Back to blog

Blog Post

Salesforce Attack Developments: Scattered Spider and ShinyHunters Team Up

Share on social

Aug 22, 2025

Lorem ipsum

Table of contents

Share on social

Join the newsletter
Salesforce Attack Developments: Scattered Spider and ShinyHunters Team Up

[Salesforce Attack Developments]

In this blog series we spotlight one of the stories from our cybersecurity newsletter, Beacon.

The story of the ongoing targeting of Salesforce customers rolls on. After last week's attribution of the hacking campaign to ShinyHunters, this week the attacks took on a new dimension as both researchers and threat actors said that the group may be working in collaboration with another hacking collective: Scattered Spider.

Evidence for this unholy alliance included the emergence of several Telegram channels combining the groups' names (along with LAPSUS$, a group that made waves back in 2022 for data extortion and conflicts with other threat actors) to become: "Scattered LAPSUS$ Hunters".

A cascade of stolen data samples and extortion demands were posted referencing victims previously associated with ShinyHunters, including Victoria’s Secret, Qantas and Coca Cola.

Records of dark web forum personas suggest that actors associated with the groups may have been working together for over a year, while an alleged representative of ShinyHunters claimed that the groups have “always been the same”.

This development highlights the propensity for overlap between actors in an ever-shifting threat landscape, and the importance of tracking techniques, tactics and procedures used in campaigns rather than distinct group identities.

If you’d like the latest dark web news and insights delivered into your inbox every Thursday at 10am, sign up to the email version of Beacon.

Charlotte Rhodes

Author

Charlotte Rhodes

Global VP Marketing at Searchlight Cyber

Charlotte Rhodes is Global VP of Marketing at Searchlight Cyber, where she leads the company's marketing strategy across brand, content, demand generation, and communications. She has been instrumental in building Searchlight's profile as the category leader in Preemptive Threat Exposure Management (PTEM).

Related Blog Posts

August 13, 2026

Phishing and Takedown now managed entirely in Monitor

August 6, 2026

How to Measure Preemptive Threat Exposure Management (PTEM) Success

August 5, 2026

August 4th – This Week’s Top Cybersecurity and Dark Web Stories

July 31, 2026

How Does Preemptive Threat Exposure Management Improve Exposure Prioritization?

July 29, 2026

July 28th – This Week’s Top Cybersecurity and Dark Web Stories

July 24, 2026

Preemptive Threat Exposure Management: Frequently Asked Questions

Never miss a beat

Get all news and updates about Searchlight Cyber, directly in your inbox.

Subscribe
Please enter a valid email address.
Background Gradient