Threat intelligence reporting warned that victims of Scattered Lapsus$ Hunters—a The Com-linked extortion operation also using names such as ShinyHunters and SLSH—should not negotiate or pay, citing a pattern of escalating coercion and unreliable promises to delete or return stolen data. The campaign is characterized as data-theft extortion without encryption, where attackers threaten public leaks while simultaneously applying pressure through media manipulation and aggressive outreach designed to overwhelm incident response and executive decision-making.
Unit 221B described harassment tactics used to intensify negotiations and reputational damage, including DDoS, email/SMS flooding, and swatting, alongside threats that can extend to physical intimidation of executives and families. Reporting also noted the group’s tendency to contact journalists to amplify pressure and create negative PR during active incidents, and assessed the operation as volatile and internally conflicted—behavior that can increase risk to victims while limiting the group’s operational discipline. The recommended focus for impacted organizations is containment, remediation, and stakeholder notification, recognizing that once data is stolen, payment does not “un-breach” it.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Unit 221B researchers, including Allison Nixon, warned that negotiating with 'Scattered Lapsus$ Hunters' is likely to escalate extortion into harassment and does not reliably result in deletion or return of stolen data. The warning also highlighted threats of DDoS and physical violence against executives and their families, and described the group as part of 'The Com.'
Unit 221B published an analysis describing an ongoing wave of incidents tied to actors in 'The Com' using names including 'ShinyHunters,' 'Scattered Lapsus Hunters,' and 'SLSH.' The report said the group often steals data without deploying encryption and pressures victims with leak threats, swatting, DDoS, message flooding, and threats against employees and families.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.