Inside The Com: Understanding the Ecosystem Behind Scattered Spider, LAPSUS$, ShinyHunters, and FALCON
Analysis and mitigations for "The Com", a decentralized, fluid ecosystem of cybercriminals known to constantly rebrand and run shared playbooks.
What is “The Com”?
The Community, or The Com is a decentralized, predominantly English-speaking cybercriminal ecosystem with no fixed leadership and no unified targeting objective apart from financial gain and reputation. The collective’s origins trace back to forums like OGUsers, later moving to RaidForums. Researchers, including teams at Flashpoint, describe it as loosely organized around "pillars," with a financially motivated hacking and extortion pillar (producing groups like LAPSUS$, Scattered Spider, and ShinyHunters) alongside separate, violence-oriented pillars that overlap socially but pursue very different objectives. As members move fluidly between crews, trade handles and infrastructure, and constantly rebrand, The Com is best understood not as one threat actor, but as the shared substrate that keeps producing new, interchangeable brands running largely the same social-engineering playbook.

This blog covers The Com as a collective, recent intrusions attributed to groups within The Com, and concludes with mitigation recommendations organizations can implement to reduce the threat these groups pose.

Key Groups Within The Com

While some groups within The Com focus on extortion activities, like doxing or physical actions like swatting, this blog focuses on key players in cyberspace: LAPSUS$, Scattered Spider, and ShinyHunters.
LAPSUS$
LAPSUS$ is one of the most well-known cybercrime groups attributed to The Com. Known for a string of 2022 intrusions targeting Okta, Nvidia, and Microsoft, the group highlights the risks of social engineering. LAPSUS$ is also known for recruiting insiders directly, openly advertising on Telegram for employees at telecom and tech companies willing to sell access. LAPSUS$ focuses on stealing data and threatening to leak it, rather than encrypting files to demand a ransom.
Scattered Spider
Scattered Spider's targeting has been opportunistic. Early on, they targeted telecom and BPO providers, later moving to casinos and hospitality, then insurance, retail, and aviation organizations. Scattered Spider’s TTPs resemble LAPSUS$, and the group uses vishing and help-desk impersonation to gain initial access, SIM swapping, MFA bombing, identity-provider abuse against platforms like Okta and Azure AD, and extensive living-off-the-land techniques once inside.
Ransomware-as-a-Service: Scattered Spider also established ransomware-as-a-service operations, including ALPHV/BlackCat, DragonForce, and Qilin, to monetize access through encryption and extortion. In some cases, Scattered Spider obtained initial access before one of the aforementioned groups was observed using ransomware for encryption.
Notable Intrusions: The group's highest-profile intrusions include the 2023 MGM Resorts and Caesars Entertainment breaches and the 2025 wave of UK retail attacks against Marks & Spencer, Co-op, and Harrods, which deployed DragonForce ransomware.
ShinyHunters
Active since approximately 2019, ShinyHunters initially focused on exfiltrating database records. They later sold these records on underground marketplaces. Recent campaigns include the targeting of Salesforce environments via the Salesloft Drift integration. This campaign showcased ShinyHunters abuse of OAuth tokens and third-party application access to reach SaaS platforms and exfiltrate data.
Scattered LAPSUS$ Hunters
This group merges the three groups mentioned above. In August 2025, a Telegram channel called Scattered LAPSUS$ Hunters (SLH) appeared and was used to coordinate threats and share information about upcoming data leaks. The brand is also linked to a "Sh1nySp1d3r" ransomware-as-a-service offering, along with mentions of the Silent Ransom Group in connection with it.
2026 was a particularly successful year for SLH, with them successfully compromising SoundCloud, Betterment, and Crunchbase. Moreover, researchers have observed the group exploit CVE-2025-61882, a critical Oracle E-Business vulnerability in their intrusions.
Law Enforcement Actions and Arrests
As groups like Scattered Spider and ShinyHunters have gained attention and carried out more brazen cyberattacks, law enforcement agencies have been building cases against them. Moreover, public-private information-sharing efforts have led to temporary disruption operations and the arrest of several members of these criminal groups. Recent international law enforcement actions include:
In the case of arrests, law enforcement agencies focused on correlating the physical hardware used in SIM-swapping attempts and the tracking of Telegram handles to uncover the individuals behind the operations. While arrests have temporarily impacted the groups, they have quickly recovered and adapted.
Conclusion
Because The Com is not a single group with a unified hierarchy, organizations need to watch for multiple groups that may work together to target them. Unlike other cybercrime groups that tend to operate individually, researchers have seen groups within The Com join forces and rebrand, as when Scattered LAPSUS$ Hunters was formed. This new group comprised members from three different groups and operated under one unified umbrella. As group names and members transform, defenders need to focus on underlying behavior and develop defensive measures to build robust mitigations.
Mitigations

These groups predominantly use social engineering for initial access. They have achieved significant success by targeting end users and abusing identities. As such, defenders must harden identities. This requires organizations to implement measures across their security stacks and prioritize user education. Key actions for organizations include:
Identity and Access Hardening
- Phishing-resistant MFA
- Migrate away from SMS/voice-based one-time passwords and push-based MFA solutions to hardware keys such as FIDO2 or passkeys. This shift will reduce the risk of SIM-swapping and MFA bombing, two techniques The Com frequently uses.
- Block outdated authentication mechanisms
- Disable legacy authentication mechanisms and protocols and restrict device code authorization flows.
- Limit device registration
- Limit the number of devices a user can register for MFA usage. Additionally, organizations should monitor and audit when users add new MFA devices.
- Conditional access policies
- Restrict authentication to devices managed through mobile device management solutions and compliant with policies.
- Privileged access management
- Deploy privileged access management solutions that restrict admin access to specific time spans and are easy to audit. Granting limited-time admin access when needed helps limit the blast radius when accounts are compromised.
User-focused Mitigations
- Callback verification
- To mitigate the risk of spoofed phone numbers or email addresses, employees should validate the contact information before reaching back out to a user.
- Verification of identity
- Confirm a user’s identity before resetting passwords or enrolling MFA devices.
- Help desk training
- Help desk personnel should receive specific training on tactics, techniques, and procedures employed by groups such as ShinyHunters
SaaS and Cloud Application Security
- OAuth and connected-app auditing
- Regularly audit third-party applications that are connected to their environment.
- Least-privileged API scopes
- Connected applications should have the bare minimum privilege required to function.
- Securing secrets
- Store secrets such as API keys and passwords in secure solutions like password managers, not in documentation.
- Monitoring for bulk exports and mass data exfiltration
- Security teams should monitor for mass download or export attempts from platforms that host sensitive information.
Ransomware Resilience
- Backups
- Back up data regularly. Organizations should also test backups and restoration procedures frequently to ensure the process and data are accurate.
- Network segmentation
- Appropriate network segmentation can limit lateral movement from a compromised host.
- Dark web monitoring
- Have access to underground sources for information about their organization. This information can help identify stolen credentials or access points that pose a risk.
Organizational Readiness
- Incident response training
- Employees should receive appropriate incident response training to ensure they understand their role in an incident and the processes they must follow.
- Brand monitoring
- Groups within The Com register lookalike domains as part of their intrusion. Attackers often create these domains shortly before an intrusion and then take them down afterward. Track any domains registered with the organization name or affiliated brands.
Example In Practice
Using FALCON as an example, Palo Alto’s Unit 42 outlines several recommendations to harden environments against its techniques. These predominantly focus on making it harder for the group to abuse valid accounts.

Indicators of Compromise: Domain Patterns
Typically, the domains these groups register are active only briefly. They may register them shortly before an intrusion attempt to evade brand monitoring protections and take them down afterward. However, public incident reporting has revealed several patterns that can shed light on the specific group behind the attack.
The table below shows examples of wildcard searches within the Pulsedive platform’s Explore capability that can identify domains tied to various groups.
Scattered Spider
Scattered Spider’s phishing domains typically take the form: organizations-keyword. Examples of this format are below:
- organization-sso[.]com
- organization-okta[.]com
- organization-helpdesk[.]com
ReliaQuest identified that 81% of the Scattered Spider domains impersonate technology vendors. The domains targeted single sign-on, identity providers, and VPNs to harvest credentials.


Scattered LAPSUS$ Hunters
SLH naming convention is in the format: keyword-organization. Examples of the format include:
- helpdesk-organization[.]com
- sso-organization[.]com
- ticket-organization[.]com

Pink and FALCON
Pink’s naming convention focuses on the term "passkey." Additionally, Pink predominantly registers its domains through NICENIC and uses Cloudflare and DDoS-Guard. Palo Alto found that FALCON also uses the same domain registrar and follows a similar passkey theme.


Shared Tactics, Techniques and Procedures
References
https://flashpoint.io/blog/understanding-illicit-ecosystems-the-com/
https://www.ic3.gov/CSA/2025/250912.pdf
https://www.bridewell.com/insights/blogs/detail/vishing-call-to-a-shared-com-ecosystem
https://unit42.paloaltonetworks.com/scattered-lapsus-hunters/
https://reliaquest.com/blog/scattered-spider-cyber-attacks-using-phishing-social-engineering-2025/
https://www.team-cymru.com/post/scattered-spider-attacks-infrastructure-profile