Scattered Lapsus$ Shiny Hunters (SLSH) is a cybercriminal threat actor associated with large-scale data theft, extortion, and supply-chain-style compromises. The group has been described as emerging from the Western cybercrime milieu known as The Com and as an outlier relative to the more common post-Soviet ransomware ecosystem. Reporting indicates operational overlap or loose decentralization involving Scattered Spider, UNC3944, LAPSUS$, and ShinyHunters, although SLSH is best understood as a distinct label used for activity blending characteristics associated with those clusters. SLSH is linked primarily to pay-or-leak extortion rather than classic encryption-based ransomware operations. Its activity has included theft of data from enterprise and SaaS environments, public claims of responsibility on leak channels, ransom demands tied to threatened publication of stolen information, and disruptive follow-on actions intended to pressure victims. Observed tradecraft includes abuse of trusted third-party integrations, compromise of SaaS application relationships, token-based access to cloud platforms, API-level intrusion, and defacement or modification of login portals to display extortion messaging. The group has been associated with attacks affecting Salesforce-related ecosystems and downstream customers through compromised business application integrations, as well as with disruptive activity targeting the education sector through the Canvas academic platform. In these incidents, SLSH or closely linked ShinyHunters-branded activity was tied to broad downstream impact across many organizations through a single platform or supplier relationship, illustrating a preference for high-leverage compromises that maximize victim count and extortion pressure. Victimology associated with SLSH spans multiple sectors, including education, technology, and enterprise SaaS customers. Public reporting also characterizes participants linked to this cluster as having caused significant disruption across numerous sectors and as materially affecting organizations in the United Kingdom and elsewhere. The actor’s operations appear financially motivated, with emphasis on data access, exfiltration, coercive disclosure threats, and exploitation of identity and trust relationships in cloud environments. Known aliases and related labels include Scattered Lapsus$ Shiny Hunters, SLSH, and references connecting the cluster to ShinyHunters, LAPSUS$, Scattered Spider, and UNC3944. Because these names reflect overlapping communities and partially intersecting operational patterns, attribution boundaries remain somewhat fluid; only the overlap itself is well supported.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named threat actor or activity cluster with operational overlap with ShinyHunters.
SLSH is conducting sophisticated supply chain attacks targeting Salesforce and its ecosystem, compromising third-party applications (such as Gainsight and Salesloft) to obtain OAuth tokens and gain API-level access to client Salesforce environments. Their operations include data exfiltration, manipulation, and potential extortion, leveraging automation and anonymization techniques.
Western cybercrime actors (linked in the text as an exception to post-Soviet ransomware landscape) associated with disruptive activity across multiple sectors; described as emerging from 'The Com'.
Western, youth-linked cybercrime cluster associated with disruptive activity across numerous sectors; described as an anomaly compared to post-Soviet ransomware ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.