Categories: Cyber Security News

Researchers Reveal Links Among LAPSUS$, Scattered Spider, and ShinyHunters

Cybersecurity firm Resecurity has uncovered extensive evidence of collaboration and operational convergence among three of the most notorious English-speaking cybercrime groups: LAPSUS$, Scattered Spider, and ShinyHunters.

The research reveals these groups now function as part of a “loosely connected and highly adaptive cybercrime ecosystem” that has targeted Fortune 100 corporations and government agencies throughout 2023-2025.

Public service announcement

Joint Operations Signal Cybercrime Supergroup Formation

In August 2025, the groups explicitly combined their brands through a shared Telegram channel used to coordinate threats and market a new Ransomware-as-a-Service offering dubbed “shinysp1d3r.” Security researchers described the channel as “chaotic” before Telegram banned it.

ShinyHunters confirmed that Scattered Spider provided initial access to targets while handling data exfiltration operations, with LAPSUS$ members actively participating in coordinated campaigns targeting Salesforce and Snowflake environments.

All three groups are linked to “The Com,” a predominantly English-speaking cybercriminal ecosystem that operates as a youth movement, encompassing teens and twenty-somethings.

The FBI issued warnings about risks associated with joining such movements, noting their shared ideology and operational coordination capabilities.

The convergence extends beyond mere collaboration. Recent attacks have demonstrated identical tactics, techniques, and procedures (TTPs) across all three groups, including advanced social engineering capabilities such as voice phishing (vishing) and help desk impersonation.

LAPSUS$ pioneered SIM swapping and MFA bombing techniques now widely adopted by Scattered Spider and ShinyHunters to bypass multi-factor authentication systems.

High-profile victims include major airlines such as Qantas, WestJet, and Hawaiian Airlines, with attacks resulting in operational disruptions and flight cancellations.

Cyberattacks on airlines

In July 2025, ShinyHunters claimed responsibility for breaching Qantas customer data, affecting nearly 6 million individuals through sophisticated voice-phishing campaigns targeting Salesforce users.

The groups have also targeted retail giants, including Victoria’s Secret, which suffered a $10 million impact from a May 2025 attack, as well as luxury brands Cartier, Dior, and Adidas.

Telecommunications companies remain frequent targets, with AT&T paying approximately $370,000 in Bitcoin ransom following a Snowflake-related breach exposing call metadata for 110 million customers.

Cyberattacks on telecoms

Most concerning are recent claims of breaching law enforcement systems, including the FBI’s National Instant Criminal Background Check System (NICS) and the UK’s National Crime Agency portals.

While verification remains ongoing, Resecurity’s analysis suggests these represent escalatory responses to law enforcement actions against group members.

Despite announcing their “retirement” in September 2025, claiming they had “achieved their goals of exposing weaknesses in digital security,” Resecurity maintains skepticism about the sincerity of this announcement.

The firm has identified multiple previously undisclosed victims currently being extorted privately, suggesting the groups have shifted to discrete operations rather than ceasing activities entirely.

The fluid boundaries between these groups represent an advanced persistent threat requiring enhanced defensive measures and improved employee awareness of evolving social engineering tactics.

Find this Story Interesting! Follow us on Google News , LinkedIn and X to Get More Instant Updates

The post Researchers Reveal Links Among LAPSUS$, Scattered Spider, and ShinyHunters appeared first on Cyber Security News.

rssfeeds-admin

Recent Posts

New restaurants, tasting room fully open at Cherapa Place

March 16, 2026 All three new food and beverage options at Cherapa Place now are…

25 minutes ago

Multifamily occupancy trends down some with more construction ahead

March 16, 2026 Vacancy in the Sioux Falls multifamily market ticked up to start the…

26 minutes ago

Antisemitism’s Afterlives

Reviewed: On Antisemitism: A Word in HistoryMark MazowerPenguin Press, $29 In April 2024, six months…

31 minutes ago

Onchain infrastructure platform RadiusTech.xyz focuses on high-volume digital transactions

RadiusTech.xyz – Cloudflare customer – (United States)  Forward-looking developers use .xyz domains to build AI…

31 minutes ago

Enchanting Video Shows How Globes Were Made by Hand in 1955: The End of a 500-Year Tradition

The first globe—a spherical representation of our planet Earth—dates back to the Age of Discovery.…

41 minutes ago

New Jersey Adds 15 Towns To Film Ready Communities Program

The New Jersey Motion Picture and Television Commission announced Tuesday that 15 towns joined the…

48 minutes ago

This website uses cookies.