Scattered Lapsus$ ShinyHunters (SLSH) is an English-language data-extortion threat actor associated with the loosely organized Western cybercrime ecosystem known as The Com. Reporting describes operational overlap with Scattered Spider (UNC3944), LAPSUS$, and ShinyHunters, but SLSH is treated as a distinct extortion brand. The group is notable for aggressive coercive tactics that go beyond conventional ransomware playbooks, including public shaming, direct harassment of executives, threats against victims and their families, swatting, repeated email flooding, DDoS pressure, and outreach to journalists and regulators to amplify reputational and legal pressure. SLSH is primarily associated with data-theft extortion rather than encryption-led ransomware operations. Its campaigns have been described as pay-or-leak operations in which stolen data is used as leverage, often accompanied by public victim naming on Telegram channels or leak infrastructure. Victims reportedly may first learn of a compromise through these public disclosures. The group has also been linked to victim-harassment tactics intended to manufacture urgency and humiliation during negotiations, and security researchers have warned that promises to delete stolen data after payment are not credible. Observed intrusion methods include social engineering and identity compromise. In early 2026 incidents, SLSH reportedly used voice phishing while impersonating internal IT staff, directing employees to victim-branded credential-harvesting pages to capture single sign-on credentials and MFA codes, then enrolling attacker-controlled MFA devices. The actor has also been linked to supply-chain and SaaS compromise activity, including abuse of OAuth tokens and API-level access in Salesforce-related intrusions, enabling access to customer data across downstream tenants. In another widely reported campaign, the group was tied to compromise and defacement activity affecting the Canvas academic platform, where ransom messaging was displayed on login portals and stolen data was allegedly used for extortion. Known targeting includes universities and educational institutions using Canvas, as well as enterprises reliant on SaaS ecosystems such as Salesforce and Gainsight. Public reporting also links the actor to attacks affecting technology companies and service providers, and to broader disruptive activity harming organizations in the United States, Canada, Australia, New Zealand, and the United Kingdom. The group has been characterized as decentralized, fluid, and less disciplined than traditional post-Soviet ransomware operations, reflecting its roots in The Com rather than in structured RaaS affiliate programs.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a named threat actor or activity cluster with operational overlap with ShinyHunters.
English-language extortion gang conducting data theft and ransom operations, using aggressive psychological coercion including harassment, swatting, threats against executives and families, DDoS attacks, email-flooding, and public pressure via journalists and regulators.
Engaged in data breaches and hacking operations, including targeting cybersecurity firms.
SLSH is conducting sophisticated supply chain attacks targeting Salesforce and its ecosystem, compromising third-party applications (such as Gainsight and Salesloft) to obtain OAuth tokens and gain API-level access to client Salesforce environments. Their operations include data exfiltration, manipulation, and potential extortion, leveraging automation and anonymization techniques.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.