Threat actors associated with the Scattered Lapsus$ Hunters group have launched a sophisticated campaign targeting Zendesk users by creating over 40 typosquatted and impersonation domains designed to mimic legitimate Zendesk portals. These domains are used to harvest credentials through fake single sign-on pages and to submit malicious tickets to real Zendesk helpdesks, potentially delivering remote-access trojans (RATs) to support agents. The attackers' tactics mirror previous campaigns against Salesforce and are believed to be linked to the same criminal crew, with the potential for lateral movement within compromised organizations and theft of sensitive data. The campaign has also been connected to the September 2025 Discord breach, where attackers exploited Discord's Zendesk-based support system to steal user data, including government-issued IDs and billing information.
Separately, investigative reporting has identified a 15-year-old in Jordan, known online as "Rey," as a possible key figure in the Scattered Lapsus$ Hunters group. The group, which combines elements of Scattered Spider, Lapsus$, and ShinyHunters, has been implicated in high-profile data thefts from companies such as Salesforce, Toyota, and FedEx. The identification of "Rey" was based on digital footprints and personal information inadvertently revealed in cybercrime forums and Telegram channels. The group has also attempted to recruit insiders at targeted companies, further increasing the threat posed by their operations.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
Public statements attributed to Scattered Lapsus$ Hunters threatened additional campaigns and data leaks, including claims of stolen Salesforce customer records. Reporting also said the group promised to return in 2026 with an 'extortion-as-a-service' model despite earlier shutdown claims.
After identifying the fake Zendesk domains and associated attack workflow, ReliaQuest shared its findings with Zendesk. At the time of reporting, Zendesk had not publicly commented.
An investigative report published on November 27, 2025 identified a 15-year-old Jordanian known as 'Rey' as an alleged key member of Scattered Lapsus$ Hunters. The accused individual and the group publicly denied the claims, and no law enforcement action was reported.
ReliaQuest discovered more than 40 typosquatted and impersonation domains mimicking Zendesk portals, used to harvest credentials and submit malicious support tickets. The infrastructure was linked to Scattered Lapsus$ Hunters and mirrored patterns seen in earlier Salesforce-related activity.
Scattered Lapsus$ Hunters was also linked to the Gainsight compromise reported in November 2025. The attribution reinforced the view that the group was expanding its focus to SaaS and customer-support ecosystems.
The coalition was later assessed to be responsible for the Discord breach reported in September 2025. This incident became one of the early major attacks attributed to the group.
Scattered Lapsus$ Hunters emerged in August 2025 as a coalition blending members and tactics associated with Scattered Spider, Lapsus$, and ShinyHunters. Researchers described it as a new grouping focused on social engineering, SaaS platforms, and extortion.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
5 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcebankinfosecurity.com
Open sourcegovinfosecurity.com
Open sourcego.theregister.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.