News: 1759765318

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Scattered Lapsus$ Hunters offering $10 in Bitcoin to 'endlessly harass' execs

(2025/10/06)


Scattered Lapsus$ Hunters has launched an unusual crowdsourced extortion scheme, offering $10 in Bitcoin to anyone willing to help pressure their alleged victims into paying ransoms.

The cybercrime collective is encouraging followers to email senior executives at organizations it claims to have breached, urging them to pay up and avoid publicity about the group's new data leak site.

Those who contact executives through personal email accounts will receive higher rewards, and participants who perform "an exceptionally well job"

sic

may be considered for "a much larger sum," according to the group's announcement.

[1]

Scattered Lapsus$ Hunters can't spell

The poor grammar and spelling errors throughout their communications —including misspelling "negotiate" as "negociate" — cast doubt on claims that the group comprises native English speakers.

The crime group announced the initiative via Telegram, complete with an instructions document that contained the contact details of executives they would like their audience to pressure on its behalf.

[2]

The method of outsourcing extortion attempts is novel for cybercriminals, and perhaps necessary, given the number of organizations allegedly caught up in a breach, which stands at 39. With entire C-suites to contact, that's a lot of emailing.

[3]

[4]

"You have permission to endlessly harass these executives till they comply with us," the group wrote. "When we tell you stop emailing a company or number of executives emails, you are to stop emailing them. This will be centralized and well operated."

On its new [5]data leak site , Scattered Lapsus$ Hunters listed the alleged victims – all supposedly having their data stolen via an intrusion at Salesforce – and gave the CRM giant a deadline of October 10 to come up with the money the criminals are after.

[6]

"If Salesforce does not engage with us to resolve this, we will completely target each and every indiviual

sic

customers of theirs listed below, failure to comply will result in massive consequences," its data leak site reads.

"If you are listed below we advise you to take every action to protect yourselves and reach out to us to resolve this. Do not be mistaken that your SaaS provider will protect all of you, they won't. Don't be the next headline, make the correct decision and reach out."

When The Register [7]asked Salesforce about the alleged intrusion on October 3, we were directed to its advisory published the day before, which stated that it believes the alleged victims it posted online related to either past attacks or "unsubstantiated incidents."

[8]Clop crew hits Oracle E-Business Suite users with fresh zero-day

[9]'Retired' cybercrime group demands ransom not to leak 1B Salesforce records

[10]Workers fear for their jobs as JLR's latest shutdown extended

[11]Car giant Stellantis says customer data nicked after partner vendor pwned

"At this time, there is no indication that the Salesforce platform has been compromised, nor is this activity related to any known vulnerability in our technology."

It sounds like a classic case of cybercriminals misattributing their attacks to intensify the notoriety they so often crave.

[12]

As confirmed by Google Threat Intelligence Group, the attack stemmed from [13]Salesloft Drift , a Salesforce integration that had its OAuth tokens abused, allowing attackers to access victims' CRM setups.

Google and Salesforce notified potentially affected organizations before Scattered Lapsus$ Hunters' [14]data leak site went live on Friday.

The Register contacted Scattered Lapsus$ Hunters about the $10 idea and how many people had taken them up on it thus far.

It told us on Monday that it had "practically paid out over $1,000 at this point," but by now, Reg readers should know not to trust the word of a cybercriminal.

For one, just days before launching their new website, the group claimed to be retiring, but appears to be doing nothing of the sort.

The group also keeps reviving Telegram channels to maintain their audience, despite these channels being rapidly shut down due to the "gobbledygook and often racist bile" for which members are known.

It comes amid a backdrop of law enforcement cuffing alleged members of the crime gang, both in the [15]UK and [16]US , which by Scattered Lapsus$ Hunters' own admission led to the decision to "retire," albeit only for a few days. ®

Get our [17]Tech Resources



[1] https://regmedia.co.uk/2025/10/06/slsh_negociate.jpg

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2aOPnmsSfIPi2ffOCDIVjEwAAAEs&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aOPnmsSfIPi2ffOCDIVjEwAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aOPnmsSfIPi2ffOCDIVjEwAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2025/10/03/scattered_lapsus_hunters_latest_leak/

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44aOPnmsSfIPi2ffOCDIVjEwAAAEs&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2025/10/03/scattered_lapsus_hunters_latest_leak/

[8] https://www.theregister.com/2025/10/06/clop_oracle_ebs_zeroday/

[9] https://www.theregister.com/2025/10/03/scattered_lapsus_hunters_latest_leak/

[10] https://www.theregister.com/2025/09/23/jaguar_landrover_shutdown_extended/

[11] https://www.theregister.com/2025/09/22/stellantis_breach/

[12] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_specialfeatures/cybersecuritymonth&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33aOPnmsSfIPi2ffOCDIVjEwAAAEs&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[13] https://www.theregister.com/2025/08/27/salesforce_salesloft_breach/

[14] https://www.theregister.com/2025/10/03/scattered_lapsus_hunters_latest_leak/

[15] https://www.theregister.com/2025/09/18/two_teens_charged_in_tfl_case/

[16] https://www.theregister.com/2025/09/22/teen_cuffed_scattered_spider_casino/

[17] https://whitepapers.theregister.com/



mark l 2

I mean how are they to know that someone has sent an email. It would be trivial to fake a screen shot of a sent email to the Salesforce execs and forward that to these malware scum as evidence you have sent an harassing email, without any actual harassment taking place.

I'm sure there are people countries where the hourly wage is a lot less than $10 an hour who will happily do that all day.

Oh boy!

Throatwarbler Mangrove

Ten whole dollars? Now I can buy that banana!

The point is, you see, that there is no point in driving yourself mad
trying to stop yourself going mad. You might just as well give in and
save your sanity for later.