Who is the most dangerous cyber adversary in 2025? This briefing names that group and shows how their tactics changed risk for U.S. organizations.
A fast, malware-light alliance fused Scattered Spider, LAPSUS$, and ShinyHunters traits into a single, agile threat. They used vishing, OAuth consent tricks, and malicious SaaS integrations to steal credentials and move laterally.
Public reporting links Salesforce, Salesloft, and Drift incidents to this group and to UNC designations via an FBI FLASH. An extortionware portal later claimed mass data exposure and kept pressure on trust and identity.
Read on for clear, evidence-based mapping of techniques to MITRE ATT&CK. Expect practical guidance on identity-first defenses, phishing-resistant MFA, and Zero Trust moves that matter.
Key Takeaways
- Validated pattern: Multiple vendor incidents and an FBI advisory link these operations across SaaS platforms.
- Human attack surface: Vishing and social engineering converted trust into access.
- Identity as perimeter: OAuth abuse and credential theft make identity controls critical.
- Actionable defense: Prioritize phishing-resistant MFA and continuous validation.
- For leaders: CISOs and business teams must adjust policy and detection to fast, low-malware attacks.
Executive summary: Why 2025 changed the cyber threat calculus
AI-scaled social engineering and identity-focused intrusions compressed time from first contact to business impact. Defenders saw malware-light campaigns replace noisy exploits, forcing a shift to behavior-based detection and Zero Trust for cloud and SaaS protection.

Darktrace logged over 12.6 million malicious emails from January to May, with more than a quarter aimed at VIPs. Text-heavy phishing suggested model-assisted messages, while AI voice and deepfake video raised vishing risks.
“Breakout times dropped to minutes; attackers turned OAuth consent, help-desk flows, and SSO trust into direct paths to data and accounts.”
Ransom-as-a-Service gangs dominated incidents, and extortion shifted toward SaaS targets. Edge exploits, like pre-disclosure abuse of CVE‑2025‑0994, added pressure, but most impactful activity avoided platform flaws.
| Activity | Primary Impact | Detection challenge |
|---|---|---|
| AI-enhanced phishing | Rapid credential theft, VIP compromise | Text appears legitimate; high click rates |
| OAuth consent abuse | Long-lived token access to cloud data | Trusted app approvals evade controls |
| Malware-light lateral movement | Fast business impact, extortion | Minimal forensic artifacts; behavior needed |
What leaders must do: Assume compromise, harden identity controls, and invest in continuous validation and anomaly-driven detection across cloud and user activity.
Search intent decoded: Who’s the top adversary and why it matters for U.S. organizations
Reporting ties a coalition of Scattered Spider, LAPSUS$, and ShinyHunters techniques to multiple high-value SaaS breaches affecting U.S. firms. This matters because the group turns people and identity systems into scaleable access paths that drive rapid impact.

Searchers want a clear answer: which threat actor poses the biggest risk and what that means for operational risk.
Named in reports as “Scattered Lapsus$ Hunters,” this coalition blends vishing and help‑desk pretexts with insider recruitment and mass data theft. For many organizations, that mix attacks SaaS platforms, customer records, and brand trust directly.
- Phishing and help‑desk coercion push users toward OAuth consents and MFA resets.
- Speed over persistence: teams grab tokens and exfiltrate data quickly, then pressure via public extortion channels.
- Legal and response complexity: attribution uncertainty raises regulatory and breach-notification risk for U.S. sectors like retail and aviation.
Security teams should expect attacks that target identity and tokens more than endpoints. Prioritize phishing-resistant MFA, OAuth governance, and tight monitoring of user behavior to reduce attack surface and preserve customer trust in a strained threat landscape.
The verdict: Scattered Lapsus$ Hunters emerge as 2025’s most dangerous threat actor
This coalition turned human trust and identity flows into repeatable win conditions. Speed, publicity, and platform-agnostic tactics made rapid compromise and public extortion their core advantage.
An alliance of fast-moving operators turned human trust and OAuth flows into a reliable path to high-value accounts.

What makes a “threat actor” in 2025?
Speed and persuasion outranked custom malware. Teams that moved quickly and convinced people to approve access could bypass many technical controls.
Credential theft, vishing, and OAuth consent tricks shortened time from contact to impact.
The supergroup model: Scattered Spider + LAPSUS$ + ShinyHunters
- Scattered Spider supplied help‑desk engineering and initial access that scaled calls and pretexts.
- LAPSUS$ added insider recruitment and source‑code theft when social routes needed amplification.
- ShinyHunters converted stolen records into fast extortion via public portals and channels.
Campaigns from late 2024 through October 2025 targeted Salesforce integrations using vishing, OAuth manipulation, and public extortion. An FBI FLASH linked parts of this activity to UNC6040 and UNC6395, while vendor reports showed no exploited Salesforce flaws — social engineering and token abuse carried the attack.
“Minimal reliance on exploits raised the bar for detection; defenders must treat identity as the primary perimeter.”
who is the most dangerous cyber adversary in 2025
Short answer: Scattered Lapsus$ Hunters. They combine large-scale social engineering with identity abuse to turn brief interactions into sustained access.

This coalition reached SaaS platforms through vishing, rogue integrations, and consent fraud rather than platform exploits.
From late‑2024 Salesforce intrusions to Salesloft and Drift token abuse (Mar–Jun 2025), operators moved fast. Telegram coordination (Aug 2025), an FBI FLASH (Sep 12, 2025), and an extortion portal (Oct 3, 2025) marked escalation.
- Signature: convincing users to reset MFA or approve connected apps, creating durable tokens that survive password changes.
- Tooling: browser stealers such as RedLine, NTDS extraction, and coerced MFA delivered quick data grabs and extortion leverage.
- Impact: stolen credentials and OAuth tokens became direct levers against customers and enterprises.
“Their edge is social engineering at scale plus identity abuse that converts human action into sustained access.”
Defenders should prioritize phishing‑resistant MFA, consent governance, and behavioral controls to regain control over identity and reduce successful attacks.
Aliases and attribution: Untangling brand names, UNC designations, and public reporting
Clear naming shortens response time and reduces duplicated effort across teams. Map common aliases so analysts align feeds, alerts, and case notes quickly.
Public advisories and vendor notes often used different labels for overlapping activity, creating analyst friction.

Scattered Spider
Also seen as: Roasted 0ktapus, 0ktapus, Octo Tempest, Storm‑0875/0971, DEV‑0971, Muddled Libra, Scattered Swine, UNC3944, Starfraud.
Context: Long-running social engineering across telecom, BPO, and enterprise targets explains multiple tags and vendor-specific records.
LAPSUS$
Also seen as: DEV‑0537, Strawberry Tempest.
Context: Labels reflect incident response streams tied to data theft and insider recruitment reporting.
ShinyHunters
Also seen as: UNC6040 and related identifiers.
Context: UNC6040 anchors public links to large‑volume data exfiltration and extortion of Snowflake and other cloud data.
“Vendor labels and UNC/DEV tags tell different parts of the story; link them and focus on behaviors rather than a single name.”
- Why map aliases: avoid fragmented intel and speed triage.
- Recommended practice: maintain an internal crosswalk and tag feeds with behavior-based labels.
- Note: supply chain and SaaS chains complicate attribution—prioritize observable activity over brand certainty.
| Alias cluster | Common indicators | Operational risk |
|---|---|---|
| Scattered Spider / UNC3944 | vishing, help‑desk pretext, OAuth consent abuse | fast token theft and lateral moves |
| LAPSUS$ / DEV‑0537 | insider recruitment, source code exfiltration, high-volume data grabs | brand damage and intellectual property loss |
| ShinyHunters / UNC6040 | mass data dumps, extortion portals, Snowflake targets | public exposure and regulatory fallout |
Timeline of activity: Key milestones from late 2024 through October 2025
Across roughly a year, repeated sequences of social engineering, OAuth consent abuse, and public extortion produced fast, high-impact results. Use this timeline to test detection and response SLAs against likely sequences rather than isolated alerts.

Late 2024: Salesforce vishing and rogue integrations
A wave of phone-based vishing convinced Salesforce users to approve fake connected apps. That approval granted API access and enabled targeted data exfiltration from major brands.
Core tactic: believable IT pretexts that pushed admins into app approvals on setup pages.
Mar–Jun 2025: Salesloft and Drift compromises, OAuth token abuse
Operators accessed Salesloft GitHub, pivoted to Drift AWS, and harvested OAuth tokens tied to customer integrations. Tokens let them reach linked accounts without platform exploits.
Notable callout: On June 5, Google confirmed malicious integrations and vishing as likely vectors, reinforcing that social routes—not product flaws—enabled access.
Aug–Oct 2025: Telegram coordination, FBI FLASH, extortionware portal launch
August 8 saw a Telegram channel unite multiple personas and tease a Ransom-as-a-Service offering. On September 12, an FBI FLASH mapped activity to UNC identifiers and pushed urgent advisories.
Groups claimed to go dark on September 17, yet activity continued. By October 3 an extortionware portal published deadlines and public pressure campaigns.
- Pattern: social calls → OAuth consents → token abuse → public pressure.
- Action: stress-test response plans against this campaign flow and verify detection for unusual emails and token approvals.
TTPs mapped to MITRE ATT&CK: How operations scale without exploiting platform flaws
This section links observed techniques to ATT&CK so defenders can close practical gaps fast. Focus is on consent, directory theft, and tools that blend into normal IT traffic.

The common thread: consent and coercion—techniques that weaponize identity flows to avoid noisy exploits.
Initial access and credential theft
Phone-led vishing coerced MFA resets or approvals for connected apps (T1566.004), creating token-based access that survives password changes.
Directory secrets came from NTDS dumps and vCenter disk tricks (T1003.003). Browser stealers like RedLine captured stored credential pairs and session tokens (T1555.003).
Cloud, discovery, and persistence
EC2 metadata theft converted web footholds into AWS role misuse (T1552.005). AD recon tools and tenant forwarding rules exposed sensitive mail and user lists (T1087, T1114.003).
RMM suites were repurposed for command and control, letting attackers operate through legitimate admin channels (T1219).
- Impact: coordinated extortion and financial theft pushed victims onto TOR portals (T1657).
- Detection focus: spikes in consent approvals, unusual directory reads, RMM anomalies, and suspicious mail rules.
“Map these behaviors to controls, not CVE hunts; identity-first detection wins time and reduces business impact.”
Tradecraft spotlight: Social engineering at scale with AI voice and automated help‑desk scripts
AI callers and tight playbooks let operators run high-volume social engineering that sounds local and calm. This turns routine support moments into attack windows that bypass many controls.
How AI-driven vishing scales realistic call flows
Automated voices mimic accents, pauses, and phrasing to build trust quickly.
AI voice agents let teams run thousands of calls with minimal human oversight. Call scripts simulate help‑desk troubleshooting, lowering suspicion and prompting compliance.
Voice cloning and accent switching expand reach across regions while keeping operations lean.
Click-through manipulation and consent coercion
Attackers guide a user through staged pages and prompts that end in connected app approvals or MFA resets. Tokens captured this way often survive password changes.
Resurgent ClickFix flows mix phishing pages, CAPTCHAs, and PowerShell prompts to gain execution under the guise of support. Darktrace logged huge volumes of phishing emails that fed these call campaigns.
- Countermeasures: live call drills, safe‑word verification, and tightened consent policies.
- Detection: correlate call spikes, ticket creation, and unusual OAuth approvals.
| Technique | Observed effect | Recommended control |
|---|---|---|
| AI vishing | High user compliance on support calls | Call verification, outbound call logging |
| ClickFix flows | Browser code execution, token capture | Block script execution, phishing-resistant MFA |
| Consent coercion | Long-lived OAuth tokens | Consent policy, app allowlists |
“Train with live-call scenarios and verify identity with out-of-band checks to reduce over-compliance.”
SaaS in the crosshairs: Why Salesforce-class platforms became prime targets
SaaS vendors bundle high-value records and an OAuth economy that makes consent abuse highly efficient for attackers. That concentration turns a single approved app into a wide door for extraction.
Salesforce and similar platforms hold customer PII, financial records, and operational content. Attack campaigns used vishing and malicious integrations to gain API-level access and pull large volumes of data.
High-value data concentration and OAuth token ecosystems
Tokens act like keys that often outlive password changes. OAuth consents and connected apps can persist and enable long-lived sessions, so token governance must outrank password resets.
Single Sign-On, trust chains, and identity as the new perimeter
SSO and broad-scoped app consents extend convenience and create trust chains. A single weak link can unlock multiple tools across the enterprise cloud stack.
- Risk: credential stuffing and social calls, including phishing, remain effective without phishing-resistant MFA.
- Detection: log consent spikes, token use from odd locations, and mass export behavior to spot early signs of compromise.
- Action: prioritize token revocation and app-connection reviews during incident response to limit damage to customers and reduce extortion risks tied to data.
Beyond the supergroup: 2025 threat trends shaping the battlefield
The dominant pattern favored speed: automated phishing at scale, paired with selective exploit use against exposed infrastructure. That mix pushed defenders to catch fast, small-window moves rather than long campaigns.
AI-amplified phishing, QR campaigns, and VIP targeting
High-volume messaging and better lures made social attacks more effective.
Darktrace logged 12.6 million malicious emails from Jan–May, with over 25% aimed at VIPs. QR phishing also stayed high, topping one million detections in February.
RaaS acceleration and affiliate variability
Ransom-as-a-Service affiliates such as Qilin, RansomHub, and Lynx broadened initial access options. That variability makes signature detections brittle and slows pre-encryption alerts.
Edge and CVE exploitation amid patch lags
Operators opportunistically hit SimpleHelp (CVE‑2024‑57727/57728) and Trimble Cityworks (CVE‑2025‑0994) where patches lagged. Edge systems and infrastructure-facing services remain easy targets.
| Trend | Observed effect | Defender focus |
|---|---|---|
| AI phishing & QR traps | Faster credential/token theft | Phishing-resistant MFA; mobile checks |
| RaaS affiliates | Variable initial access patterns | Anomaly detection; behavioral playbooks |
| Edge CVE hits | Service disruption; data exposure | Rapid patching; perimeter visibility |
“Speed and scale, not just sophistication, define modern threat campaigns.”
Comparative risk: How Scattered Lapsus$ Hunters stack against APTs and RaaS syndicates
Fast public extortion and token theft favor speed and visibility over long dwell times. Defenders must shift emphasis from endpoint alerts to identity and SaaS event analytics.
Motivation and tempo matter more than payload size for this coalition.
This group focuses on rapid monetization. Operators use OAuth consent tricks, help‑desk scripts, and public pressure to force payouts or disclosure.
Motivations, tempo, and malware-light operations
Compared to APTs, they chase quick wins and publicity rather than long missions. That reduces forensic traces tied to malware and shifts detection toward identity signals.
Supply chain and SaaS extortion versus classic ransomware
RaaS affiliates still rely on encryption and affiliates vary entry vectors. The supergroup instead weaponizes repos, integration tokens, and customer data to extort at scale.
- Key contrasts: swift public extortion vs stealthy persistence.
- Impact: disclosure risks, customer churn, and regulatory fallout rival ransom payments.
- Detection need: combine network logs, OAuth event feeds, and user behavior analytics.
For action, map controls to likely operations, test token revocation playbooks, and run incident drills that simulate SaaS compromise.
Read a detailed report for incident examples and recommended controls.
Sectors at risk in the United States: From retail and aviation to insurers and government
Cloud-first firms and heavy SaaS adopters concentrate customer records and operational content, which raises extortion exposure. Public‑facing tools and delayed patching widen attack paths into critical infrastructure and service systems.
Cloud-first enterprises became high-value targets when OAuth approvals granted broad API reach. Retail, aviation, and insurers saw consent abuse turn routine integrations into rapid data pulls. Government and CNI-adjacent agencies faced extra risk from internet-facing management systems and slow patch cycles.
Enterprise SaaS adopters and cloud-first organizations
Centralized records amplify extortion leverage.
- Risk: token theft and consent misuse that bypass password resets.
- Control: app allowlists, token revocation playbooks, identity telemetry.
Critical national infrastructure exposure via internet-facing systems
Management consoles and sector tools were frequent entry points during campaigns.
“Attackers target convenience: a single approved app can unlock broad access to customer data and operations.”
| Sector | Primary vector | Recommended action |
|---|---|---|
| Retail & fashion | OAuth consent abuse, token exports | Consent governance, export monitoring |
| Aviation & logistics | Third‑party integrations, API misuse | Third‑party risk reviews, strict scopes |
| Insurance & healthcare | Phishing to obtain admin approvals | Phishing‑resistant MFA, live call verification |
| Government & CNI | Internet‑facing tools, delayed patches | Rapid patching, network segmentation, incident alignment |
Indicators and behaviors: What defenders should look for in 2025 intrusions
Focus on identity signals and small linked events; these often reveal coordinated campaigns early. Fast, low-noise operations hide behind routine support activity, so correlation matters more than single alerts.
Start by treating small, linked identity events as likely parts of a larger campaign rather than isolated anomalies.
Unusual MFA resets, OAuth consent spikes, and help‑desk impersonation
Watch identity events closely: unexpected MFA resets, sudden spikes in OAuth consents, and help‑desk tickets tied to the same users. These patterns often precede token-based access and fast data export.
Browser stealer beacons and RMM anomalies
Correlate endpoint artifacts and remote sessions: RedLine‑style credential harvests, new RMM installs (ScreenConnect, TeamViewer, Splashtop, Pulseway), and odd remote sessions typically signal lateral moves.
- Flag connected apps created or approved outside normal change windows or with broad scopes; revoke if suspicious.
- Look for tenant-level forwarding rules, mailbox rules pointing to external addresses, and mass rule edits tied to one actor.
- Detect known browser credential file reads and exfil patterns that suggest stolen credentials.
- Monitor EC2 metadata access from unexpected processes or containers as a server‑side credential theft indicator.
“Single events may look benign; combined patterns reveal coordinated operations.”
For more context on high-volume email and identity trends see the mid‑year threat review. Tie anomalies together across logs so defenders spot attackers before impact.
Defensive priorities: Identity-first controls that blunt adversary advantages
Defenders must treat identity as the primary control plane and bake verification into every access decision. Shift effort from chasing indicators to preventing token abuse and credential loss at source.
Phishing-resistant MFA, Zero Trust, and least privilege
Mandate phishing‑resistant MFA (FIDO2) for high‑risk users first, then expand org‑wide. Start with VIPs, admins, and service accounts. Enforce least privilege so approvals grant only narrow scopes.
Email and SaaS anomaly detection with behavioral analytics
Layer behavioral analytics over mail and SaaS activity to catch consent abuse early. Instrument detections for unusual consent spikes, mass exports, and rapid privilege changes. Correlate email, ticket, and token events to reveal linked campaigns.
Cloud posture management to harden OAuth and IAM
Deploy Cloud Security Posture Management (CSPM) to surface risky OAuth scopes, stale tokens, exposed secrets, and permissive IAM roles. Review help‑desk workflows and add second‑channel verification to block social resets.
- Action: test token revocation playbooks and point‑in‑time restores for SaaS backups.
- Focus: block broad scopes, log consent approvals, and segment network and systems by trust level.
“Make identity your control plane: harden access, verify continuously, and detect behavior, not just signatures.”
Validation and readiness: Proving controls against real adversary TTPs
Continuous validation turns assumptions about security into repeatable evidence. Run tests that replay real sequences so leaders can measure gaps and tune controls.
Continuous security validation mapped to MITRE ATT&CK
Map tests to ATT&CK techniques to ensure coverage across identity and cloud flows.
Use platforms that emulate T1566.004 (vishing consent fraud), T1552.005 (metadata theft), T1219 (RMM persistence), and T1657 (extortion activity). That mapping makes detection work measurable.
Simulating Scattered Spider, LAPSUS$, ShinyHunters campaigns for measurable resilience
Don’t guess—prove it. Run continuous, mapped tests that replicate vishing-to-OAuth abuse and token misuse chains.
- Include SaaS consent flows, RMM persistence, and staged exfiltration to validate end-to-end coverage.
- Map each detection to ATT&CK techniques and log control efficacy over time.
- Validate EDR/XDR visibility into browser credential reads and new RMM installs.
- Test network alerts for abnormal egress tied to data staging and exfil endpoints.
“Measure resilience: time to detect, time to contain, and time to evict.”
| Test focus | Primary metric | Actionable outcome |
|---|---|---|
| Vishing → OAuth consent | Detection lead time | Update consent allowlists; add second‑channel verification |
| Metadata credential theft | Privilege escalation alerts | Harden instance metadata access; rotate role keys |
| RMM persistence & staging | Containment time | Block unauthorized RMM installs; tighten vendor onboarding |
For step‑by‑step validation guidance and to align remediation to real cases, see a practical resource from Picus on why validation matters: continuous validation playbooks.
Case-based lessons: How extortionware portals reshape negotiation and disclosure risk
Extortion portals compress decision windows and force fast, cross‑functional action. When operators publish alleged datasets and deadlines, legal, IR, and communications teams must move in sync.
An October Tor posting listed claimed Salesforce files — an entry read “Salesforce, Inc. 989.45m/~1B+ records” with an Oct 10 deadline. That public claim amplified pressure on firms and their customers.
Public leak sites change an incident from a technical response into a public relations and regulatory case almost instantly.
- Decision speed: portals name alleged content and set tight timelines, making deliberation costly.
- Legal posture: counsel must prepare payment, notification, and evidence preservation options under time pressure.
- IR actions: triage which customer records and files are implicated, then run token revocation and consent rollback in parallel with log reviews to test claims of compromise.
- Communications: use pre‑approved statements and FAQ templates to protect trust while investigations proceed.
“Documented decision frameworks reduce chaos and support consistent, defensible actions during public pressure.”
Conclusion
Evidence shows a fast, identity‑first threat that turned trust and tokens into reliable access paths.
Protective moves that focus on people, tokens, and behavior will reduce exposure and blunt public pressure tactics.
Act now: treat OAuth consents and tokens as first‑class assets. Monitor, govern, and revoke aggressively during incidents to limit data loss and rapid access escalation.
Build joint workflows across security, IT, legal, and communications so extortion portals don’t force ad hoc choices. Prioritize phishing‑resistant MFA, Zero Trust, anomaly detection, CSPM, and mapped validation exercises.
Patch edge systems, close known vulnerabilities, and teach support teams safe verification. Validate defenses with realistic simulations so tools and engineering processes improve time to detect, contain, and evict future attacks.