SLSH Extortion Group - Swatting and Executive Harassment Tactics — Threadlinqs Intelligence
As of 2026-05-30, SLSH Extortion Group - Swatting and Executive Harassment Tactics is a high-severity threat intel threat attributed to Scattered Lapsus ShinyHunters (United States), tracked by Threadlinqs Intelligence with 6 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 35 indicators of compromise.
Threat ID: TL-2026-0035 · Severity: HIGH · CVSS: 8.5 · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Scattered Lapsus ShinyHunters · United States · FINANCIAL
SLSH is an extortion group operating within 'The Com' — a distributed cybercriminal social network spanning Telegram and Discord — that combines traditional cyber intrusion techniques (SIM swapping,
SLSH operates at the intersection of cybercrime and physical violence — a disturbing evolution in the threat landscape where digital attacks are amplified by real-world intimidation.
**The Com Ecosystem:**
The Com is a loosely organized archipelago of crime-focused chat communities across Telegram and Discord that functions as a distributed cybercriminal social network. Key characteristics:
- Members are predominantly young, Western (US/UK/Canada/Australia), English-speaking
- Facilitates instant collaboration between different criminal cliques
- Status-driven: members constantly compete over exploits, stolen cryptocurrency holdings
- Disputes frequently escalate to physical violence (assaults, firebombings, kidnapping)
- Overlapping membership between cybercrime groups and harm/extortion communities
- Groups include: Scattered Spider, LAPSUS$, Beige Group, ViLE, 764, CVLT, Court, Leak Society
**SLSH Extortion Methodology:**
1. **Initial Breach**: Social engineering (vishing — voice phishing of corporate helpdesks), SIM swapping (hijacking employee phone numbers to intercept MFA), credential purchase from darknet markets, targeting cloud services with weak authentication (Snowflake-style attacks)
2. **Data Theft**: Once inside corporate networks, exfiltrate sensitive data including customer PII, financial records, executive communications, board meeting minutes, M&A data
3. **Initial Extortion Demand**: Contact victim organization privately demanding cryptocurrency ransom in exchange for not leaking/selling stolen data
4. **Escalation — Executive Targeting**: When organizations refuse to pay or involve law enforcement:
- **Swatting**: File false police reports (bomb threats, hostage situations, active shooter) at executives' home addresses, triggering armed police response. Has caused deaths (60-year-old grandfather killed in 2020 swatting incident)
- **Doxing**: Publish executives' home addresses, family members' information, children's schools, daily routines on criminal forums
- **Physical Threats**: Send threatening letters, packages, or hire individuals for physical confrontation ('brickings, firebombings, shootings for hire')
- **Harassment Campaigns**: Flood executives' phones with calls, send messages to family members, post on social media
- **AI-Generated Harassment**: Use AI to create fake nude photos of targets (documented by Mandiant in Snowflake investigation), deepfake audio for impersonation
5. **Monetization**: Sell stolen data on cybercrime forums regardless of ransom payment, trade access to compromised networks, sell doxing services on removal-for-payment forums
**Connection to Major Incidents:**
- **MGM Resorts (2023)**: Scattered Spider (Com member 'Holy'/Vsphere) social engineered MGM helpdesk, partnered with ALPHV/BlackCat ransomware. The 17-year-old British attacker was also active in harm communities targeting children.
- **Snowflake Breaches (2024)**: UNC5537 (including Com member 'Judische'/Waifu) stole data from 160+ organizations including AT&T (110M records), TicketMaster, Santander. Made death threats against Mandiant researchers, created AI-generated fake nude photos to harass investigators.
- **T-Mobile (2021)**: Beige Group member John Erin Binns breached T-Mobile (76.6M customers). Currently in Turkish prison fighting extradition.
- **GoDaddy (2020)**: Beige Group tricked employee into installing malware, redirected crypto platform traffic.
- **ViLE (2024)**: Members hacked DEA portal accessing 16 federal databases, used fraudulent emergency data requests to dox targets, operated pay-to-remove doxing forum.
**The Violence Escalation:**
KrebsOnSecurity documented 'Violence as a Service' — cybercriminals hiring people to carry out physical attacks on rivals and targets:
- Firing handguns into homes
- Molotov cocktail attacks on residences
- Kidnapping and physical assault (crypto mugging)
- Swatting resulting in death
- Coerced self-harm in minors
This represents a
Target sectors: All Sectors, Hospitality, Technology, Finance, Telecommunications, Cloud Services
Target regions: Global, North America, Europe
Detections & IOCs
As of 2026-07-28, this threat has 6 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 35 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1589, T1591, T1588, T1566, T1078, T1204, T1098, T1621, T1557, T1552