Find notable cyber news and cases, enriched with sources, timelines, and signals.

Scattered LAPSUS$ Hunters IT help-desk vishing campaign

Campaign
First reported
Last updated
Happening score
H score 29
1 unique sources, 1 articles

Summary

Hide ▲

Scattered LAPSUS$ Hunters (SLH) is running a help-desk vishing campaign that recruits women to impersonate employees, raising the success rate of account-takeover attempts against organizations. The group is offering $500 to $1,000 per call and supplying pre-written scripts to standardize the impersonation. The operation targets IT help desks and call centers to trigger password resets or installation of RMM tools for remote access.

Related Happenings

The Gentlemen affiliate-driven RaaS expansion and enterprise scale-up

Threat Actor Meta
H score57 First: 21.04.2026 17:00 Last: 21.04.2026 17:00 Sources 1

About this happening: The Gentlemen ransomware-as-a-service operation is using an operator-maintained EDR-killer portfolio, led by GentleKiller, to disable security software before encrypti...

Npm registry spear-phishing campaign targeting sales personnel

Campaign
H score28 First: 29.12.2025 11:44 Last: 29.12.2025 11:44 Sources 1

About this happening: Unknown threat actors ran a five-month spear-phishing campaign that abused 27 npm packages as browser-hosting infrastructure, turning a software registry into a resili...

BatShadow job-seeker social-engineering campaign

Campaign
H score33 First: 07.10.2025 20:04 Last: 07.10.2025 20:04 Sources 1

About this happening: BatShadow is running a phishing campaign that targets job seekers and digital marketing professionals with ZIP archives and lure PDFs that deliver Vampire Bo...

ShinyHunters publicly operates extortion-as-a-service with partner crews

Threat Actor Meta
H score57 First: 07.10.2025 00:08 Last: 07.10.2025 00:08 Sources 1

About this happening: ShinyHunters publicly framed itself as an extortion-as-a-service (EaaS) operator, a shift that can scale multi-victim extortion and blur attribution across partner breache...

Microsoft Teams initial-access campaign impersonating IT help desk staff

Campaign
H score36 First: 30.08.2025 15:06 Last: 30.08.2025 15:06 Sources 1

About this happening: The Microsoft Teams phishing campaign is giving unknown threat actors a reliable path to initial access in enterprise environments and to install remote access softw...

Timeline

  1. 25.02.2026 17:06 2 articles · 4mo ago

    Initial report: Scattered LAPSUS$ Hunters IT help-desk vishing campaign

    Initial Disclosure

    The current phase is a recruitment push that pays women to make vishing calls and use scripts to impersonate employees. This expands SLH's help-desk social-engineering approach and improves the odds of successful password reset abuse.

    Show sources