Scattered Lapsus ShinyHunters (SLSH) is an English-language cybercrime extortion group associated with the loosely organized online criminal ecosystem known as The Com. The group is characterized as a fluid, unruly data-extortion actor rather than a conventional ransomware operation. Its campaigns emphasize theft of access and data, followed by aggressive coercion intended to force payment, with little credibility that stolen information will be deleted if victims comply. SLSH is known for social-engineering-driven initial access, particularly voice phishing in which operators impersonate internal IT staff. Reported intrusion chains include directing employees to victim-branded credential-harvesting pages, capturing single sign-on credentials and multi-factor authentication codes, and enrolling attacker-controlled MFA devices to maintain access. The group’s operations therefore combine initial access, credential theft, session and identity abuse, persistence, and post-compromise extortion. The actor’s extortion playbook is unusually aggressive and includes harassment, threats, swatting, repeated email flooding, public shaming on Telegram, and outreach to journalists and regulators to amplify pressure on victims. SLSH has also used DDoS attacks against victim-facing services during extortion campaigns and has threatened executives and their families, including false emergency reports intended to trigger armed police responses. This behavior distinguishes the group from more structured ransomware affiliate programs that primarily rely on encryption and negotiated payment channels. Operations attributed to SLSH have been variously branded under Scattered Lapsus ShinyHunters and ShinyHunters, reflecting overlap among actors and identities within The Com. The group has also been referred to as SLSH. Available reporting ties its membership to Western, adolescent-heavy cybercrime communities rather than to a state-sponsored apparatus. Its dominant activity is financially motivated data-theft extortion supported by social engineering, public intimidation, and disruptive pressure tactics rather than malware-based encryption.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
14 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
English-language extortion gang conducting data theft and ransom operations, using aggressive psychological coercion including harassment, swatting, threats against executives and families, DDoS attacks, email-flooding, and public pressure via journalists and regulators.
Engaged in data breaches and hacking operations, including targeting cybersecurity firms.
An overlapping branding/cluster associated with ShinyHunters-style vishing/live-phishing-driven data theft followed by extortion; described as emerging from 'The Com' ecosystem.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.