SLSH Extortion Group - Swatting and Executive Harassment Tactics
SLSH Extortion Group (TL-2026-0035), also tracked as SLSH, is a high-severity tracked intrusion set scored CVSS 8.5, first published 2026-02-03. It is attributed to Scattered Lapsus ShinyHunters (United States) with high confidence, affects N/A Enterprise Organizations, maps to 19 MITRE ATT&CK techniques (T1005, T1078, T1098), and is covered by 6 detection rules and 35 indicators of compromise.
Key facts for TL-2026-0035
- Threat ID
- TL-2026-0035
- Also known as
- SLSH, Scattered Lapsus, ShinyHunters, Scattered Spider adjacent
- Severity
- HIGH
- CVSS
- 8.5 (N/A - Threat Actor Profile)
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-02-03
- Last reviewed
- 2026-02-03
- Attribution
- Scattered Lapsus ShinyHunters
- Attribution confidence
- HIGH
- Nation-state nexus
- United States
- Motivation
- FINANCIAL
- Target sectors
- All Sectors, Hospitality, Technology, Finance, Telecommunications, Cloud Services
- Target regions
- Global, North America, Europe
- Detection rules
- 6
- Indicators of compromise
- 35
SLSH is an extortion group operating within 'The Com' — a distributed cybercriminal social network spanning Telegram and Discord — that combines traditional cyber intrusion techniques (SIM swapping, social engineering, credential theft) with real-world physical intimidation tactics including swatting, executive harassment, physical surveillance, and threats of violence to coerce ransom payments from corporate victims. SLSH represents the convergence of cybercrime and physical violence ('Violence as a Service'), where data breaches are weaponized not just for financial extortion but as leverage for swatting campaigns against corporate executives, board members, and their families. The group operates alongside and overlaps with other Com groups including Scattered Spider (ALPHV/BlackCat affiliate, MGM hack), LAPSUS$, Beige Group, ViLE, and UNC5537 (Snowflake breaches). Tactics include: breaching corporate networks via social engineering and vishing, stealing sensitive data, demanding ransom, and when payment is refused, escalating to swatting attacks (fake hostage/bomb threats to executives' home addresses), doxing executives' families, sending physical threats, and in extreme cases commissioning real-world violence. FBI and international law enforcement have documented multiple arrests related to these groups, but the decentralized nature of The Com makes permanent disruption difficult.
How SLSH Extortion Group works
SLSH operates at the intersection of cybercrime and physical violence — a disturbing evolution in the threat landscape where digital attacks are amplified by real-world intimidation.
**The Com Ecosystem:**
The Com is a loosely organized archipelago of crime-focused chat communities across Telegram and Discord that functions as a distributed cybercriminal social network. Key characteristics: - Members are predominantly young, Western (US/UK/Canada/Australia), English-speaking - Facilitates instant collaboration between different criminal cliques - Status-driven: members constantly compete over exploits, stolen cryptocurrency holdings - Disputes frequently escalate to physical violence (assaults, firebombings, kidnapping) - Overlapping membership between cybercrime groups and harm/extortion communities - Groups include: Scattered Spider, LAPSUS$, Beige Group, ViLE, 764, CVLT, Court, Leak Society
**SLSH Extortion Methodology:**
1. **Initial Breach**: Social engineering (vishing — voice phishing of corporate helpdesks), SIM swapping (hijacking employee phone numbers to intercept MFA), credential purchase from darknet markets, targeting cloud services with weak authentication (Snowflake-style attacks)
2. **Data Theft**: Once inside corporate networks, exfiltrate sensitive data including customer PII, financial records, executive communications, board meeting minutes, M&A data
3. **Initial Extortion Demand**: Contact victim organization privately demanding cryptocurrency ransom in exchange for not leaking/selling stolen data
4. **Escalation — Executive Targeting**: When organizations refuse to pay or involve law enforcement: - **Swatting**: File false police reports (bomb threats, hostage situations, active shooter) at executives' home addresses, triggering armed police response. Has caused deaths (60-year-old grandfather killed in 2020 swatting incident) - **Doxing**: Publish executives' home addresses, family members' information, children's schools, daily routines on criminal forums - **Physical Threats**: Send threatening letters, packages, or hire individuals for physical confrontation ('brickings, firebombings, shootings for hire') - **Harassment Campaigns**: Flood executives' phones with calls, send messages to family members, post on social media - **AI-Generated Harassment**: Use AI to create fake nude photos of targets (documented by Mandiant in Snowflake investigation), deepfake audio for impersonation
5. **Monetization**: Sell stolen data on cybercrime forums regardless of ransom payment, trade access to compromised networks, sell doxing services on removal-for-payment forums
**Connection to Major Incidents:**
- **MGM Resorts (2023)**: Scattered Spider (Com member 'Holy'/Vsphere) social engineered MGM helpdesk, partnered with ALPHV/BlackCat ransomware. The 17-year-old British attacker was also active in harm communities targeting children. - **Snowflake Breaches (2024)**: UNC5537 (including Com member 'Judische'/Waifu) stole data from 160+ organizations including AT&T (110M records), TicketMaster, Santander. Made death threats against Mandiant researchers, created AI-generated fake nude photos to harass investigators. - **T-Mobile (2021)**: Beige Group member John Erin Binns breached T-Mobile (76.6M customers). Currently in Turkish prison fighting extradition. - **GoDaddy (2020)**: Beige Group tricked employee into installing malware, redirected crypto platform traffic. - **ViLE (2024)**: Members hacked DEA portal accessing 16 federal databases, used fraudulent emergency data requests to dox targets, operated pay-to-remove doxing forum.
**The Violence Escalation:**
KrebsOnSecurity documented 'Violence as a Service' — cybercriminals hiring people to carry out physical attacks on rivals and targets: - Firing handguns into homes - Molotov cocktail attacks on residences - Kidnapping and physical assault (crypto mugging) - Swatting resulting in death - Coerced self-harm in minors
This represents a fundamental shift in the threat model: cybersecurity incidents now carry physical safety risks for executives and their families.
MITRE ATT&CK techniques used in TL-2026-0035
collection
T1005 Data from Local System; T1530 Data from Cloud Storage
defense-evasion
persistence
execution
impact
T1485 Data Destruction; T1486 Data Encrypted for Impact; T1657 Financial Theft
discovery
credential-access
T1528 Steal Application Access Token; T1552 Unsecured Credentials; T1557 Adversary-in-the-Middle; T1621 Multi-Factor Authentication Request Generation
initial-access
exfiltration
T1567 Exfiltration Over Web Service
resource-development
reconnaissance
T1589 Gather Victim Identity Information; T1591 Gather Victim Org Information; T1596 Search Open Technical Databases
Affected products and versions in SLSH Extortion Group
- N/A — Enterprise Organizations
Vulnerable versions: All organizations with SSO/cloud infrastructure
Remediation for SLSH Extortion Group
Immediate actions
- Implement mandatory callback verification for ALL MFA reset requests
- Use employee directory for callbacks - never caller-provided numbers
- Require manager approval for MFA changes
- Brief executives on swatting risks and notify local law enforcement preemptively
- Establish media response plan for breach disclosure scenarios
Workarounds
- Require in-person verification for MFA resets
- Implement secondary verification channel (video call with known manager)
- Disable telephonic MFA reset entirely if possible
Longer-term hardening
- Deploy phishing-resistant MFA (FIDO2/hardware keys)
- Train help desk extensively on vishing recognition
- Implement time delays between MFA reset and new device enrollment
- Create executive protection protocols for cyber incidents
- Establish relationships with law enforcement cyber units
Timeline of SLSH Extortion Group
- KrebsOnSecurity documents wave of voice phishing (vishing) attacks targeting corporate VPN credentials during COVID-19 work-from-home. Beige Group members use vishing to breach corporate networks. GoDaddy employee tricked into installing malware, enabling cryptocurrency platform traffic redirection. Source: https://krebsonsecurity.com/2020/08/voice-phishers-targeting-corporate-vpns/
- KrebsOnSecurity publishes 'Violence as a Service' documenting cybercriminals hiring people for physical attacks: handgun shootings, Molotov cocktails, kidnapping. 21-year-old arrested for stalking in connection with physical attack schemes. Swatting death of 60-year-old grandfather leads to 5-year prison sentence for perpetrator. Source: https://krebsonsecurity.com/2022/09/violence-as-a-service-brickings-firebombings-shootings-for-hire/
- Scattered Spider (Com members) partners with ALPHV/BlackCat to breach MGM Resorts, shutting down Las Vegas casinos. Initial access via social engineering of MGM helpdesk. 17-year-old UK member ('Holy'/Vsphere, formerly LAPSUS$) also active in harm communities targeting children. CrowdStrike names and tracks the group. Source: https://krebsonsecurity.com/2024/09/the-dark-nexus-between-harm-groups-and-the-com/
- UNC5537 (Com members including 'Judische'/Waifu) begins breaching 160+ Snowflake customers including AT&T (110M records), TicketMaster, Santander. Victims extorted with ransom demands. Group makes death threats against Mandiant researchers and creates AI-generated fake nude photos to harass investigators. Source: https://cloud.google.com/blog/topics/threat-intelligence/unc5537-snowflake-data-theft-extortion
- Two ViLE members (Sagar 'Weep' Singh, 20, and Nicholas 'Convict' Ceraolo, 25) plead guilty to hacking DEA portal accessing 16 federal databases. Used fraudulent emergency data requests to dox targets. Operated pay-to-remove doxing forum. Co-conspirator 'Kayte' administered forum from Australia. Source: https://www.justice.gov/usao-edny/pr/two-men-plead-guilty-computer-intrusion-and-aggravated-identity-theft-hacking-federal
- SLSH extortion group escalates executive harassment tactics: combining data breach extortion with systematic swatting of C-suite executives and board members who refuse payment. AI-generated deepfakes used for harassment. Physical surveillance of executive residences documented. Multiple organizations report coordinated swatting + data leak campaigns.
- As of 2026-05-29, SLSH (Scattered Lapsus ShinyHunters) is firmly ACTIVE: in May 2026 it breached Instructure/Canvas (~3.65TB, ~275M people) and extorted UPenn with a PAY-OR-LEAK deadline, after a Q1 spree (Grubhub, Panera, Wynn, Odido). Arrests in France, Canada, Turkey, Finland and an FBI site seizure failed to disrupt the decentralized group, whose swatting/executive-harassment playbook continues per Krebs and Mandiant.
Sources cited for SLSH Extortion Group
- KrebsOnSecurity — The Dark Nexus Between Harm Groups and The Com
- KrebsOnSecurity — Violence as a Service
- Wired — Inside the Com Child Predator Networks
- DOJ — ViLE Members Plead Guilty to DEA Portal Hack
- CrowdStrike — Scattered Spider Profile
- Mandiant — UNC5537 Snowflake Data Theft
- RCMP — Warning About Violent Online Groups Targeting Youth
- West Midlands Police — MGM Hack Arrest
Threats related to SLSH Extortion Group
Detection coverage for TL-2026-0035
As of 2026-02-03, Threadlinqs Intelligence publishes 6 detection rule(s) for TL-2026-0035 across Splunk SPL, Microsoft KQL and Sigma, covering 35 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.