Threat Intelligence / Actor / Scattered LAPSUS$ Hunters

Scattered LAPSUS$ Hunters

As of 2026-07-31, Scattered LAPSUS$ Hunters is a threat actor tracked by Threadlinqs Intelligence across 10 threats spanning phishing, data breach, threat actor. ATT&CK coverage spans 89 techniques across 14 tactics in 10 of 10 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1566 (Phishing), T1213 (Data from Information Repositories).

10 tracked threat(s) · Categories: PHISHING, DATA_BREACH, THREAT_ACTOR, THREAT_INTEL, CAMPAIGN

ATT&CK techniques observed

89 techniques observed across 10 of 10 tracked threats · Credential Access (15), Resource Development (10), Stealth (formerly Defense Evasion) (10), Discovery (9), Initial Access (9), Impact (8)

Tracked threats

Full actor intelligence — infrastructure, IOCs, detection coverage and operator fingerprints — is available via the Threadlinqs MCP server (Purple tier). View plans →

Threadlinqs Intelligence