CrowdStrike has confirmed that internal screenshots shared by a now-terminated employee made their way to hackers, after being published on Telegram by the Scattered Lapsus$ Hunters cybercrime collective. The company emphasized that no breach of its systems occurred and that no customer data was exposed.
According to a CrowdStrike spokesperson, their systems were never compromised and customers remained protected throughout. They have turned the case over to relevant law enforcement agencies.
CrowdStrike did not name the insider or the threat group involved, but the statement followed inquiries about screenshots leaked by members of ShinyHunters, Scattered Spider, and Lapsus$.
ShinyHunters said that they allegedly paid the insider $25,000 for access. They claimed to have received SSO authentication cookies, though CrowdStrike had already detected the activity and cut off the insider’s access. The group also tried to buy CrowdStrike’s internal reports on ShinyHunters and Scattered Spider but said they never obtained them.
Scattered Lapsus$ Hunters’ growing activity
The groups behind the leak—now operating collectively as Scattered Lapsus$ Hunters—have been responsible for a wave of extortion operations, many tied to large-scale Salesforce breaches. They have targeted major companies through voice-phishing campaigns, impacting organizations such as Google, Cisco, Allianz Life, Qantas, Adidas, Workday, and LVMH subsidiaries.
Their extortion attempts have reached dozens of high-profile firms including FedEx, Disney/Hulu, Marriott, McDonald’s, UPS, Chanel, and IKEA. The group also claimed responsibility for the Jaguar Land Rover breach, which caused over £196 million ($220 million) in damages.
ShinyHunters and Scattered Spider have recently shifted to a new ransomware-as-a-service platform, ShinySp1d3r, after previously relying on ALPHV/BlackCat, RansomHub, Qilin, and DragonForce encryptors.













Comments