home.social

#scatteredspider — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #scatteredspider, aggregated by home.social.

  1. NEW: When “Goodbye” isn’t the end: Scattered LAPSUS$ Hunters hack on

    Others seem to have interpreted their "goodbye" message differently than I had. Were they lying or did people just not understand a significant statement in their message?

    And while headlines focus on them hitting a bank, I think we need to take a closer look at their attacks on the aviation sector.

    databreaches.net/2025/09/21/wh

    #databreach #ScatteredSpider #ShinyHunters #LAPSUS$ #CollinsAerospace #airlines #airports

  2. One Arrested in Sophisticated Cyber Crime:
    lvmpd.com/Home/Components/News

    h/t, casino.org/news/teen-suspect-s

    Las Vegas casinos not named in the press release, but sure sounds like Scattered Spider attacks.

    As a reminder: Caesars was hit in August 2023 and MGM was hit in September 2023 and this teen is charged with hitting multiple casinos between August and October 2023.

    #databreach #cybersecurity #MGM #Caesars #arrest #ScatteredSpider

  3. "The ShinyHunters extortion group claims to have stolen over 1.5 billion Salesforce records from 760 companies using compromised Salesloft Drift OAuth tokens.

    [...]

    In March, one of the threat actors breached Salesloft's GitHub repository, which contained the private source code for the company.

    ShinyHunters told BleepingComputer that the threat actors used the TruffleHog security tool to scan the source code for secrets, which resulted in the finding of OAuth tokens for the Salesloft Drift and the Drift Email platforms."

    Read more of Lawrence Abrams' great reporting on Bleeping Computer:
    bleepingcomputer.com/news/secu

    #Salesforce #Salesloft #Oauth #Drift #databreach #ransom #ShinyyHunters #ScatteredSpider #LAPSUS$ #UNC6040 #UNC6395