Scattered LAPSUS$ Hunters is a financially motivated cybercriminal collective and extortion brand that emerged in 2025 as an apparent amalgamation of actors or branding associated with Scattered Spider, LAPSUS$, and ShinyHunters. Public reporting also refers to the group as SLH, SLSH, LPH, and the "Trinity of Chaos." The cluster is generally characterized as English-speaking, relatively young, and heavily reliant on social engineering, credential theft, and abuse of legitimate cloud and SaaS access rather than bespoke exploitation or traditional ransomware encryption. The group has been linked to large-scale data theft and extortion campaigns targeting enterprise SaaS environments, customer support platforms, source-code repositories, and identity-centric workflows. Reported victim sectors include technology, telecommunications, retail, aviation, education, automotive, logistics, and government-related entities. Activity attributed to the group includes Salesforce-related data theft extortion, compromise of support environments such as Zendesk through outsourced or third-party agent accounts, theft of source code from GitHub-accessible environments, and publication or threatened publication of stolen data through leak sites and Telegram channels. Observed tradecraft centers on interactive social engineering and valid-account abuse. Commonly reported techniques include vishing and help-desk impersonation, phishing against employees and contractors, MFA fatigue and device-registration abuse, session hijacking, token theft, insider recruitment, and compromise of third-party service providers or business-process outsourcers. Once access is obtained, the actors exploit trusted integrations among SaaS platforms, identity providers, internal administrative tooling, and APIs to enumerate users, collect support records, extract sensitive attachments, and move laterally across connected cloud services. Their operations frequently map to supply-chain compromise, valid accounts, data from information repositories, and exfiltration over web services. Scattered LAPSUS$ Hunters is primarily associated with data theft and extortion rather than consistent deployment of file-encrypting ransomware. The group has advertised extortion-as-a-service concepts and has at times claimed development of ransomware-branded tooling, but its most consistently reported monetization model is pay-or-leak extortion based on stolen data. Public reporting also describes offshoot or associated brands such as CoinbaseCartel, and references overlap with broader "The Com" ecosystem of socially engineered intrusions and extortion activity. Attribution should be treated carefully because the name itself appears to function partly as an umbrella brand invoking three notorious cybercrime groups, and some public reporting describes it as a loose syndicate rather than a tightly unified organization. High-confidence reporting nevertheless places the brand within the English-speaking financially motivated threat landscape focused on cloud compromise, SaaS data theft, and aggressive extortion.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
44 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
2 malware families attributed to this actor across reporting.
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
3 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Financially motivated extortion activity centered on compromising outsourced BPO agent accounts to access Zendesk, mass-export support tickets and attachments, and pressure victims with threats to publish sensitive user data.
Claimed responsibility for the September 2025 Discord-related extortion incident after a social-engineering compromise of a support agent, publicly taunted Discord, and demanded ransom while asserting possession of large volumes of government ID photos.
Ransom-motivated group that falsely claimed complete compromise and data theft from Resecurity, but was instead caught in a decoy environment that aided law-enforcement follow-on action.
Data-leak and extortion crew that falsely claimed full access to Resecurity systems but instead fell into a honeypot, leading to investigative action.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.