Find notable cyber news and cases, enriched with sources, timelines, and signals.

Scattered LAPSUS$ Hunters IT help-desk vishing campaign

Campaign
First reported
Last updated
Happening score
H score 33
1 unique sources, 1 articles

Summary

Hide ▲

Scattered LAPSUS$ Hunters (SLH) is running a help-desk vishing campaign that recruits women to impersonate employees, raising the success rate of account-takeover attempts against organizations. The group is offering $500 to $1,000 per call and supplying pre-written scripts to standardize the impersonation. The operation targets IT help desks and call centers to trigger password resets or installation of RMM tools for remote access.

Related Happenings

Npm registry spear-phishing campaign targeting sales personnel

Campaign
First: 29.12.2025 11:44 Last: 29.12.2025 11:44 Sources 1

About this happening: **Unknown threat actors** ran a **five-month** spear-phishing campaign that abused **27 npm packages** as browser-hosting infrastructure, turning a software registry into a resili...

BatShadow job-seeker social-engineering campaign

Campaign
First: 07.10.2025 20:04 Last: 07.10.2025 20:04 Sources 1

About this happening: **BatShadow** is running a **phishing campaign** that targets **job seekers** and **digital marketing professionals** with **ZIP archives** and lure PDFs that deliver **Vampire Bo...

ShinyHunters publicly operates extortion-as-a-service with partner crews

Threat Actor Meta
First: 07.10.2025 00:08 Last: 07.10.2025 00:08 Sources 1

About this happening: ShinyHunters publicly framed itself as an **extortion-as-a-service (EaaS)** operator, a shift that can scale **multi-victim extortion** and blur attribution across partner breache...

Microsoft Teams initial-access campaign impersonating IT help desk staff

Campaign
First: 30.08.2025 15:06 Last: 30.08.2025 15:06 Sources 1

About this happening: The **Microsoft Teams** phishing campaign is giving **unknown threat actors** a reliable path to **initial access** in enterprise environments and to install **remote access softw...

Timeline

  1. 25.02.2026 17:06 2 articles · 3mo ago

    Initial report: Scattered LAPSUS$ Hunters IT help-desk vishing campaign

    Initial Disclosure

    The current phase is a **recruitment push** that pays women to make **vishing calls** and use scripts to impersonate employees. This expands SLH's help-desk social-engineering approach and improves the odds of successful **password reset** abuse.

    Show sources