Find notable cyber news and cases, enriched with sources, timelines, and signals.

Scattered Spider, ShinyHunters and LAPSUS$ form a new cybercrime alliance

Threat Actor Meta
First reported
Last updated
Happening score
H score 20
1 unique sources, 1 articles

Summary

Hide ▲

Scattered Spider, ShinyHunters, and LAPSUS$ have formed a new cybercrime alliance, expanding access to tools, data, and infrastructure and increasing the potential scale of future operations. The consolidation matters because it can make credential theft, SIM swapping, and extortion campaigns more versatile and harder to disrupt. The shift also suggests the actors are responding to pressure by pooling capabilities rather than operating in isolation.

Related Happenings

Scattered LAPSUS$ Hunters shifts from borrowed encryptors to ShinySp1d3r RaaS

Threat Actor Meta
First: 26.11.2025 19:22 Last: 26.11.2025 19:22 Sources 1

About this happening: **Scattered LAPSUS$ Hunters (SLSH)** has shifted from using other gangs’ encryptors to launching **ShinySp1d3r**, giving the group its own **ransomware-as-a-service** brand and gr...

Scattered LAPSUS$ Hunters federated extortion collective

Threat Actor Meta
First: 04.11.2025 16:15 Last: 04.11.2025 16:15 Sources 1

About this happening: **Scattered LAPSUS$ Hunters (SLH)** has been identified as a coordinated alliance linking **Scattered Spider**, **ShinyHunters** and **LAPSUS$**, creating a unified brand that exp...

Scattered Lapsus$ Hunters signal extortion-as-a-service shift and possible new ransomware testing

Threat Actor Meta
First: 22.10.2025 11:30 Last: 22.10.2025 11:30 Sources 1

About this happening: **Scattered Lapsus$ Hunters** are signaling a move toward **extortion-as-a-service (EaaS)**, a shift that could widen their reach while reducing direct attribution pressure. Obser...

ShinyHunters publicly operates extortion-as-a-service with partner crews

Threat Actor Meta
First: 07.10.2025 00:08 Last: 07.10.2025 00:08 Sources 1

About this happening: ShinyHunters publicly framed itself as an **extortion-as-a-service (EaaS)** operator, a shift that can scale **multi-victim extortion** and blur attribution across partner breache...

Russian threat ecosystem shift changes threat-actor operations

Threat Actor Meta
First: 03.10.2025 22:07 Last: 03.10.2025 22:07 Sources 1

About this happening: Russian threat actors are increasingly outsourcing **reconnaissance** to **foreign youth**, widening their operational reach while reducing attribution risk. The pattern matters b...

Timeline

  1. 21.08.2025 09:45 1 articles · 9mo ago

    Scattered Spider, ShinyHunters, and LAPSUS$ form a new cybercrime alliance

    Campaign Scope Update

    Scattered Spider, ShinyHunters, and LAPSUS$ form a new cybercrime alliance associated with The Com, bringing together groups known for social engineering, credential theft, SIM swapping, initial access, ransomware deployment, data theft, and extortion.

    Show sources