Description

A new cybercrime syndicate called Scattered Lapsus$ Hunters (SLSH), or SP1D3R HUNTERS, has taken credit for a huge data breach of Salesforce customer environments. The syndicate allegedly took more than one billion Salesforce records in two large-scale extortion campaigns, which was one of the largest data heists in recent history. The threat actors, who are a coalition of LAPSUS$ members, ShinyHunters (Bling Libra), and Scattered Spider (Muddled Libra) members, initiated a data leak site (DLS) on October 3, 2025, with 39 impacted global entities. In spite of FBI domain seizures related to their activities, the group is still active through darknet platforms. The attack highlights an essential change in cybercrime patterns from ransomware to extortion-as-a-service (EaaS) activities. Rather than encrypting infrastructure, the attackers steal sensitive information and extort ransom payments, frequently gaining a 25–30% cut from collaborating threat actors. Retail and hospitality industries were among the primary targets because of their dependence on Salesforce CRM systems as well as the high dollar content of their customer data. The attack also has significant threats such as identity theft, fraud, and loss of consumer confidence, particularly during busy periods of business. Organizations need to embrace Zero Trust architecture, automate credential scanning, and conditionally enforce access controls in order to contain similar threats. Information Sharing and Analysis Centers (ISACs) and improved incident response efforts are needed to counter this new breed of coordinated cyber extortion networks.