#ScatteredLapsus$Hunters
Crowdstrike catches insider who was paid $25,000 to feed info to Scattered Lapsus$ Hunters

www.bleepingcomputer.com/news/securit...

#CyberSecurity #InsiderThreat #ScatteredLapsus$Hunters
November 25, 2025 at 7:06 PM
⚠️ Salesforce rejects ransom demand after data extortion

#Salesforce says it will not negotiate with or pay extortionists claiming they stole data from its customers.

ScatteredLapsus$Hunters target client systems, not the core Salesforce platform.

#ransomNews #dataextortion #cloudsecurity
October 8, 2025 at 12:37 PM
November 5, 2025 at 6:00 PM
#Scattered #LAPSUS$ #Hunters #SLH website shinyhunte[.]rs disapeared and is displaying a personal warning message. #ScatteredLAPSUS$Hunters #Cybercrime
October 20, 2025 at 9:08 PM
Notorious hacker group doxxes ICE and FBI officials in leak | Mashable mashable.com/article... #cybersecurity #ScatteredLAPSUS$Hunters #ICE #DHS #FBI #doxxed #breach
October 18, 2025 at 2:48 PM
🚨 UPDATE Salesforce

Scattered Lapsus$ Hunters claim fresh victims via new leak site.

The merged cybercrime collective (LAPSUS$, ShinyHunters, Scattered Spider) has launched a new website to announce recent breaches and data dumps.

#ransomNews #ScatteredLapsus #CyberExtortion
October 3, 2025 at 12:21 PM
#JosephCox‬ @josephcox.bsky.social
‪
wrote about the seizure of #ScatteredLAPSUS$Hunters' site that was apparently going to dump data from #Salesforces customers including #Disney/Hulu, #FedEx, #Toyota, #UPS, #QANTUS more

#AUSPOL #Hacking #DarkWeb
Wrote about the seizure of Scattered LAPSUS$ Hunters' site that was apparently going to dump data from Salesforces customers including Disney/Hulu, FedEx, Toyota, UPS, more

www.404media.co/behind-the-b...
Behind the Blog: Sinkholes and Site Seizures
This week, we discuss a ransomware gang, book bans, and infrastructure.
www.404media.co
October 13, 2025 at 1:19 AM
Last week we have observed 190 events across 33 countries and attributed them to 34 ransomwares.
The top targeted country was #UnitedStates and the most targeted sector was #Construction.
The ransomware #ScatteredLAPSUS$Hunters has been busy with 42 new events (22%)!

Learn more: https://ecrime.ch/
October 6, 2025 at 12:52 PM
Feed: "DataBreaches.Net"
By: Dissent on Tuesday, January 6, 2026
Cyber Counterintelligence (CCI): Resecurity releases data on John Erin Binns (IRDev)
It may be a bit of an understatement to say that Resecurity has been up in the faces of ScatteredLapsus$Hunters and ShinyHunters.  Not only did they recently em
databreaches.net
January 7, 2026 at 5:24 AM
Feed: "DataBreaches.Net"
By: Dissent on Wednesday, January 7, 2026
NordVPN Hack Claim Firmly Refuted by NordVPN
This has not been a great week for hackers whose claims have been refuted. First, ScatteredLapsus$Hunters' claim about Resecurity was refuted , and now claims b
databreaches.net
January 7, 2026 at 5:23 AM
Feed: "DataBreaches.Net"
By: Dissent on Monday, January 5, 2026
Threat actors insisted that Resecurity’s honeypot was real data. We found no evidence that it was.
ScatteredLapsus$Hunters (SLH) welcomed the new year by announcing that they had hacked Resecurity and taken "everything," including: – All internal chats and lo
databreaches.net
January 6, 2026 at 4:03 AM
📌 Resecurity Releases Data on Threat Actor John Erin Binns (IRDev) Linked to ScatteredLapsus$Hunters and ShinyHunters https://www.cyberhub.blog/article/17781-resecurity-releases-data-on-threat-actor-john-erin-binns-irdev-linked-to-scatteredlapsushunters-and-shinyhunters
Resecurity Releases Data on Threat Actor John Erin Binns (IRDev) Linked to ScatteredLapsus$Hunters and ShinyHunters
Resecurity, a cybersecurity firm specializing in threat intelligence, has released data on John Erin Binns, also known as IRDev, a threat actor associated with groups such as ScatteredLapsus$Hunters and ShinyHunters. Previously, Resecurity successfully deployed a honeypot to gather intelligence on ScatteredLapsus$Hunters, providing law enforcement with details on an attempt to access synthetic data. The recent disclosure sheds light on Binns' activities, although specific technical details, exact dates, and concrete impact are not provided in the article. This information could potentially enhance the cybersecurity community's understanding of the tactics, techniques, and procedures (TTPs) employed by these threat actors. However, the lack of detailed technical information limits the immediate operational value of the disclosure. The collaboration between private cybersecurity firms and law enforcement is crucial for effective cyber crime prevention and prosecution. Cybersecurity professionals should remain vigilant and continue to monitor developments related to these threat actors to enhance their defensive strategies.
www.cyberhub.blog
January 8, 2026 at 8:40 PM
📌 NordVPN Firmly Denies Brute-Force Attack Claims, Highlighting the Importance of Verification in Cybersecurity https://www.cyberhub.blog/article/17725-nordvpn-firmly-denies-brute-force-attack-claims-highlighting-the-importance-of-verification-in-cybersecurity
NordVPN Firmly Denies Brute-Force Attack Claims, Highlighting the Importance of Verification in Cybersecurity
On January 6, 2026, a malicious actor using the pseudonym "1011" claimed to have compromised NordVPN through a brute-force attack. NordVPN has firmly denied these allegations, although they have not provided additional technical details about their security measures. This incident is part of a series of similar false claims, including a previous denial against the group "ScatteredLapsus$Hunters" regarding Resecurity. Importantly, there is no evidence of any breach, data leak, or concrete impact reported in the article. Brute-force attacks are a common method where attackers systematically check all possible passwords to gain access. If the claim were true, it would suggest potential vulnerabilities in NordVPN's security measures. However, given the lack of evidence and NordVPN's denial, the immediate technical implication is that their security measures may be robust enough to prevent such attacks. False claims of breaches can cause unnecessary panic and undermine trust in legitimate security services. This incident highlights the importance of verifying claims before accepting them as fact, especially in the cybersecurity field where misinformation can have serious consequences. For cybersecurity professionals, this underscores the need for thorough investigation and verification of breach claims. It also highlights the importance of transparent communication from companies about their security measures to maintain trust and credibility. In conclusion, while the claim by "1011" is serious, the lack of evidence and NordVPN's denial suggest that this may be another false claim in a series of similar incidents. Cybersecurity professionals should remain vigilant and demand evidence before accepting such claims as fact.
www.cyberhub.blog
January 7, 2026 at 1:40 PM
📌 Developing: Salesforce Data Leak Site Under Seizure, Indicates Government Intervention https://www.cyberhub.blog/article/14126-developing-salesforce-data-leak-site-under-seizure-indicates-government-intervention
Developing: Salesforce Data Leak Site Under Seizure, Indicates Government Intervention
The data leak site associated with Salesforce, breachforums[.]hn, appears to be undergoing seizure. Recent WHOIS data reveals that the domain's name servers have been updated to Cloudflare's infrastructure (hans.ns.cloudflare.com and surina.ns.cloudflare.com), a common indicator of law enforcement action. This suggests that authorities may be taking control of the domain to disrupt its operations or gather intelligence. The site is reportedly used by the group ScatteredLAPSUS$Hunters, which has been involved in data breaches. Notably, the corresponding onion site remains operational, indicating that while the clearnet presence is being targeted, the dark web operations continue unimpeded. This development highlights the ongoing cat-and-mouse game between law enforcement and cybercriminals. For cybersecurity professionals, this serves as a reminder of the importance of monitoring both clearnet and dark web activities for comprehensive threat intelligence. The situation is fluid, and further updates are expected as more information becomes available. Organizations should remain vigilant and ensure that their incident response plans are up to date. Continuous monitoring and threat intelligence sharing are crucial in staying ahead of such threats.
www.cyberhub.blog
October 8, 2025 at 11:20 AM
Hacking group #ScatteredLapsus$Hunters has said it is attempting to extort porn site Pornhub, after claiming to have stolen personal information belonging to the website’s premium members.

techcrunch.com/2025/12/16/h...
December 27, 2025 at 8:31 AM
Eurojust coordina 18 arresti per frode carte di credito da 300 milioni di euro; gruppi cyber si federano, Apache smentisce Akira e aziende subiscono costi record per cyberattacchi.

#ApacheOpenOffice #Cartedicredito #Eurojust #frode #ScatteredLapsus$Hunters
www.matricedigitale.it/2025/11/05/a...
November 5, 2025 at 4:24 PM
Scattered Lapsus$ Hunters offre ricompense Bitcoin per molestie a dirigenti, mentre ParkMobile risarcisce 22 milioni di utenti con crediti da 0,92 € dopo il breach del 2021.

#Bitcoin #Salesforce #ScatteredLapsus$Hunters #smishing
www.matricedigitale.it/2025/10/06/s...
October 6, 2025 at 5:09 PM
Domains used by notorious hacking group ShinyHunters for Salesforce hacks disrupted in FBI takedown | TechRadar www.techradar.com/pr... #cybersecurity #ShinyHunters #ScatteredLapsus$Hunters #domains #seized #Saleforce #Salesloft
Domains used by notorious hacking group ShinyHunters for Salesforce hacks disrupted in FBI takedown
Two domains were seized, but one returned quickly
www.techradar.com
October 14, 2025 at 2:22 PM