A new ransomware collective known as Trinity of Chaos, comprising the notorious threat groups Lapsus$, Scattered Spider, and ShinyHunters, has launched a data leak site on the TOR network, showcasing sensitive data allegedly stolen from 39 major organizations. The group claims to specialize in high-value corporate data acquisition and strategic breach operations, targeting a wide range of sectors including automotive, financial, insurance, technology, telecommunications, and more. Among the high-profile victims named are Google, Cisco, Stellantis, Toyota, FedEx, Disney, Marriott, McDonald’s, Qantas, Pandora, and Air France. The collective has also taken responsibility for the alleged theft of one billion Salesforce records, highlighting the scale and ambition of their operations. The group first emerged in August 2025, coordinating their activities and marketing a new ransomware-as-a-service (RaaS) offering called “shinysp1d3r” via a Telegram channel, which was later banned. According to security researchers, Scattered Spider provided initial access to targets, while ShinyHunters managed data exfiltration and public dumps, with Lapsus$ members actively participating in the campaigns. The leak site has published data samples including contact information and order details from Dell customers, full names and addresses from Telstra customers, and personally identifiable information from Kuwait Airways passengers. Other telecommunications firms such as Verizon, True Corporation & dtac, and Lycamobile have also been listed as victims, raising concerns about the potential for identity theft and social engineering attacks. The exposure of such sensitive data across multiple industries significantly increases the risk of downstream attacks, including phishing, fraud, and targeted scams. Security researchers have warned that the scale of the leaks could have far-reaching consequences for both individuals and organizations, especially given the diversity of the affected sectors. The Trinity of Chaos collective has demonstrated a high level of coordination and technical sophistication, leveraging the strengths of its constituent groups to maximize impact. The group’s public-facing leak site serves both as a tool for extortion and as a marketing platform for their RaaS offering. The inclusion of data from major global brands underscores the group’s reach and the potential for widespread reputational and financial damage. The collective’s activities have prompted urgent calls for affected organizations to assess their exposure, notify impacted individuals, and strengthen their security postures. The emergence of Trinity of Chaos marks a significant escalation in the ransomware threat landscape, with the group’s collaborative model likely to inspire similar alliances among other threat actors. Security experts continue to monitor the situation closely, warning that the group’s ongoing campaigns could result in further high-profile breaches and data leaks.

TTPs, infrastructure, and targeting history in one profile.
2 events from the most recent confirmed update back to the earliest known activity.
Reporting emerged alleging that multiple international companies had been compromised by a threat actor referred to as Scattered Lapsus$ Hunters. The references provided do not identify a more precise date for the underlying intrusions, so the reporting date is used.
A ransomware collective calling itself Trinity of Chaos launched a data leak site, marking a new public extortion and victim-shaming capability for the group. The available references do not provide a more specific event date beyond the publication day.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See this adversary's TTPs, infrastructure, and targeting history, correlated against your exposure.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.