Threat Intelligence / Actor / Scattered LAPSUS$ Hunters
Scattered LAPSUS$ Hunters
As of 2026-07-31, Scattered LAPSUS$ Hunters is a threat actor tracked by Threadlinqs Intelligence across 10 threats spanning phishing, data breach, threat actor. ATT&CK coverage spans 89 techniques across 14 tactics in 10 of 10 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1566 (Phishing), T1213 (Data from Information Repositories).
ATT&CK techniques observed
- T1078 Valid Accounts — Initial Access — observed in 10 of 10 tracked threats
- T1566 Phishing — Initial Access — observed in 10 of 10 tracked threats
- T1213 Data from Information Repositories — Collection — observed in 9 of 10 tracked threats
- T1567 Exfiltration Over Web Service — Exfiltration — observed in 9 of 10 tracked threats
- T1199 Trusted Relationship — Initial Access — observed in 8 of 10 tracked threats
- T1528 Steal Application Access Token — Credential Access — observed in 8 of 10 tracked threats
- T1530 Data from Cloud Storage — Collection — observed in 8 of 10 tracked threats
- T1657 Financial Theft — Impact — observed in 8 of 10 tracked threats
- T1550 Use Alternate Authentication Material — Lateral Movement — observed in 7 of 10 tracked threats
- T1583 Acquire Infrastructure — Resource Development — observed in 7 of 10 tracked threats
- T1537 Transfer Data to Cloud Account — Exfiltration — observed in 6 of 10 tracked threats
- T1539 Steal Web Session Cookie — Credential Access — observed in 6 of 10 tracked threats
- T1552 Unsecured Credentials — Credential Access — observed in 6 of 10 tracked threats
- T1556 Modify Authentication Process — Credential Access — observed in 6 of 10 tracked threats
- T1588 Obtain Capabilities — Resource Development — observed in 6 of 10 tracked threats
Tracked threats
- Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys — HIGH
- Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted — HIGH
- Grafana Labs Source Code Theft via Stolen GitHub Access Token — CoinbaseCartel Extortion Campaign — HIGH
- ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026) — HIGH
- ShinyHunters Leaks 5.1 Million Panera Bread Customer Records — HIGH
- ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass — HIGH
- ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks — HIGH
- Panera Bread Data Breach - 5.1 Million Accounts Exposed — MEDIUM
- ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft — HIGH
- ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering — CRITICAL
Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →