Desk live·
ForensicPost
Cloud/Actors/File 26-0625

Scattered Lapsus$ Hunters Name Combines Three Separate Crews

Scattered Lapsus$ Hunters combines names from three separate crews. The naming is a marketing decision, and it creates a real problem for anyone trying to attribute an incident to a roster.

Constructed geometry · not a chart of case data
TargetMultiple organisations
ActorScattered Lapsus$ Hunters
S. Rosler10 min readConfidence: medium2 sources reviewed

The designation Scattered Lapsus$ Hunters concatenates three existing names: Scattered Spider, LAPSUS$ and ShinyHunters. Reporting describes the associated activity as combining social engineering and voice phishing capability with automated data extraction tooling.

A crew that names itself after three predecessors is making a claim about its own capability, and the claim is doing work for them.

Why The Naming Matters Operationally

Attribution language is load-bearing in this desk’s files. Saying an incident was carried out by a group implies a roster, a shared toolset and a pattern that predicts the next incident. When a name is a coalition brand rather than an organisation, each of those implications weakens.

We use a name where the leak site, the negotiation style and the technique match prior cases. Where only the name matches, we say "claimed by". A composite brand makes that distinction harder to apply and easier to get wrong.

The Brand Is Also An Extortion Instrument

Named victims in this cluster have included large technology, aviation, insurance and luxury-goods companies. That roster is itself leverage: a victim deciding whether to pay is weighing what happened to organisations it recognises.

Which puts reporting in an awkward position, and it is worth being explicit about it. Coverage of the victim list is legitimate and useful. It also supplies exactly the reputational pressure the extortion model depends on. We publish the pattern, name organisations that have confirmed, and do not reproduce leak-site rosters as fact.

How we reported this

Compiled from public reporting and vendor research, listed below. Group composition claims originate with the actors and with researchers interpreting them; we treat the coalition framing as reported rather than established. Corrections: corrections@forensicpost.com.

Sources
  1. Salesforce extortion accelerates with new leak siteUpGuard
  2. Threat spotlight: ShinyHunters data breach targets Salesforce amid Scattered Spider collaborationReliaQuest
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary