Scattered LAPSUS$ Hunters (SLH/SLSH) has been observed recruiting women to conduct voice-phishing (vishing) calls aimed at corporate IT help desks, offering $500–$1,000 per call and providing pre-written scripts to guide impersonation attempts. Reporting based on Dataminr-collected Telegram posts indicates applicants are directed to contact a group “Support” account, undergo screening questions, and—if accepted—receive scripts intended to improve success rates in persuading help desk staff to reset passwords or otherwise facilitate account takeover.
The recruitment effort aligns with SLH’s established social-engineering tradecraft associated with the broader ecosystem of Lapsus$, Scattered Spider, and ShinyHunters, including tactics to bypass MFA such as SIM swapping and MFA prompt bombing (fatigue), and persuading targets to install or use remote monitoring and management (RMM) tooling for access. Dataminr assessed the focus on “female voices” is likely intended to evade common help-desk suspicion patterns and increase impersonation effectiveness; follow-on activity attributed to Scattered Spider-style intrusions has been linked in prior reporting to lateral movement, data theft, and in some cases ransomware deployment after initial access is obtained.

Get the infrastructure and lures behind it.
4 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-24, Dataminr published an intelligence brief describing SLH's recruitment drive and assessed it as an evolution of the group's help-desk-focused social-engineering tactics. The report highlighted the use of prewritten scripts and recommended stronger identity verification and phishing-resistant MFA defenses.
On 2026-02-22, Scattered Lapsus$ Hunters posted recruitment messages on Telegram seeking women to conduct voice-phishing calls against IT help desks. The ads offered roughly $500 to $1,000 upfront per call and included prepared scripts to support impersonation attempts.
In October 2025, Scattered Lapsus$ Hunters was reported to have crowdsourced harassment of executives at extortion targets via Telegram, offering $10 in Bitcoin per action. The group later claimed, without independent verification, that it had paid out more than $1,000 shortly after the effort began.
In September 2025, Palo Alto Networks Unit 42 observed a case in which actors linked to Scattered Spider obtained privileged credentials through a help desk, conducted reconnaissance in virtualized environments, and attempted to exfiltrate Outlook mailbox files and Snowflake data. The case illustrated the group's established pattern of using social engineering for initial access followed by lateral movement and privilege escalation.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcego.theregister.com
Open sourcethehackernews.com
Open sourcedataminr.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.