CrowdStrike terminated an employee after discovering that the individual had shared internal screenshots of company systems with a hacking group. The screenshots, which included dashboards and links to company resources such as an Okta dashboard, were later published by Scattered Lapsus$ Hunters on Telegram. CrowdStrike emphasized that their systems were not breached, no customer data was exposed, and the incident was promptly reported to law enforcement.
The hacking group ShinyHunters claimed to have offered the insider $25,000 for network access and alleged they received SSO authentication cookies, but CrowdStrike stated that the insider's access was cut off before any compromise occurred. The hackers also attempted to obtain internal reports about ShinyHunters and Scattered Spider but were unsuccessful. CrowdStrike denied any connection between this incident and recent claims of broader Salesforce-ecosystem breaches involving other companies.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Following reports about the insider leak, CrowdStrike stated that it had not been breached and that the exposed material came from an internal employee sharing information rather than an external intrusion. This public clarification appeared as the story became widely reported.
CrowdStrike fired the employee responsible for sharing internal information with hackers. Multiple reports described the action as the company's response to the insider incident.
An insider at CrowdStrike sent internal screenshots and other non-public company information to a hacking group described in reporting as Scattered Spider/Lapsus$-linked actors. The incident was characterized as an insider leak rather than a compromise of CrowdStrike's systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcehackread.com
Open sourcesecurityaffairs.com
Open sourcecsoonline.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.