The cybercriminal alliance known as Scattered LAPSUS$ Hunters (SLSH), an amalgamation of groups including Scattered Spider, LAPSUS$, and ShinyHunters, has intensified its campaign of data theft and extortion against major corporations. In November 2025, Salesforce detected unusual activity involving Gainsight-published applications, leading to the revocation of access tokens and removal of affected apps from its AppExchange. Salesforce determined that the incident was not due to a vulnerability in its platform, but rather unauthorized access to customer data through compromised app connections. The breach was traced back to a supply chain attack on Salesloft Drift in August 2025, which enabled attackers to obtain secrets used to access additional Salesforce instances. Gainsight confirmed that stolen OAuth tokens were used in the attack, and indicators of compromise were shared with affected customers.
SLSH has leveraged this access to threaten public data leaks and extort both Salesforce and its customers, with a new extortion portal listing dozens of victim companies, including Toyota, FedEx, Disney/Hulu, and UPS. The group has also escalated its tactics by openly recruiting insiders from large organizations, offering rewards for internal access to facilitate further breaches. Recent reports indicate that SLSH's activities are coordinated through Telegram channels, and the group has been linked to high-profile incidents involving both data theft and attempted insider recruitment. Security advisories and ongoing investigations highlight the persistent threat posed by SLSH and the importance of monitoring supply chain risks and insider threats.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
13 events from the most recent confirmed update back to the earliest known activity.
Reporting indicated that the FBI had targeted BreachForums and was aware of SLSH's activities, highlighting ongoing law-enforcement attention to the group's ecosystem.
Operational security mistakes exposed the identity of SLSH technical operator 'Rey,' who was identified as teenager Saif Al-Din Khader from Amman, Jordan.
Researchers reported that the group intends to expand ShinySp1d3r beyond Windows with planned Linux and ESXi variants, signaling broader targeting ambitions.
The alliance introduced its own ransomware-as-a-service operation, ShinySp1d3r, initially for Windows, after previously relying on other affiliates' ransomware tooling.
After obtaining victim data, SLSH warned organizations that stolen information would be published unless ransom demands were met.
The threat group Bling Libra, also known as ShinyHunters, claimed it had obtained access to 285 additional Salesforce instances, indicating broader compromise and follow-on extortion potential.
In response to the incident, Gainsight suspended connections to other SaaS platforms to limit further risk while the compromise was being addressed.
Investigation linked the Salesforce-related compromise to a supply-chain attack involving Salesloft Drift, expanding the scope beyond a direct single-platform intrusion.
Salesforce identified unusual activity involving Gainsight-published applications, prompting revocation of tokens and customer notifications about the incident.
SLSH recently succeeded in paying a former CrowdStrike employee in exchange for internal access, marking a concrete insider-recruitment success for the group.
During 2025, the group actively sought insiders in sectors including retail and hospitality to facilitate intrusions and data theft.
Throughout 2025, SLSH used social engineering, including voice phishing, to compromise Salesforce portals and steal data from companies including Toyota, FedEx, Disney/Hulu, and UPS, threatening leaks unless ransoms were paid.
The Scattered LAPSUS$ Hunters alliance resumed activity in 2025, returning to data theft, extortion, and insider-recruitment operations against organizations.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.