Scattered Lapsus$ Hunters
Scattered LAPSUS$ Hunters is a financially motivated cybercriminal collective described in the content as a loose alliance or conglomerate formed in mid-2025 from Scattered Spider, LAPSUS$, and ShinyHunters, and sometimes dubbed the "Trinity of Chaos." Reported aliases include SLH, SLSH, LPH, Trinity of Chaos, and variants of the name using different capitalization or separators. The group is described as typically young, reckless, and English-speaking. The content links the group to large-scale data theft, extortion, leak-site operations, and some ransomware-branded activity. Reported victimology includes SaaS and enterprise cloud environments, especially Salesforce-related compromises, as well as retail, hospitality, telecommunications, automotive, education, government, and software targets. Specific incidents and claims in the content include extortion demands directed at Salesforce; attacks or claimed attacks involving Instructure, Jaguar Land Rover, Marks & Spencer, Co-op, Harrods, SK Telecom, Discord/Zendesk-related exposure claims, and publication of apparent phone numbers and addresses of hundreds of government officials including nearly 700 DHS personnel. Tradecraft described in the content centers on social engineering rather than software exploitation. Reported techniques include voice phishing/vishing, help-desk impersonation, MFA-device registration, password resets, phishing and interactive social engineering, use of stolen credentials or tokens, and rapid exfiltration from SaaS platforms. The group is repeatedly associated with Salesforce data theft and broader enterprise cloud targeting. Related reporting in the content also describes overlap with identity-platform and SSO-focused operations, including Okta-targeting campaigns, and extortion workflows involving leak sites and Telegram channels. The content also describes affiliated or overlapping branding and sub-groups. ShinyHunters is repeatedly identified as part of the trio. CoinbaseCartel is described as a data-theft offshoot of the larger Scattered Lapsus$ Hunters collective. Public reporting cited in the content notes analytical overlap among labels including Scattered Spider, ShinyHunters, and LAPSUS$, and some reporting uses alternate shorthand such as SLSH or LPH for the collective.
Know when an actor pivots toward your sector
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Tradecraft
47 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
Associated malware families
2 malware families attributed to this actor across reporting.
Associated vulnerabilities
1 CVE this actor has used in observed campaigns. 1 of them exploited in the wild.
Observables
2 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
Recent activity
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Data-leak and extortion crew that falsely claimed full access to Resecurity systems but instead fell into a honeypot, leading to investigative action.
Larger cybercriminal collective from which CoinbaseCartel emerged as a data-theft offshoot.
Named as an interconnected extortionist network associated with The Com, involved in SIM swapping and coercive/extortion activity including threats of physical harm.
A cybercriminal collective that listed Instructure on its leak site during a wave of Salesforce-related breaches affecting multiple companies.
The version that knows your environment.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.