Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
third-party-vendor-breachvendor-distribution-compromiseunderground-data-leakcybercrime-service-ecosystem

Scattered LAPSUS$ Hunters Target Salesforce via Gainsight Supply Chain Attack

Updated 3mo agoFirst seen Nov 26, 20252 sources

The cybercriminal alliance known as Scattered LAPSUS$ Hunters (SLSH), an amalgamation of groups including Scattered Spider, LAPSUS$, and ShinyHunters, has intensified its campaign of data theft and extortion against major corporations. In November 2025, Salesforce detected unusual activity involving Gainsight-published applications, leading to the revocation of access tokens and removal of affected apps from its AppExchange. Salesforce determined that the incident was not due to a vulnerability in its platform, but rather unauthorized access to customer data through compromised app connections. The breach was traced back to a supply chain attack on Salesloft Drift in August 2025, which enabled attackers to obtain secrets used to access additional Salesforce instances. Gainsight confirmed that stolen OAuth tokens were used in the attack, and indicators of compromise were shared with affected customers.

SLSH has leveraged this access to threaten public data leaks and extort both Salesforce and its customers, with a new extortion portal listing dozens of victim companies, including Toyota, FedEx, Disney/Hulu, and UPS. The group has also escalated its tactics by openly recruiting insiders from large organizations, offering rewards for internal access to facilitate further breaches. Recent reports indicate that SLSH's activities are coordinated through Telegram channels, and the group has been linked to high-profile incidents involving both data theft and attempted insider recruitment. Security advisories and ongoing investigations highlight the persistent threat posed by SLSH and the importance of monitoring supply chain risks and insider threats.

Share:
Scattered LAPSUS$ Hunters Target Salesforce via Gainsight Supply Chain Attack
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

13 events from the most recent confirmed update back to the earliest known activity.

13 EVENTS
Nov 26, 20257mo ago

Law enforcement scrutiny of SLSH and BreachForums becomes public

Reporting indicated that the FBI had targeted BreachForums and was aware of SLSH's activities, highlighting ongoing law-enforcement attention to the group's ecosystem.

Researchers identify 'Rey' as Saif Al-Din Khader

Operational security mistakes exposed the identity of SLSH technical operator 'Rey,' who was identified as teenager Saif Al-Din Khader from Amman, Jordan.

Plans emerge for Linux and ESXi versions of ShinySp1d3r

Researchers reported that the group intends to expand ShinySp1d3r beyond Windows with planned Linux and ESXi variants, signaling broader targeting ambitions.

SLSH launches ShinySp1d3r ransomware-as-a-service

The alliance introduced its own ransomware-as-a-service operation, ShinySp1d3r, initially for Windows, after previously relying on other affiliates' ransomware tooling.

SLSH threatens to leak stolen data unless ransoms are paid

After obtaining victim data, SLSH warned organizations that stolen information would be published unless ransom demands were met.

Bling Libra claims access to 285 more Salesforce instances

The threat group Bling Libra, also known as ShinyHunters, claimed it had obtained access to 285 additional Salesforce instances, indicating broader compromise and follow-on extortion potential.

Gainsight suspends SaaS connections as a precaution

In response to the incident, Gainsight suspended connections to other SaaS platforms to limit further risk while the compromise was being addressed.

Supply-chain breach traced to Salesloft Drift integration

Investigation linked the Salesforce-related compromise to a supply-chain attack involving Salesloft Drift, expanding the scope beyond a direct single-platform intrusion.

Salesforce detects unusual activity tied to Gainsight apps

Salesforce identified unusual activity involving Gainsight-published applications, prompting revocation of tokens and customer notifications about the incident.

Former CrowdStrike employee reportedly paid for internal access

SLSH recently succeeded in paying a former CrowdStrike employee in exchange for internal access, marking a concrete insider-recruitment success for the group.

Jan 1, 20251y ago

SLSH begins recruiting corporate insiders across industries

During 2025, the group actively sought insiders in sectors including retail and hospitality to facilitate intrusions and data theft.

SLSH conducts 2025 extortion campaign against major companies

Throughout 2025, SLSH used social engineering, including voice phishing, to compromise Salesforce portals and steal data from companies including Toyota, FedEx, Disney/Hulu, and UPS, threatening leaks unless ransoms were paid.

SLSH resumes operations after a brief hiatus

The Scattered LAPSUS$ Hunters alliance resumed activity in 2025, returning to data theft, extortion, and insider-recruitment operations against organizations.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

42 LINKEDOpen in app
Malware
2 linked
Organizations
37 linked
SalesforceScattered Lapsus$ HuntersCrowdStrikefbiZendeskBleepingComputerEuropolLapsus$The Walt Disney CompanyFedexRoyal Jordanian AirlinesFlashpointPalo Alto NetworksSchneider ElectricDriftUnited Parcel ServiceHubspotShinySp1d3rToyota Motor CorporationBling LibraQilinHellcatRansomHubGainsightIntel 471Cyb3r Drag0nz TeamMicrosoft CorporationDragonForceShinyHuntersSentinelOneTelefónicaALPHV/BlackCatU.S. Centers for Disease Control and PreventionScattered SpiderBreachForumsOperationEndgameOrangeRomania
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Scattered LAPSUS$ Hunters Target Salesforce via Gainsight Supply Chain Attack | Mallory