Cybersecurity researchers at Palo Alto Networks’ Unit 42 have observed a series of new developments linked to the notorious Scattered LAPSUS$ Hunters group, offering a glimpse into the shifting tactics of one of the most disruptive cybercriminal syndicates operating today.
The update follows Unit 42’s previous Golden Scale report, which focused on the group’s Salesforce data theft activity. Since early October 2025, analysts have continued to monitor a Telegram channel known as “SLSH 6.0 part 3,” where the threat actors have posted multiple statements outlining their recent activity and potential future plans.
Fallout from the Extortion Deadline
According to Unit 42, the group set a ransom payment deadline of 11:59 p.m. ET on 10 October 2025. After that deadline expired, news reports indicated that the actors leaked stolen data allegedly belonging to six companies across the aviation, energy and retail sectors.
The leaked information reportedly included personally identifiable information (PII) such as names, dates of birth, email addresses, phone numbers and frequent flyer numbers.
When Unit 42 attempted to access the group’s data leak site (DLS), researchers found a defacement message instead of any posted data, preventing confirmation of whether victim data remained listed.
On 11 October, a day after the deadline, the group claimed on Telegram that “nothing else will be leaked.” They added, “the things we have cannot be leaked for obvious reasons,” though Unit 42 said the meaning behind this remark remains unclear. The group could be referring to the heightened risk of law enforcement attention depending on the type or ownership of the stolen data.
Later the same day, the actors appeared to hint at a temporary pause in their activity, stating they might step away until the start of next year. However, in a subsequent post, they warned, “I promise you, you WILL feel our wrath,” suggesting further operations could resume in 2026.
Extortion-as-a-Service
Shortly before the payment deadline, on 10 October, Scattered LAPSUS$ Hunters announced plans to launch an “extortion-as-a-service” (EaaS) programme. Similar in structure to ransomware-as-a-service (RaaS) operations, the scheme would allow affiliates to carry out extortion campaigns — but without encrypting victims’ files.
Unit 42 noted that the shift away from encryption could be an attempt to evade law enforcement scrutiny, which has increasingly targeted ransomware operations.
Earlier in the month, on 5 October, the group advertised for insider access at organisations in multiple sectors, including call centres, gaming, hosting, software-as-a-service (SaaS) and telecommunications. Their recruitment post specifically targeted insiders in the US, UK, Australia, Canada and France.
Threat actors linked to a group known as “The Com” have previously made similar recruitment attempts, according to Unit 42’s May 2025 update on Muddled Libra (also known as Scattered Spider).
Possible Development of New Ransomware
On 4 October, the group also claimed to be developing new ransomware dubbed “SHINYSP1D3R.” The claim appears related to activity previously flagged by Falconfeeds in August 2025, though Unit 42 said it remains unclear whether the ransomware is in active development or was a false claim.
The clearnet version of the group’s data leak site is currently unavailable, and it remains unknown whether any of the listed victims paid a ransom. Unit 42 also noted uncertainty around whether the EaaS model will prove as profitable as the threat actors anticipate, given that it lacks the operational disruption caused by file encryption.
Recommended reading
- New Report Reveals Rising Threat of Open Source Malware
- Open Source AI Vital to Public Sector Tech Adoption, Says Think Tank
- Open-Source AI: The New Frontier for Developers
“It is not evident why the threat actors would potentially be interested in operating both an EaaS and a RaaS program, other than attempting to diversify their revenue streams,” Unit 42 said, adding that it will continue to monitor developments.
The report also warned that the theft and leakage of PII – including loyalty and frequent flyer data – could enable cybercriminals to commit identity theft and fraud, fuelling underground markets such as fake travel agencies advertised across Telegram and dark web forums.
Given the growing popularity of RaaS and the emerging EaaS model, Unit 42 urged organisations to develop new response playbooks tailored to data theft and extortion scenarios. These plans should include having third-party experts on standby to assist with negotiations, verification of stolen data, and related crisis management steps.
“If your organisation has been threatened with data theft extortion by Scattered LAPSUS$ Hunters or other cybercriminals,” the report concluded, “the Unit 42 Incident Response team is here and ready to support with either a suspected compromise or to reduce the risk via a proactive threat assessment.”





