# Scattered LAPSUS$ Hunters

> As of 2026-07-31, Scattered LAPSUS$ Hunters is a threat actor tracked by Threadlinqs Intelligence across 10 threats spanning phishing, data breach, threat actor. ATT&CK coverage spans 89 techniques across 14 tactics in 10 of 10 tracked threats. Most-observed techniques: T1078 (Valid Accounts), T1566 (Phishing), T1213 (Data from Information Repositories).

- **Tracked threats:** 10
- **Categories:** PHISHING, DATA_BREACH, THREAT_ACTOR, THREAT_INTEL, CAMPAIGN
- **As of:** 2026-07-31

## ATT&CK techniques observed

89 techniques observed across 10 of 10 tracked threats. Tactics: Credential Access (15), Resource Development (10), Stealth (formerly Defense Evasion) (10), Discovery (9), Initial Access (9), Impact (8).

- [T1078](https://attack.mitre.org/techniques/T1078/) Valid Accounts — Initial Access — observed in 10 of 10 tracked threats
- [T1566](https://attack.mitre.org/techniques/T1566/) Phishing — Initial Access — observed in 10 of 10 tracked threats
- [T1213](https://attack.mitre.org/techniques/T1213/) Data from Information Repositories — Collection — observed in 9 of 10 tracked threats
- [T1567](https://attack.mitre.org/techniques/T1567/) Exfiltration Over Web Service — Exfiltration — observed in 9 of 10 tracked threats
- [T1199](https://attack.mitre.org/techniques/T1199/) Trusted Relationship — Initial Access — observed in 8 of 10 tracked threats
- [T1528](https://attack.mitre.org/techniques/T1528/) Steal Application Access Token — Credential Access — observed in 8 of 10 tracked threats
- [T1530](https://attack.mitre.org/techniques/T1530/) Data from Cloud Storage — Collection — observed in 8 of 10 tracked threats
- [T1657](https://attack.mitre.org/techniques/T1657/) Financial Theft — Impact — observed in 8 of 10 tracked threats
- [T1550](https://attack.mitre.org/techniques/T1550/) Use Alternate Authentication Material — Lateral Movement — observed in 7 of 10 tracked threats
- [T1583](https://attack.mitre.org/techniques/T1583/) Acquire Infrastructure — Resource Development — observed in 7 of 10 tracked threats
- [T1537](https://attack.mitre.org/techniques/T1537/) Transfer Data to Cloud Account — Exfiltration — observed in 6 of 10 tracked threats
- [T1539](https://attack.mitre.org/techniques/T1539/) Steal Web Session Cookie — Credential Access — observed in 6 of 10 tracked threats
- [T1552](https://attack.mitre.org/techniques/T1552/) Unsecured Credentials — Credential Access — observed in 6 of 10 tracked threats
- [T1556](https://attack.mitre.org/techniques/T1556/) Modify Authentication Process — Credential Access — observed in 6 of 10 tracked threats
- [T1588](https://attack.mitre.org/techniques/T1588/) Obtain Capabilities — Resource Development — observed in 6 of 10 tracked threats

## Tracked threats

- [Device Code Phishing: OAuth Device Authorization Grant Abuse Bypasses All MFA Forms, Including Passkeys](https://intel.threadlinqs.com/threat/TL-2026-1793) — HIGH
- [Infinite Campus Salesforce Breach by ShinyHunters / UNC6040 — 137,100 K-12 School Staff Accounts Exfiltrated and Extorted](https://intel.threadlinqs.com/threat/TL-2026-0804) — HIGH
- [Grafana Labs Source Code Theft via Stolen GitHub Access Token — CoinbaseCartel Extortion Campaign](https://intel.threadlinqs.com/threat/TL-2026-0527) — HIGH
- [ShinyHunters Mass Defacement of Canvas LMS — Instructure Re-Breach Extortion Campaign Affecting ~330 Educational Institutions (May 2026)](https://intel.threadlinqs.com/threat/TL-2026-0482) — HIGH
- [ShinyHunters Leaks 5.1 Million Panera Bread Customer Records](https://intel.threadlinqs.com/threat/TL-2026-0055) — HIGH
- [ShinyHunters Evolves TTPs: Vishing and Login Harvesting for SSO/MFA Bypass](https://intel.threadlinqs.com/threat/TL-2026-0054) — HIGH
- [ShinyHunters-Branded Extortion Campaign Expands with Vishing & SSO Attacks](https://intel.threadlinqs.com/threat/TL-2026-0045) — HIGH
- [Panera Bread Data Breach - 5.1 Million Accounts Exposed](https://intel.threadlinqs.com/threat/TL-2026-0031) — MEDIUM
- [ShinyHunters Extortion Campaign - Evolved Vishing and SSO Credential Theft](https://intel.threadlinqs.com/threat/TL-2026-0030) — HIGH
- [ShinyHunters SSO Vishing Campaign - Cloud Data Theft via Social Engineering](https://intel.threadlinqs.com/threat/TL-2026-0013) — CRITICAL

## Full data

Infrastructure, IOC values and detection queries (Splunk SPL / Microsoft KQL / Sigma) require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/actor/Scattered%20LAPSUS%24%20Hunters
