The designation Scattered Lapsus$ Hunters concatenates three existing names: Scattered Spider, LAPSUS$ and ShinyHunters. Reporting describes the associated activity as combining social engineering and voice phishing capability with automated data extraction tooling.
A crew that names itself after three predecessors is making a claim about its own capability, and the claim is doing work for them.
Why The Naming Matters Operationally
Attribution language is load-bearing in this desk’s files. Saying an incident was carried out by a group implies a roster, a shared toolset and a pattern that predicts the next incident. When a name is a coalition brand rather than an organisation, each of those implications weakens.
We use a name where the leak site, the negotiation style and the technique match prior cases. Where only the name matches, we say "claimed by". A composite brand makes that distinction harder to apply and easier to get wrong.
The Brand Is Also An Extortion Instrument
Named victims in this cluster have included large technology, aviation, insurance and luxury-goods companies. That roster is itself leverage: a victim deciding whether to pay is weighing what happened to organisations it recognises.
Which puts reporting in an awkward position, and it is worth being explicit about it. Coverage of the victim list is legitimate and useful. It also supplies exactly the reputational pressure the extortion model depends on. We publish the pattern, name organisations that have confirmed, and do not reproduce leak-site rosters as fact.
Compiled from public reporting and vendor research, listed below. Group composition claims originate with the actors and with researchers interpreting them; we treat the coalition framing as reported rather than established. Corrections: corrections@forensicpost.com.