesk-based support system** that exposed user data, including **names, emails, billing information, IP addresses, and government-issued IDs**. The campaign underscores the group’s **expanding focus on high-value SaaS platforms** (Salesforce, Salesloft, Gainsight, and now Zendesk) to exploit **downstream customer data access**. While the activity aligns with SLSH’s modus operandi, ReliaQuest notes it could also be the work of a **copycat group** adopting similar phishing and credential-harvesting techniques. Organizations are urged to **monitor for typosquatted domains**, **audit helpdesk ticket submissions**, and **enhance endpoint protections** for support teams. This development follows the group’s **November 2025 unveiling of the ShinySp1d3r RaaS platform**, signaling a **multi-pronged escalation** in both **technical sophistication** and **target diversification**.
Show sources
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
-
27.11.2025 09:03 1 articles · 3mo ago
ShinyHunters-Scattered Spider-LAPSUS$ Alliance Unveils ShinySp1d3r RaaS Platform
The **ShinyHunters-Scattered Spider-LAPSUS$ (SLSH) alliance** has developed **ShinySp1d3r**, a new **ransomware-as-a-service (RaaS) platform** combining advanced technical features with extortion-as-a-service (EaaS) capabilities. The platform includes **anti-forensic measures** such as hooking the *EtwEventWrite* function to disable Windows Event Viewer logging, terminating processes to bypass file locks, and filling free drive space with random data to overwrite deleted files. ShinySp1d3r also supports **network propagation** via *deployViaSCM*, *deployViaWMI*, and *attemptGPODeployment* to encrypt open network shares and spread laterally. The platform is administered by **Saif Al-Din Khader (aka Rey)**, a core SLSH member and former BreachForums/HellCat ransomware administrator, who claims to have **cooperated with law enforcement since June 2025**. Rey describes ShinySp1d3r as a **rehashed version of HellCat ransomware modified with AI tools**. The SLSH alliance has been linked to **51 cyberattacks in the past year**, leveraging **insider recruitment, RaaS/EaaS hybrid models, and multi-vector monetization** to target organizations. Palo Alto Networks Unit 42 warns that the group’s **combined offerings and tactical adaptability** pose a formidable threat, particularly to **Salesforce-dependent enterprises and third-party IT providers**.
Show sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
-
26.11.2025 14:05 3 articles · 3mo ago
Gainsight Attack Expands Salesforce Customer Impact with New IOCs
The **Gainsight cyber-attack** has expanded significantly, with Salesforce initially identifying **three impacted customers** but later confirming a **larger, unspecified number of victims** by **November 21, 2025**. Gainsight CEO Chuck Ganapathi stated only a "handful" of customers had their data affected, though the full scope remains undisclosed. The breach began with **reconnaissance from IP 3.239.45[.]43 on October 23, 2025**, followed by **unauthorized access via an AT&T IP address on November 8** and approximately **20 suspicious intrusions between November 16–23** using **commercial VPNs (Mullvad, Surfshark)** and the **Salesforce-Multi-Org-Fetcher/1.0 technique**—a tactic linked to the **Salesloft Drift attack**. Salesforce **revoked all access and refresh tokens** for Gainsight applications, while **Google disabled OAuth clients** with callback URIs like *gainsightcloud[.]com*. Gainsight disabled read/write capabilities for **Customer Success (CS), Community (CC), Northpass, and Skilljar**, while isolating **Staircase** (confirmed unaffected). Third parties (**Gong.io, Zendesk, HubSpot**) severed integrations as a precaution, with HubSpot explicitly stating no evidence of compromise. Forensic analysis by **Mandiant** and Salesforce revealed attackers exploited **compromised multifactor credentials** for VPN and critical system access. Customers were advised to **rotate S3 keys, reset NXT passwords, and re-authorize integrations**, while adopting **Google Threat Intelligence Group (GTIG) mitigations** to counter the **ShinyHunters-Scattered Spider-LAPSUS$ collective’s evolving tactics**. The incident underscores the group’s persistent focus on **Salesforce ecosystems**, leveraging **third-party app vulnerabilities, OAuth token abuse, and VPN obfuscation** to maximize impact. **Meanwhile, the SLSH alliance has extended its targeting to Zendesk users**, deploying **typosquatted domains and malicious helpdesk tickets** to harvest credentials and deploy malware, as detailed in a concurrent campaign reported on **November 27, 2025**.
Show sources
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
-
20.11.2025 20:54 1 articles · 3mo ago
Almaviva Breach Exposes 2.3TB of FS Italiane Group Data
A threat actor breached **Almaviva**, the IT services provider for **FS Italiane Group (Italy’s national railway operator)**, stealing **2.3TB of data** and leaking it on a dark web forum. The compromised files include **internal shares, multi-company repositories, technical documentation, contracts with public entities, HR archives, accounting data, and complete datasets from FS Group companies**, with evidence confirming the data is recent (Q3 2025). Almaviva publicly acknowledged the breach, stating its **security monitoring services detected and isolated the attack**, activated counter-response procedures, and ensured the protection of critical services. The company notified Italian authorities, including the **police, national cybersecurity agency (ACN), and data protection authority (Garante)**, and is conducting an investigation with government support. The **structure of the leaked data**—organized into compressed archives by department/company—mirrors the tactics of **ransomware groups and data brokers active in 2024–2025**, though no specific group has claimed responsibility. Almaviva, a global IT provider with **41,000+ employees and $1.4B in annual revenue**, serves FS Italiane Group, a **100% state-owned railway operator** with **$18B+ in annual revenue**, managing railway infrastructure, passenger/freight transport, and logistics chains. As of November 20, 2025, it remains unclear whether **passenger information was exposed** or if other Almaviva clients beyond FS Italiane Group were impacted. The breach underscores the **growing risk to critical infrastructure via third-party IT providers**, a tactic increasingly used by groups like **ShinyHunters and Scattered Spider**.
Show sources
- Hacker claims to steal 2.3TB data from Italian rail group, Almavia — www.bleepingcomputer.com — 20.11.2025 20:54
-
25.09.2025 14:48 2 articles · 5mo ago
Scattered Spider Members Arrested in September 2025
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
25.09.2025 14:48 2 articles · 5mo ago
Noah Urban Sentenced for SIM-Swapping and Cybercrime Activities
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
25.09.2025 14:48 2 articles · 5mo ago
Ransomware Attack Disrupts European Airports
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
24.09.2025 23:21 3 articles · 5mo ago
Scattered Spider Member Surrenders in Las Vegas
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
18.09.2025 17:37 4 articles · 5mo ago
UK Arrests Scattered Spider Members Linked to Transport for London Hack
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
15.09.2025 23:12 5 articles · 5mo ago
Scattered Lapsus$ Hunters' Claims and Google's Response
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
13.09.2025 12:04 6 articles · 5mo ago
FBI Alert on UNC6040 and UNC6395 Targeting Salesforce Platforms
The **Gainsight cyber-attack** has expanded to impact more Salesforce customers than initially disclosed, with notifications sent to all affected parties by **November 21, 2025**. The breach began with **unauthorized access via an AT&T IP address on November 8**, followed by approximately **20 suspicious intrusions** between November 16–23 using **commercial VPN services (Mullvad, Surfshark)** and the **Salesforce-Multi-Org-Fetcher/1.0 technique**—a method previously observed in the **Salesloft Drift attack**. Gainsight temporarily disabled read/write capabilities for products like **Customer Success (CS), Community (CC), and Northpass**, while isolating **Staircase** (confirmed unaffected due to separate infrastructure). Third-party vendors, including **Gong.io, Zendesk, and HubSpot**, also disabled Gainsight integrations as a precaution, though HubSpot reported no evidence of compromise. Forensic investigations by **Mandiant (Google Cloud’s incident response team)** and Salesforce revealed the attackers leveraged **compromised multifactor credentials** for VPN and critical system access. Gainsight advised customers to **rotate S3 keys, reset NXT passwords, and re-authorize integrations**, while recommending mitigation measures from the **Google Threat Intelligence Group (GTIG)** to counter the **ShinyHunters-Scattered Spider-LAPSUS$ collective’s evolving tactics**. The incident underscores the persistent threat to **Salesforce ecosystems**, with attackers exploiting **third-party app vulnerabilities** and **OAuth token abuse** to expand their reach.
Show sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
-
10.09.2025 18:29 5 articles · 5mo ago
Jaguar Land Rover Data Breach Confirmed
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
25.08.2025 22:48 3 articles · 6mo ago
Farmers Insurance Data Breach Details Revealed
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
21.08.2025 09:45 1 articles · 6mo ago
Scattered Spider Member Sentenced for Cybercrime Activities
A 20-year-old member of Scattered Spider, Noah Michael Urban, was sentenced to ten years in prison and $13 million in restitution for wire fraud and aggravated identity theft. Urban was arrested in January 2024 for committing wire fraud and aggravated identity theft between August 2022 and March 2023, resulting in the theft of at least $800,000 from five victims. Urban and his co-conspirators used SIM swapping attacks to hijack victims' cryptocurrency accounts and steal digital assets.
Show sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
-
12.08.2025 19:20 15 articles · 6mo ago
ShinyHunters and Scattered Spider Target Salesforce Customers
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
12.08.2025 15:00 15 articles · 6mo ago
ShinyHunters and Scattered Spider Collaboration Detected
The Co-operative Group in the U.K. reported a significant financial loss of £80 million ($107 million) due to a cyberattack in April 2025. The attack, attributed to Scattered Spider affiliates, resulted in a revenue reduction of £206 million ($277 million) and additional expected losses of £20 million ($27 million) for the second half of 2025. The Co-op had to shut down parts of its IT systems, causing disruptions to back-office and call-center services. The attack led to the theft of personal data of 6.5 million members, forcing the Co-op to rebuild its Windows domain controllers and extend system unavailability. The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods. The Co-op's response prevented encryption but resulted in significant financial impact and operational disruptions. The group implemented manual processes, rerouted items, and offered discounts to mitigate the impact. Despite these measures, the Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco. The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
Show sources
- ShinyHunters Tactics Now Mirror Scattered Spider — www.darkreading.com — 12.08.2025 15:00
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
Information Snippets
-
ShinyHunters and Scattered Spider have been observed collaborating on attacks, leveraging each other's strengths.
First reported: 12.08.2025 15:005 sources, 20 articlesShow sources
- ShinyHunters Tactics Now Mirror Scattered Spider — www.darkreading.com — 12.08.2025 15:00
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The collaboration involves shared attack patterns, infrastructure, and synchronized targeting of victims.
First reported: 12.08.2025 15:005 sources, 21 articlesShow sources
- ShinyHunters Tactics Now Mirror Scattered Spider — www.darkreading.com — 12.08.2025 15:00
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
ShinyHunters has adopted tactics similar to Scattered Spider, including vishing and domain spoofing.
First reported: 12.08.2025 15:005 sources, 20 articlesShow sources
- ShinyHunters Tactics Now Mirror Scattered Spider — www.darkreading.com — 12.08.2025 15:00
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The groups have targeted major companies across multiple sectors, including retail and insurance.
First reported: 12.08.2025 15:003 sources, 15 articlesShow sources
- ShinyHunters Tactics Now Mirror Scattered Spider — www.darkreading.com — 12.08.2025 15:00
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
-
The collaboration has led to the use of similar domain formats and registry characteristics.
First reported: 12.08.2025 15:004 sources, 17 articlesShow sources
- ShinyHunters Tactics Now Mirror Scattered Spider — www.darkreading.com — 12.08.2025 15:00
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Defenders must shift focus to behavioral patterns and proactive detection measures to counter this threat.
First reported: 12.08.2025 15:003 sources, 15 articlesShow sources
- ShinyHunters Tactics Now Mirror Scattered Spider — www.darkreading.com — 12.08.2025 15:00
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
ShinyHunters and Scattered Spider are targeting Salesforce customers and may expand to financial services and technology providers.
First reported: 12.08.2025 19:204 sources, 17 articlesShow sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The collaboration includes the use of vishing, social engineering, and VPN obfuscation for data exfiltration.
First reported: 12.08.2025 19:205 sources, 20 articlesShow sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
ShinyHunters has been linked to attacks on Salesforce instances globally, tracked by Google as UNC6240.
First reported: 12.08.2025 19:204 sources, 16 articlesShow sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
A new Telegram channel emerged, conflating ShinyHunters, Scattered Spider, and LAPSUS$, claiming to develop a ransomware-as-a-service solution.
First reported: 12.08.2025 19:205 sources, 15 articlesShow sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider and LAPSUS$ have ties to The Com, a network of experienced English-speaking cybercriminals.
First reported: 12.08.2025 19:204 sources, 15 articlesShow sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The groups have targeted the same sectors, including retail, insurance, and aviation, around the same time.
First reported: 12.08.2025 19:204 sources, 17 articlesShow sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The collaboration may have been ongoing for over a year, with synchronized timing and similar targeting of previous attacks.
First reported: 12.08.2025 19:203 sources, 13 articlesShow sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
BreachForums has been commandeered by international law enforcement and turned into a honeypot.
First reported: 12.08.2025 19:203 sources, 10 articlesShow sources
- Cybercrime Groups ShinyHunters, Scattered Spider Join Forces in Extortion Attacks on Businesses — thehackernews.com — 12.08.2025 19:20
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Workday confirmed a breach involving a third-party CRM system, likely linked to ShinyHunters' Salesforce attacks.
First reported: 18.08.2025 20:003 sources, 9 articlesShow sources
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Attackers used social engineering to impersonate Workday's HR department, gaining access to business contact information.
First reported: 18.08.2025 20:003 sources, 10 articlesShow sources
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Workday quickly blocked access to the compromised system and adopted additional internal security measures.
First reported: 18.08.2025 20:003 sources, 9 articlesShow sources
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Workday is a strategic partner with Salesforce and was one of several companies targeted by a sophisticated social engineering scam.
First reported: 18.08.2025 20:003 sources, 9 articlesShow sources
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The attack on Workday is part of a series of attacks targeting high-profile organizations through their Salesforce instances.
First reported: 18.08.2025 20:003 sources, 10 articlesShow sources
- Workday Breach Likely Linked to ShinyHunters Salesforce Attacks — www.darkreading.com — 18.08.2025 20:00
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The attack on Allianz Life involved the theft of personal information of 1.1 million individuals.
First reported: 19.08.2025 10:173 sources, 10 articlesShow sources
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The breach at Allianz Life occurred on July 16th, impacting nearly 1.4 million customers.
First reported: 19.08.2025 10:173 sources, 10 articlesShow sources
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The stolen data includes email addresses, names, genders, dates of birth, phone numbers, and physical addresses.
First reported: 19.08.2025 10:173 sources, 10 articlesShow sources
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The attackers used a malicious OAuth app to gain access to Salesforce instances.
First reported: 19.08.2025 10:174 sources, 11 articlesShow sources
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The extortion demands were signed as coming from ShinyHunters, a known extortion group.
First reported: 19.08.2025 10:174 sources, 12 articlesShow sources
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The attacks began at the start of the year and involved tricking employees into linking a malicious OAuth app.
First reported: 19.08.2025 10:174 sources, 13 articlesShow sources
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Allianz Life confirmed that some selected employees were also impacted by the breach.
First reported: 19.08.2025 10:173 sources, 9 articlesShow sources
- Massive Allianz Life data breach impacts 1.1 million people — www.bleepingcomputer.com — 19.08.2025 10:17
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Allianz Life breach affected 1.1 million individuals out of 1.4 million customers.
First reported: 19.08.2025 21:503 sources, 9 articlesShow sources
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The breach was first reported by TechCrunch and confirmed by Allianz Life on July 16.
First reported: 19.08.2025 21:503 sources, 9 articlesShow sources
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The compromised data includes dates of birth, genders, phone numbers, email addresses, names, and physical addresses.
First reported: 19.08.2025 21:503 sources, 9 articlesShow sources
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The breach involved a third-party, cloud-based CRM system used by Allianz Life.
First reported: 19.08.2025 21:503 sources, 10 articlesShow sources
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The stolen data was hosted on a Salesforce database, affecting multiple companies.
First reported: 19.08.2025 21:503 sources, 10 articlesShow sources
- Millions Allegedly Affected in Allianz Insurance Breach — www.darkreading.com — 19.08.2025 21:50
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
A 20-year-old member of Scattered Spider, Noah Michael Urban, was sentenced to ten years in prison and $13 million in restitution for wire fraud and aggravated identity theft.
First reported: 21.08.2025 09:453 sources, 10 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Urban was arrested in January 2024 for committing wire fraud and aggravated identity theft between August 2022 and March 2023, resulting in the theft of at least $800,000 from five victims.
First reported: 21.08.2025 09:453 sources, 9 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Urban and his co-conspirators used SIM swapping attacks to hijack victims' cryptocurrency accounts and steal digital assets.
First reported: 21.08.2025 09:453 sources, 9 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider has been collaborating with ShinyHunters and LAPSUS$ to form a new cybercrime alliance, associated with The Com, a broader English-speaking cybercriminal collective.
First reported: 21.08.2025 09:453 sources, 9 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider uses tactics such as timed leaks, countdown threats, and taunts directed at security firms to generate urgency and drive media attention.
First reported: 21.08.2025 09:454 sources, 10 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider employs social engineering techniques, including vishing, smishing, and MFA fatigue attacks, to exploit weaknesses in security programs.
First reported: 21.08.2025 09:455 sources, 13 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group adopts a wave-like approach by targeting specific sectors and attacking multiple organizations within that vertical over a short span of time.
First reported: 21.08.2025 09:454 sources, 12 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider has ties to a wider network of like-minded actors, which has given them access to more tools, data, and infrastructure, multiplying their effectiveness.
First reported: 21.08.2025 09:454 sources, 12 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider's tactics include social engineering, credential theft, SIM swapping, initial access, ransomware deployment, data theft, and extortion attacks.
First reported: 21.08.2025 09:456 sources, 14 articlesShow sources
- Scattered Spider Hacker Gets 10 Years, $13M Restitution for SIM Swapping Crypto Theft — thehackernews.com — 21.08.2025 09:45
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Farmers Insurance has disclosed a data breach impacting 1.1 million customers, with data stolen in the widespread Salesforce attacks.
First reported: 25.08.2025 22:484 sources, 11 articlesShow sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The breach at Farmers Insurance involved the theft of names, addresses, dates of birth, driver's license numbers, and/or last four digits of Social Security numbers.
First reported: 25.08.2025 22:483 sources, 5 articlesShow sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
Farmers Insurance began sending data breach notifications to impacted individuals on August 22, 2025.
First reported: 25.08.2025 22:483 sources, 5 articlesShow sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
The data breach at Farmers Insurance was detected on May 30, 2025, by a third-party vendor's monitoring tools.
First reported: 25.08.2025 22:483 sources, 5 articlesShow sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
The breach at Farmers Insurance involved a third-party vendor's database containing customer information.
First reported: 25.08.2025 22:483 sources, 5 articlesShow sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
Farmers Insurance operates through a network of agents and subsidiaries, serving more than 10 million households nationwide.
First reported: 25.08.2025 22:483 sources, 5 articlesShow sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
The Salesforce data theft attacks have impacted numerous organizations this year, with threat actors classified as 'UNC6040' or 'UNC6240' conducting social engineering attacks on Salesforce customers.
First reported: 25.08.2025 22:484 sources, 7 articlesShow sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
-
ShinyHunters and Scattered Spider are collaborating on Salesforce attacks, with ShinyHunters handling the dump and exfiltration of the Salesforce CRM instances.
First reported: 25.08.2025 22:484 sources, 10 articlesShow sources
- Farmers Insurance data breach impacts 1.1M people after Salesforce attack — www.bleepingcomputer.com — 25.08.2025 22:48
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
-
Jaguar Land Rover (JLR) confirmed that attackers stole data during a recent cyberattack.
First reported: 10.09.2025 18:293 sources, 7 articlesShow sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
-
The cyberattack forced JLR to shut down systems and instruct staff not to report to work.
First reported: 10.09.2025 18:293 sources, 7 articlesShow sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
-
JLR has been working to restart operations and investigating the incident with the U.K. National Cyber Security Centre (NCSC).
First reported: 10.09.2025 18:293 sources, 6 articlesShow sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
JLR disclosed the attack on September 2, stating that its production activities have been severely disrupted.
First reported: 10.09.2025 18:293 sources, 6 articlesShow sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
JLR has notified the relevant authorities about the data breach.
First reported: 10.09.2025 18:293 sources, 6 articlesShow sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
JLR has not attributed the attack to a specific cybercrime group, and no known ransomware gangs have taken responsibility.
First reported: 10.09.2025 18:293 sources, 6 articlesShow sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
A group calling themselves "Scattered Lapsus$ Hunters" has claimed responsibility for the breach on Telegram, sharing screenshots of an internal JLR SAP system and claiming ransomware deployment.
First reported: 10.09.2025 18:293 sources, 6 articlesShow sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
-
The group claims to be associated with Lapsus$, Scattered Spider, and ShinyHunters, and is behind widespread Salesforce data theft attacks.
First reported: 10.09.2025 18:293 sources, 7 articlesShow sources
- Jaguar Land Rover confirms data theft after recent cyberattack — www.bleepingcomputer.com — 10.09.2025 18:29
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
-
The FBI has issued a flash alert on UNC6040 and UNC6395 targeting Salesforce platforms.
First reported: 13.09.2025 12:044 sources, 7 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
UNC6395 exploited compromised OAuth tokens for the Salesloft Drift application.
First reported: 13.09.2025 12:044 sources, 7 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
-
Salesloft isolated the Drift infrastructure and implemented new security measures.
First reported: 13.09.2025 12:044 sources, 7 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
-
UNC6040 has been active since October 2024, using vishing campaigns and custom Python scripts.
First reported: 13.09.2025 12:044 sources, 7 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
-
UNC6040 has used a modified version of Salesforce's Data Loader for data exfiltration.
First reported: 13.09.2025 12:044 sources, 6 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
-
UNC6240, associated with ShinyHunters, has been involved in extortion activities.
First reported: 13.09.2025 12:044 sources, 9 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
-
The group 'scattered LAPSUS$ hunters 4.0' announced it is shutting down on September 12, 2025.
First reported: 13.09.2025 12:044 sources, 6 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
-
The group's shutdown may be an attempt to avoid law enforcement attention.
First reported: 13.09.2025 12:043 sources, 6 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group's shutdown may be temporary, with potential for rebranding and resurfacing.
First reported: 13.09.2025 12:043 sources, 6 articlesShow sources
- FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks — thehackernews.com — 13.09.2025 12:04
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group 'Scattered Lapsus$ Hunters' claimed access to Google's Law Enforcement Request System (LERS) and the FBI's eCheck background check system.
First reported: 15.09.2025 23:123 sources, 5 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group posted screenshots of their alleged access to both Google's LERS and the FBI's eCheck system shortly after announcing they were 'going dark'.
First reported: 15.09.2025 23:123 sources, 5 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group's claims raised concerns about potential impersonation of law enforcement to gain access to sensitive user data.
First reported: 15.09.2025 23:123 sources, 5 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
Google confirmed the creation of a fraudulent account in its LERS platform but stated that no data was accessed.
First reported: 15.09.2025 23:123 sources, 6 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group's actions are part of a broader pattern of data theft attacks targeting Salesforce data.
First reported: 15.09.2025 23:123 sources, 5 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group has been taunting the FBI, Google, Mandiant, and security researchers in posts to various Telegram channels.
First reported: 15.09.2025 23:123 sources, 6 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group has been using social engineering and exploiting exposed authentication tokens to conduct data theft attacks.
First reported: 15.09.2025 23:123 sources, 6 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group has targeted numerous high-profile companies, including Google, Adidas, Qantas, Allianz Life, Cisco, Kering, Louis Vuitton, Dior, Tiffany & Co, Cloudflare, Zscaler, Elastic, Proofpoint, JFrog, Rubrik, Palo Alto Networks, and many more.
First reported: 15.09.2025 23:124 sources, 9 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group has been using social engineering scams to trick employees into connecting Salesforce's Data Loader tool to corporate Salesforce instances.
First reported: 15.09.2025 23:123 sources, 8 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
-
The group breached Salesloft's GitHub repository and used Trufflehog to scan for secrets exposed in the private source code.
First reported: 15.09.2025 23:123 sources, 9 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
-
The group has been taunting Google Threat Intelligence (Mandiant) and security researchers.
First reported: 15.09.2025 23:123 sources, 9 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
-
The group has been using various tactics to conduct data theft attacks, including social engineering, vishing, and exploiting OAuth tokens.
First reported: 15.09.2025 23:124 sources, 12 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
-
The group has been targeting Salesforce customers and may expand to financial services and technology providers.
First reported: 15.09.2025 23:125 sources, 14 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group has been using a wave-like approach by targeting specific sectors and attacking multiple organizations within that vertical over a short span of time.
First reported: 15.09.2025 23:124 sources, 11 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group has ties to a wider network of like-minded actors, which has given them access to more tools, data, and infrastructure, multiplying their effectiveness.
First reported: 15.09.2025 23:126 sources, 14 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group has been using social engineering techniques, including vishing, smishing, and MFA fatigue attacks, to exploit weaknesses in security programs.
First reported: 15.09.2025 23:126 sources, 16 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group has been using tactics such as timed leaks, countdown threats, and taunts directed at security firms to generate urgency and drive media attention.
First reported: 15.09.2025 23:126 sources, 15 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group has been using social engineering, credential theft, SIM swapping, initial access, ransomware deployment, data theft, and extortion attacks.
First reported: 15.09.2025 23:125 sources, 16 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group has been using a modified version of Salesforce's Data Loader for data exfiltration.
First reported: 15.09.2025 23:126 sources, 15 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group has been involved in extortion activities.
First reported: 15.09.2025 23:124 sources, 15 articlesShow sources
- Google confirms hackers gained access to law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- CrowdStrike catches insider feeding information to hackers — www.bleepingcomputer.com — 21.11.2025 18:48
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Crunchbase Confirms Data Breach After Hacking Claims — www.securityweek.com — 26.01.2026 14:22
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group 'Scattered Lapsus$ Hunters' announced it is shutting down on September 12, 2025, possibly to avoid law enforcement attention.
First reported: 15.09.2025 23:123 sources, 8 articlesShow sources
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown may be temporary, with potential for rebranding and resurfacing.
First reported: 15.09.2025 23:123 sources, 8 articlesShow sources
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group posted a lengthy message to a BreachForums-linked domain causing some to believe the threat actors were retiring.
First reported: 15.09.2025 23:123 sources, 8 articlesShow sources
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Cybersecurity researchers believe the group will continue conducting attacks quietly despite their claims of going dark.
First reported: 15.09.2025 23:123 sources, 7 articlesShow sources
- Google confirms fraudulent account created in law enforcement portal — www.bleepingcomputer.com — 15.09.2025 23:12
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
-
Scattered Spider has resumed attacks targeting the financial sector, despite previous claims of going 'dark'.
First reported: 17.09.2025 11:493 sources, 7 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider gained initial access by socially engineering an executive's account and resetting their password via Azure Active Directory Self-Service Password Management.
First reported: 17.09.2025 11:493 sources, 7 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The attackers accessed sensitive IT and security documents, moved laterally through the Citrix environment and VPN, and compromised VMware ESXi infrastructure to dump credentials and further infiltrate the network.
First reported: 17.09.2025 11:493 sources, 4 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
Scattered Spider attempted to exfiltrate data from Snowflake, Amazon Web Services (AWS), and other repositories.
First reported: 17.09.2025 11:493 sources, 6 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's recent activity undercuts their claims of ceasing operations, suggesting a strategic move to evade law enforcement pressure.
First reported: 17.09.2025 11:493 sources, 6 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider is part of a broader online entity called The Com and shares significant overlap with ShinyHunters and LAPSUS$.
First reported: 17.09.2025 11:493 sources, 5 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
-
The group's retirement claims are likely a strategic retreat to reassess practices, refine tradecraft, and evade ongoing efforts to disrupt their activities.
First reported: 17.09.2025 11:493 sources, 6 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider may regroup or rebrand under a different alias in the future, similar to ransomware groups.
First reported: 17.09.2025 11:493 sources, 6 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's farewell letter is viewed as a strategic retreat to complicate attribution efforts and evade law enforcement.
First reported: 17.09.2025 11:493 sources, 6 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider's recent activity includes targeted intrusions against a U.S. banking organization, using sophisticated tactics to evade detection.
First reported: 17.09.2025 11:493 sources, 6 articlesShow sources
- Scattered Spider Resurfaces With Financial Sector Attacks Despite Retirement Claims — thehackernews.com — 17.09.2025 11:49
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group 'Scattered Lapsus$ Hunters' announced it is shutting down on September 12, 2025, possibly to avoid law enforcement attention.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown may be temporary, with potential for rebranding and resurfacing.
First reported: 17.09.2025 22:122 sources, 3 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
The group posted a lengthy message to a BreachForums-linked domain causing some to believe the threat actors were retiring.
First reported: 17.09.2025 22:122 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
Scattered Spider has been targeting the financial sector, including an increase in domains potentially linked to the group focusing on the finance sector.
First reported: 17.09.2025 22:122 sources, 3 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
-
Scattered Spider has conducted a targeted intrusion against a U.S. banking organization.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider's shutdown announcement is viewed as a strategic retreat to complicate attribution efforts and evade law enforcement.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider's recent activity includes targeted intrusions against a U.S. banking organization, using sophisticated tactics to evade detection.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider's shutdown may be a strategic move to evade law enforcement pressure.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's farewell letter indicates that some members may continue in the field of cybersecurity in roles more beneficial to society.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 6 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group became a significant enough threat for the FBI to warn of their social engineering tactics this summer to groups that were more likely to be at risk.
First reported: 17.09.2025 22:122 sources, 3 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
-
Scattered Spider has been emulating some of Scattered Spider's tactics when attacking major enterprises such as Google, Louis Vuitton, Allianz, and more.
First reported: 17.09.2025 22:123 sources, 6 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Security researchers are skeptical of the shutdown announcement, with some pointing to evidence of continued activity.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 4 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's shutdown is more surprising for some groups compared to others, such as Scattered Spider, which has been on a rampage as of late despite the arrests of several alleged members.
First reported: 17.09.2025 22:123 sources, 5 articlesShow sources
- 'Scattered Lapsus$ Hunters,' Others Announce End of Hacking Spree — www.darkreading.com — 17.09.2025 22:12
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The UK National Crime Agency (NCA) has arrested two teenagers, Owen Flowers and Thalha Jubair, linked to the Scattered Spider hacking collective.
First reported: 18.09.2025 17:373 sources, 6 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Owen Flowers, 18, from Walsall, and Thalha Jubair, 19, from East London, are scheduled to appear at Westminster Magistrates Court.
First reported: 18.09.2025 17:373 sources, 6 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Flowers was previously arrested in September 2024 for his alleged involvement in the Transport for London (TfL) attack and was released on bail.
First reported: 18.09.2025 17:373 sources, 6 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Additional evidence links Flowers to attacks against U.S. healthcare companies, including SSM Health Care Corporation and Sutter Health.
First reported: 18.09.2025 17:373 sources, 6 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Thalha Jubair was charged with conspiracies to commit computer fraud, money laundering, and wire fraud, affecting at least 47 U.S. organizations.
First reported: 18.09.2025 17:373 sources, 7 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Jubair and his accomplices have received at least $115 million in ransom payments from victims.
First reported: 18.09.2025 17:373 sources, 7 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The TfL cyberattack in August 2024 disrupted internal systems and online services, and compromised customer data including names, contact details, and addresses.
First reported: 18.09.2025 17:373 sources, 7 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
TfL provides transportation services to over 8.4 million Londoners through its surface, underground, and Crossrail transport systems.
First reported: 18.09.2025 17:372 sources, 6 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
In May 2023, TfL experienced another security breach when the Clop ransomware gang stole data from one of its suppliers' MOVEit Managed File Transfer (MFT) servers.
First reported: 18.09.2025 17:373 sources, 7 articlesShow sources
- UK arrests 'Scattered Spider' teens linked to Transport for London hack — www.bleepingcomputer.com — 18.09.2025 17:37
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Thalha Jubair is also known by the aliases EarthtoStar, Brad, Austin, and @autistic.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Thalha Jubair has been charged under the Regulation of Investigatory Powers Act (RIPA) 2000 for failing to surrender PINs and passwords for devices seized by law enforcement.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The U.S. Department of Justice (DoJ) has charged Jubair with conspiracies to commit computer fraud, wire fraud, and money laundering in relation to at least 120 computer network intrusions and extorting 47 U.S. entities.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The attacks involved the use of social engineering techniques to gain unauthorized access to the target networks, and then leveraging that access to steal and encrypt information, and demand ransom from victims in return for regaining control and preventing the leak of the exfiltrated data.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Victims paid at least $115,000,000 in ransom payments.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The incidents caused widespread disruption to U.S. businesses and organizations, including critical infrastructure and the federal court system, in October 2024 and January 2025.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
In July 2024, law enforcement seized cryptocurrency wallets on a server allegedly controlled by Jubair and confiscated digital assets worth about $36 million at the time.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Jubair is also said to have transferred a portion of the proceeds that originated from one of the victims, worth about $8.4 million at the time, to another wallet.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Jubair has been charged with computer fraud conspiracy, two counts of computer fraud, wire fraud conspiracy, two counts of wire fraud, and money laundering conspiracy.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
If convicted, Jubair faces a maximum penalty of 95 years in prison.
First reported: 19.09.2025 10:053 sources, 6 articlesShow sources
- U.K. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack — thehackernews.com — 19.09.2025 10:05
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
A member of Scattered Spider turned himself in to the Clark County Juvenile Detention Center in Las Vegas.
First reported: 24.09.2025 23:213 sources, 5 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The suspect was identified by the FBI's Las Vegas Cyber Task Force and faces several charges including extortion and computer-related crimes.
First reported: 24.09.2025 23:213 sources, 5 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Clark County District Attorney's Office is seeking to transfer the juvenile to the criminal division to face charges as an adult.
First reported: 24.09.2025 23:213 sources, 5 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Two other suspected members, Thalha Jubair and Owen Flowers, were arrested in the UK for their involvement in the Transport for London (TfL) hack.
First reported: 24.09.2025 23:213 sources, 5 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider, along with Lapsus$ and Shiny Hunters, announced they were shutting down their operations, but security researchers remain skeptical.
First reported: 24.09.2025 23:213 sources, 5 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group's farewell letter indicated that some members plan to retire while others will continue in cybersecurity roles.
First reported: 24.09.2025 23:212 sources, 3 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider's activities include high-profile breaches and ransomware attacks on notable victims such as Caesars Entertainment and MGM Resorts.
First reported: 24.09.2025 23:213 sources, 4 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The FBI and CISA released an advisory on Scattered Spider in November 2023, providing details on how enterprises could defend their networks.
First reported: 24.09.2025 23:213 sources, 4 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
In November 2024, the Department of Justice unsealed criminal charges against five members of Scattered Spider, with sentences up to 20 years in federal prison.
First reported: 24.09.2025 23:213 sources, 4 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The FBI arrested 19-year-old Remington Goy Ogletree in December 2024 for running a phishing operation targeting telecommunications companies and a national bank.
First reported: 24.09.2025 23:213 sources, 4 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Noah Urban, a 20-year-old linked to Scattered Spider, pled guilty to cybercrime charges and agreed to pay millions in restitution.
First reported: 24.09.2025 23:213 sources, 4 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The alleged ringleader of Scattered Spider was arrested in Palma de Mallorca with a laptop, mobile phone, and $27 million in bitcoin.
First reported: 24.09.2025 23:213 sources, 4 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Despite numerous arrests, Scattered Spider continued its attacks, targeting enterprises like Marks & Spencer, Harrods, and Co-Op.
First reported: 24.09.2025 23:213 sources, 4 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The FBI warned organizations about Scattered Spider's social engineering tactics against airline companies and their third-party IT providers.
First reported: 24.09.2025 23:213 sources, 5 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider's farewell letter hinted at potential ongoing data exploitation and future attacks, indicating their operations may not be fully shut down.
First reported: 24.09.2025 23:213 sources, 5 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Cybersecurity experts warn that the group's retirement claims are likely a tactic to evade law enforcement and that the void will be quickly filled by other threat actors.
First reported: 24.09.2025 23:212 sources, 4 articlesShow sources
- The Fall of Scattered Spider? Teen Member Surrenders Amid Group's Shutdown Claims — www.darkreading.com — 24.09.2025 23:21
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider members were arrested in September 2025, following their announcement of shutting down operations.
First reported: 25.09.2025 14:482 sources, 4 articlesShow sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Noah Urban, a key member of Scattered Spider, was sentenced to ten years in prison for his role in SIM-swapping and cybercrime activities.
First reported: 25.09.2025 14:482 sources, 4 articlesShow sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Urban's role involved social engineering to gain access to sensitive systems, using tactics such as SIM-swapping and phishing.
First reported: 25.09.2025 14:482 sources, 4 articlesShow sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Urban's activities included breaching T-Mobile's customer service portal and exploiting a Twilio employee's credentials.
First reported: 25.09.2025 14:482 sources, 4 articlesShow sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group 0ktapus, which includes Scattered Spider members, was involved in high-profile breaches, including the theft of personal information from Gemini Trust.
First reported: 25.09.2025 14:482 sources, 4 articlesShow sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
A man from West Sussex was arrested in connection with a ransomware attack that disrupted operations at several European airports, including Heathrow.
First reported: 25.09.2025 14:482 sources, 4 articlesShow sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The ransomware variant used in the attack was identified as HardBit, described as an "incredibly basic" variant.
First reported: 25.09.2025 14:482 sources, 4 articlesShow sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The attack affected Collins Aerospace baggage and check-in software, causing flight delays at multiple airports.
First reported: 25.09.2025 14:482 sources, 4 articlesShow sources
- Threatsday Bulletin: Rootkit Patch, Federal Breach, OnePlus SMS Leak, TikTok Scandal & More — thehackernews.com — 25.09.2025 14:48
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Co-operative Group in the U.K. reported a loss of £80 million ($107 million) due to a cyberattack in April 2025.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The attack caused a revenue reduction of £206 million ($277 million) and additional losses of £20 million ($27 million) expected for the second half of 2025.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Co-op Group operates 2,300 food retail stores and 59 franchise stores.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The cyberattack forced the Co-op to shut down parts of its IT systems, causing disruptions to back-office and call-center services.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider affiliates were responsible for the Co-op cyberattack, stealing personal data of 6.5 million members.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Co-op had to rebuild its Windows domain controllers and extend system unavailability due to the attack.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The U.K. National Crime Agency arrested four suspects linked to the Co-op cyberattack and similar incidents at Marks & Spencer and Harrods.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Co-op's response to the attack prevented encryption but resulted in significant financial impact and operational disruptions.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Co-op implemented manual processes, rerouted items, and offered discounts to mitigate the impact of the cyberattack.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Co-op faced stock allocation issues and a collapse in sales for certain categories, such as tobacco, due to the cyberattack.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Co-op maintained strong liquidity with £800 million available to navigate external pressures and maintain long-term ambitions.
First reported: 25.09.2025 21:052 sources, 4 articlesShow sources
- Co-op says it lost $107 million after Scattered Spider attack — www.bleepingcomputer.com — 25.09.2025 21:05
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
A threat actor breached Almaviva, the IT services provider for Italy's national railway operator FS Italiane Group, stealing 2.3TB of data including confidential documents, technical documentation, contracts with public entities, HR archives, accounting data, and datasets from FS Group companies.
First reported: 20.11.2025 20:542 sources, 4 articlesShow sources
- Hacker claims to steal 2.3TB data from Italian rail group, Almavia — www.bleepingcomputer.com — 20.11.2025 20:54
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The breach was confirmed by Almaviva, which stated it identified and isolated the cyberattack, activated security and counter-response procedures, and informed Italian authorities, including the police, national cybersecurity agency, and data protection authority.
First reported: 20.11.2025 20:542 sources, 4 articlesShow sources
- Hacker claims to steal 2.3TB data from Italian rail group, Almavia — www.bleepingcomputer.com — 20.11.2025 20:54
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The leaked data is recent, dating to Q3 2025, and was organized into compressed archives by department/company, consistent with the modus operandi of ransomware groups and data brokers active in 2024–2025.
First reported: 20.11.2025 20:542 sources, 4 articlesShow sources
- Hacker claims to steal 2.3TB data from Italian rail group, Almavia — www.bleepingcomputer.com — 20.11.2025 20:54
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Almaviva, a global IT services provider with 41,000+ employees and $1.4B annual revenue, serves FS Italiane Group, a 100% state-owned railway operator with $18B+ annual revenue managing railway infrastructure, passenger/freight transport, and logistics chains.
First reported: 20.11.2025 20:542 sources, 4 articlesShow sources
- Hacker claims to steal 2.3TB data from Italian rail group, Almavia — www.bleepingcomputer.com — 20.11.2025 20:54
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The breach’s impact on passenger data or other Almaviva clients beyond FS Italiane Group remains unclear as of November 20, 2025.
First reported: 20.11.2025 20:542 sources, 4 articlesShow sources
- Hacker claims to steal 2.3TB data from Italian rail group, Almavia — www.bleepingcomputer.com — 20.11.2025 20:54
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The Gainsight cyber-attack initially impacted three Salesforce customers but later expanded to a larger, unspecified number of customers, all of whom were notified by Gainsight and Salesforce by November 21, 2025.
First reported: 26.11.2025 14:053 sources, 5 articlesShow sources
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Gainsight temporarily disabled read/write capabilities from Salesforce for several products, including Customer Success (CS), Community (CC), Northpass - Customer Education (CE), Skilljar (SJ), and Staircase (ST), with Staircase isolated on separate infrastructure and unaffected by the breach.
First reported: 26.11.2025 14:053 sources, 5 articlesShow sources
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Gong.io, Zendesk, and HubSpot disabled their connectors to Gainsight applications as a precautionary measure, with HubSpot confirming no evidence of impact on its systems or customers.
First reported: 26.11.2025 14:053 sources, 5 articlesShow sources
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Salesforce's indicators of compromise (IOCs) revealed the first unauthorized access occurred on November 8, 2025, via an AT&T IP address, followed by approximately twenty suspicious intrusions between November 16 and 23, using tools like Mullvad and Surfshark VPNs.
First reported: 26.11.2025 14:053 sources, 5 articlesShow sources
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The threat actors employed the Salesforce-Multi-Org-Fetcher/1.0 technique, previously observed in the Salesloft Drift attack, and leveraged compromised multifactor credentials for VPN and critical system access.
First reported: 26.11.2025 14:053 sources, 5 articlesShow sources
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Gainsight engaged Mandiant (Google Cloud’s incident response team) to conduct an independent forensic investigation and recommended customers rotate S3 keys, reset NXT user passwords, and re-authorize connected applications as precautionary measures.
First reported: 26.11.2025 14:053 sources, 5 articlesShow sources
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Gainsight advised customers to implement preventative actions outlined by the Google Threat Intelligence Group (GTIG) to mitigate threats from the ShinyHunters-Scattered Spider-LAPSUS$ collective.
First reported: 26.11.2025 14:053 sources, 5 articlesShow sources
- Gainsight Cyber-Attack Affect More Salesforce Customers — www.infosecurity-magazine.com — 26.11.2025 14:05
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The initial list of impacted Gainsight customers provided by Salesforce was 3, but this expanded to a larger, unspecified number by November 21, 2025, with Gainsight CEO Chuck Ganapathi stating only a 'handful' of customers had their data affected.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Salesforce revoked all access and refresh tokens associated with Gainsight-published applications due to detected 'unusual activity'.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Google disabled OAuth clients with callback URIs like 'gainsightcloud[.]com' as a precautionary measure.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Reconnaissance efforts against customers with compromised Gainsight access tokens were first recorded from the IP address '3.239.45[.]43' on October 23, 2025, preceding the unauthorized access waves starting November 8, 2025.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
A new ransomware-as-a-service (RaaS) platform named 'ShinySp1d3r' (or 'Sh1nySp1d3r') is being developed by the Scattered Spider, LAPSUS$, and ShinyHunters (SLSH) alliance, featuring advanced capabilities such as hooking the 'EtwEventWrite' function to prevent Windows Event Viewer logging, terminating processes to enable encryption, and filling free drive space with random data to overwrite deleted files.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
ShinySp1d3r also includes network propagation features like 'deployViaSCM', 'deployViaWMI', and 'attemptGPODeployment' to encrypt open network shares and spread to other devices.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The individual responsible for releasing ShinySp1d3r is a core SLSH member named 'Rey' (aka @ReyXBF), identified as Saif Al-Din Khader, who previously administered BreachForums and the data leak website for HellCat ransomware.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Rey claims to have been cooperating with law enforcement since at least June 2025 and describes ShinySp1d3r as a rehash of HellCat modified with AI tools.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The SLSH alliance has been linked to at least 51 cyberattacks over the past year, combining RaaS and extortion-as-a-service (EaaS) offerings to maximize monetization.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Palo Alto Networks Unit 42 highlights that SLSH's insider recruitment tactics add another layer of complexity for organizations to defend against.
First reported: 27.11.2025 09:032 sources, 4 articlesShow sources
- Gainsight Expands Impacted Customer List Following Salesforce Security Alert — thehackernews.com — 27.11.2025 09:03
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Lapsus$ Hunters is targeting Zendesk users with over 40 typosquatted domains (e.g., znedesk[.]com, vpn-zendesk[.]com) hosting phishing SSO portals to harvest credentials.
First reported: 27.11.2025 11:303 sources, 4 articlesShow sources
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group is submitting fraudulent helpdesk tickets to Zendesk portals, targeting support staff with RATs and malware via pretexts like urgent system administration requests or fake password resets.
First reported: 27.11.2025 11:303 sources, 4 articlesShow sources
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
All malicious Zendesk domains were registered through NiceNic with US/UK registrant details and Cloudflare-masked nameservers, mirroring tactics used in the August 2025 Salesforce campaign.
First reported: 27.11.2025 11:303 sources, 4 articlesShow sources
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Discord confirmed a breach via its Zendesk-based support system, with threat actors stealing user data (names, emails, billing info, IP addresses, and government-issued IDs).
First reported: 27.11.2025 11:303 sources, 4 articlesShow sources
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
ReliaQuest suggests the Zendesk campaign may be the work of Scattered Lapsus$ Hunters or a copycat group exploiting similar phishing and social engineering tactics.
First reported: 27.11.2025 11:303 sources, 4 articlesShow sources
- Scattered Lapsus$ Hunters Take Aim At Zendesk Users — www.infosecurity-magazine.com — 27.11.2025 11:30
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
ShinyHunters compromised Mixpanel via an SMS phishing (smishing) attack on November 8, 2025, stealing 94GB of data containing over 200 million records of PornHub Premium members' historical search, watch, and download activity from 2021 or earlier.
First reported: 15.12.2025 23:272 sources, 5 articlesShow sources
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The stolen Mixpanel data includes PornHub Premium members' email addresses, activity types (watched, downloaded, searched), video URLs, video names, associated keywords, locations, and timestamps.
First reported: 15.12.2025 23:272 sources, 4 articlesShow sources
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
ShinyHunters is extorting Mixpanel customers, including PornHub, with emails beginning with "We are ShinyHunters" and threatening to publish the stolen data unless a ransom is paid.
First reported: 15.12.2025 23:272 sources, 4 articlesShow sources
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
PornHub confirmed it was impacted by the Mixpanel breach but clarified that its own systems were not compromised, and no passwords, payment details, or financial information were exposed.
First reported: 15.12.2025 23:272 sources, 4 articlesShow sources
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
ShinyHunters is linked to the exploitation of the Oracle E-Business Suite zero-day (CVE-2025-61884) and the Salesforce/Drift attacks that impacted numerous organizations in 2025.
First reported: 15.12.2025 23:272 sources, 4 articlesShow sources
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Mixpanel disputes the claim that the PornHub data originated from its November 2025 breach, stating the data was last accessed by a legitimate PornHub employee account in 2023 and that there is no evidence it was stolen during their recent security incident.
First reported: 15.12.2025 23:272 sources, 3 articlesShow sources
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The extorted PornHub data includes 201,211,943 records of historical search, watch, and download activity, with specific details such as video URLs, video names, associated keywords, locations, and timestamps tied to Premium members' email addresses.
First reported: 15.12.2025 23:272 sources, 3 articlesShow sources
- PornHub extorted after hackers steal Premium member activity data — www.bleepingcomputer.com — 15.12.2025 23:27
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Mandiant has identified an expansion in ShinyHunters-style threat activity, involving advanced vishing and credential harvesting to target SaaS platforms for extortion, with clusters UNC6661, UNC6671, and UNC6240 (ShinyHunters) observed using these tactics.
First reported: 31.01.2026 09:582 sources, 3 articlesShow sources
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
UNC6661 impersonated IT staff in early to mid-January 2026, directing employees to credential harvesting links under the pretense of updating MFA settings, then using stolen credentials to register their own MFA devices and exfiltrate data from SaaS platforms.
First reported: 31.01.2026 09:582 sources, 3 articlesShow sources
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
UNC6671, active since early January 2026, also impersonated IT staff to harvest credentials and MFA codes, gaining access to Okta customer accounts and using PowerShell to exfiltrate data from SharePoint and OneDrive.
First reported: 31.01.2026 09:582 sources, 3 articlesShow sources
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
UNC6661 and UNC6671 differ in their use of domain registrars (NICENIC for UNC6661, Tucows for UNC6671) and extortion email indicators, suggesting involvement by distinct but related groups.
First reported: 31.01.2026 09:582 sources, 3 articlesShow sources
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The threat actors are targeting cryptocurrency firms, indicating a broader financial motive beyond traditional extortion.
First reported: 31.01.2026 09:582 sources, 3 articlesShow sources
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Google recommends hardening SaaS platforms by improving help desk verification processes, restricting egress points, enforcing strong passwords, and removing SMS/phone/email as MFA methods, while emphasizing phishing-resistant MFA like FIDO2 security keys or passkeys.
First reported: 31.01.2026 09:582 sources, 3 articlesShow sources
- Mandiant Finds ShinyHunters-Style Vishing Attacks Stealing MFA to Breach SaaS Platforms — thehackernews.com — 31.01.2026 09:58
- Mandiant details how ShinyHunters abuse SSO to steal cloud data — www.bleepingcomputer.com — 31.01.2026 17:02
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
SLSH escalates extortion by harassing executives, their families, and swatting targets to coerce payment, using coordinated Telegram campaigns to amplify psychological pressure.
First reported: 02.02.2026 18:152 sources, 2 articlesShow sources
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
SLSH members originate from 'The Com,' a decentralized network of cybercriminal Discord/Telegram communities known for internal feuds, betrayals, and unreliable behavior, undermining their ability to honor extortion agreements.
First reported: 02.02.2026 18:152 sources, 2 articlesShow sources
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
SLSH's extortion tactics mirror violent sextortion schemes, demanding payment for promises to delete stolen data without technical proof or intent to follow through, while using harassment (DDoS, email floods, negative PR) to overwhelm victims.
First reported: 02.02.2026 18:152 sources, 2 articlesShow sources
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Allison Nixon (Unit 221B) advises victims to refuse negotiation with SLSH, as engagement incentivizes further harassment and provides the group with intelligence on the value of stolen data for future fraud.
First reported: 02.02.2026 18:152 sources, 2 articlesShow sources
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
SLSH manipulates media coverage to amplify perceived threats, using journalist outreach and public Telegram channels to create a veneer of credibility while distracting from their lack of operational discipline.
First reported: 02.02.2026 18:152 sources, 2 articlesShow sources
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
SLSH's January 2026 vishing campaigns involved impersonating IT staff to harvest SSO credentials and MFA codes, then registering their own MFA devices to maintain persistent access to victim networks.
First reported: 02.02.2026 18:152 sources, 2 articlesShow sources
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
SLSH threatens physical violence against security researchers (e.g., Allison Nixon, Brian Krebs) and cybersecurity firms in public statements, using these threats as indicators of compromise during victim communications.
First reported: 02.02.2026 18:152 sources, 2 articlesShow sources
- Please Don’t Feed the Scattered Lapsus Shiny Hunters — krebsonsecurity.com — 02.02.2026 18:15
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Lapsus$ Hunters (SLH) is actively recruiting women for vishing attacks, offering $500–$1,000 per successful call to IT help desks, along with pre-written scripts to increase impersonation success rates.
First reported: 25.02.2026 17:061 source, 1 articleShow sources
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
SLH's recruitment of female voices aims to bypass traditional attacker profiles that IT help desk staff are trained to identify, exploiting psychological biases to improve social engineering effectiveness.
First reported: 25.02.2026 17:061 source, 1 articleShow sources
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group leverages legitimate services and residential proxy networks (e.g., Luminati, OxyLabs) alongside tunneling tools (Ngrok, Teleport, Pinggy) and free file-sharing platforms (file.io, gofile.io, mega.nz, transfer.sh) to evade detection during attacks.
First reported: 25.02.2026 17:061 source, 1 articleShow sources
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider has been observed creating virtual machines (VMs) post-initial access to conduct reconnaissance (e.g., Active Directory enumeration) and exfiltrate data from targets like Outlook mailboxes and Snowflake databases.
First reported: 25.02.2026 17:061 source, 1 articleShow sources
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
Scattered Spider uses the Microsoft Graph API to facilitate unauthorized access to Azure cloud resources, demonstrating a focus on exploiting identity and cloud infrastructure weaknesses.
First reported: 25.02.2026 17:061 source, 1 articleShow sources
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
-
The group employs cloud enumeration tools such as ADRecon for Active Directory reconnaissance, highlighting their technical proficiency in post-exploitation activities.
First reported: 25.02.2026 17:061 source, 1 articleShow sources
- SLH Offers $500–$1,000 Per Call to Recruit Women for IT Help Desk Vishing Attacks — thehackernews.com — 25.02.2026 17:06
Similar Happenings
World Leaks Ransomware Group Exfiltrates 1.4TB of Nike Data
The World Leaks ransomware group has claimed responsibility for a data breach affecting Nike, posting a 1.4TB cache of stolen internal data. The leaked files include R&D and product details, supply chain information, and internal documents dating back to 2020. Nike is investigating the incident, but no customer or employee PII has been identified in the dump. The breach could have significant commercial and operational impacts, including potential disruptions to product launches and supply chain operations. World Leaks removed the Nike entry from its leak site, suggesting potential negotiations or ransom payment. World Leaks is believed to be a rebrand of the Hunters International ransomware group, which emerged in late 2023 and was flagged as a possible Hive ransomware rebrand due to code similarities. Hunters International claimed responsibility for over 280 attacks, including victims such as the U.S. Marshals Service, Tata Technologies, Hoya, AutoCanada, and Austal USA.
EU Investigates X Over Grok-Generated Sexual Content
The European Commission, along with authorities in the UK, France, California, and now Ireland, are investigating X (formerly Twitter) over the use of its Grok AI tool to generate non-consensual sexual images, including child sexual abuse material (CSAM). The investigations are examining whether X has complied with data protection laws and adequately safeguarded against the generation of harmful content. The Irish Data Protection Commission (DPC) has opened a formal inquiry into X's compliance with GDPR obligations, joining the UK's Information Commissioner's Office (ICO), the European Commission, and French prosecutors in their respective investigations. French authorities have also raided X's offices in Paris and summoned Elon Musk and X CEO Linda Yaccarino for interviews. X has restricted Grok's image generation capabilities to paid subscribers, a move criticized by UK officials.
Multi-Stage Phishing Campaign Targeting Russia with Amnesia RAT and Ransomware
A sophisticated multi-stage phishing campaign is targeting users in Russia, employing social engineering tactics to deliver ransomware and Amnesia RAT. The attack begins with business-themed documents that appear benign but contain malicious scripts and payloads distributed via GitHub and Dropbox. The campaign leverages multiple public cloud services to enhance resilience and uses defendnot to disable Microsoft Defender. The malware suppresses visibility, neutralizes endpoint protection, conducts reconnaissance, and deploys payloads capable of data theft, remote control, and financial fraud.
Vishing Attacks Target Okta SSO Accounts for Data Theft
Threat actors are using vishing attacks to steal Okta SSO credentials, bypassing MFA and gaining access to enterprise cloud services. The attacks involve real-time manipulation of phishing pages and social engineering to trick employees into revealing their credentials and MFA codes. Once access is gained, attackers exfiltrate data from integrated platforms like Salesforce and demand extortion payments. The phishing kits used in these attacks are sold as a service and are actively employed by multiple hacking groups targeting identity providers and cryptocurrency platforms. Okta recommends using phishing-resistant MFA methods to mitigate these threats. Attackers use Telegram channels to receive stolen credentials and adapt their campaign based on the MFA or authentication solution the target is using. Phishing kits allow attackers to generate fake MFA notifications to bypass MFA protections.
Jordanian Cybercriminal Admits Selling Access to 50 Enterprise Networks
Feras Khalil Ahmad Albashiti, a 40-year-old Jordanian national residing in Georgia, pleaded guilty in a US court to selling unauthorized access to at least 50 compromised enterprise networks. The access was sold to an undercover agent on an underground cybercriminal forum. Albashiti, known online as 'r1z,' received payment in cryptocurrency. He faces up to 10 years in prison and a $250,000 fine, with sentencing scheduled for May 11, 2026. The Justice Department's Office of International Affairs secured Albashiti's extradition from Georgia in July 2024. Initial access brokers like Albashiti are critical middlemen in the cybercrime ecosystem, providing other threat actors with the credentials needed to breach victims' networks and drop malicious tools to steal data, deploy ransomware, or conduct espionage.