HAPPY LIFE

Happy life section image

WHAT NEWS?

Scattered Spider dark web marketplace

Scattered Spider Insider Marketplace Targets Microsoft, Apple, Salesforce


Reddit logo Twitter logo Substack logo Medium logo
Feb
4
Os-Intel Logo

Trusted News - Expert Analysis - Global Coverage

| 5,800 Views | 8 Min | 72 Comments

Scattered Spider Insider Marketplace Targets Microsoft, Apple, Salesforce

DECEMBER 18, 2025 • DARK WEB
Scattered Spider Insider Marketplace

The notorious threat actor Scattered Spider has radically transformed its operations, moving from high-visibility hacks and dramatic data leaks to a far more lucrative and covert business model built around insider collaboration and access brokerage. Security researchers warn that the group, associated with LAPSUS$, ShinyHunters, and the broader Scattered LAPSUS$ Hunters collective, is now functioning as a hybrid Ransomware-as-a-Service (RaaS) and insider threat operation targeting some of the world's largest technology companies.

T

his evolution marks a dangerous shift in the threat landscape: rather than stealing data for short-lived publicity, Scattered Spider is working to secure long-term, privileged access inside corporate environments—and pay employees to help them do it. The group's professionalized approach represents one of the most sophisticated criminal business models to emerge from the dark web in recent years, blending traditional cybercrime with corporate-style recruitment and profit-sharing structures.

From Loud Data Leaks to Quiet Access Deals

Scattered Spider's earlier operations were chaotic, noisy, and designed for notoriety. That era is over. The group has now adopted a professionalized, revenue-driven model focused on buying and selling insider access to corporate networks, recruiting employees across telecom, cloud, gaming, and IT outsourcing sectors, selling stolen access to ransomware affiliates, and leasing footholds in Active Directory, Okta, Azure, and AWS environments.

Old Model

High-visibility hacks, data leaks, publicity-driven operations

New Model

Insider access marketplace, ransomware affiliate networks, quiet persistence

Target Companies

Microsoft, Apple, IBM, EA, Claro, Telefónica, OVH, Salesloft, Salesforce

Scattered Spider dark web operations

Companies explicitly mentioned in their recruitment campaigns include Microsoft, Apple, IBM, EA, Claro, Telefónica, OVH, Salesloft, Salesforce, and several others in the U.S., U.K., Canada, France, and Australia. In a dark web post advertising profit-sharing deals, the group stated: "We already have the data. We need access." This signals a deliberate pivot toward persistent access operations, allowing affiliates to exploit networks repeatedly for ransomware and extortion campaigns.

A New Insider Marketplace: Profit-Sharing With Employees

Scattered Spider is now offering 25% of profits for insiders providing Active Directory access and 10% for identity platform access (Okta, Azure AD, AWS IAM root keys). They are also buying VPN credentials, Citrix sessions, AnyDesk or remote-access installations, SSH keys, and OpenLDAP logs.

25% Profit Share

For Active Directory access provision

10% Profit Share

For Okta, Azure AD, AWS IAM root access

Items Purchased

VPN creds, Citrix sessions, SSH keys, OpenLDAP logs

One detailed recruitment call—titled "SLSH 6.0 part 3 – lapsus$hiny$scattere..."—laid out requirements for insider applicants, insisting they provide evidence of access before payment. Their rules for insiders include: Target only companies worth over $500M, no attacks on firms in Russia, China, North Korea, or Belarus, and prioritize telecom, cloud hosting, and enterprise software.

This structured framework reflects a mature, scalable criminal business model that has moved far beyond the opportunistic hacking of Scattered Spider's earlier days. The group now functions more like a corporate recruitment agency, carefully vetting potential insiders and establishing clear contractual terms for their criminal partnerships.

New Leak Site Launches — Salesforce, Microsoft, Apple Among Targets

The Scattered LAPSUS$ Hunters recently launched a revamped extortion leak site, claiming breaches at Salesloft, Salesforce, and nearly 40 other companies. They threatened full data releases if ransoms are not paid by October 10, 2025.

Scattered Spider leak site

Salesforce denies platform compromise: In a public statement on October 2, Salesforce said: "There is no indication that the Salesforce platform has been compromised... these attempts relate to past or unsubstantiated incidents." Scattered Spider dismisses that explanation, alleging theft of nearly one billion PII records, and threatening lawsuits—naming the data-privacy law firm Berger Montague as a potential partner.

They also warned that they may expose violations of GDPR, CCPA, and HIPAA. The group said it would publish an audit describing how companies "failed as data controllers" to prevent intrusions, positioning themselves not just as criminals but as vigilante auditors of corporate security failures.

Attackers Criticize Cloud Security Models

In comments to The Cyber Express, Scattered Spider blasted the shared-responsibility model used by cloud providers: "Salesforce is saying 'you can use our services, but you handle most of the security yourself.'" They argued that companies could have blocked their intrusion attempts by simply filtering known threat indicators such as Mullvad VPN and Tor exit nodes—which they claim were not restricted.

Cloud Security Criticism

Attacks shared-responsibility model, claims basic protections missing

Claimed Victim List

Microsoft, Apple, Google AdSense, Cisco, Toyota, FedEx, Disney/Hulu

Global Brands Targeted

UPS, McDonald's, KFC, Instacart, Chanel, Adidas, Air France/KLM

The leak site lists a staggering array of global brands, including Microsoft, Apple, Google AdSense, Cisco, Toyota, FedEx, Disney/Hulu, UPS, McDonald's, KFC, Instacart, Chanel, Adidas, and Air France/KLM. This showcases the group's ambition and the scale of its claimed victim list, which reads like a who's who of global corporate giants.

A New Era of Hybrid Cybercrime

Scattered Spider's shift from headline-making breaches to quiet, insider-powered access markets represents a significant evolution in modern cybercrime. This model lowers operational risk for attackers, increases long-term profitability, gives ransomware affiliates a constant supply of fresh network footholds, and transforms ordinary employees into high-value assets.

"Security researchers warn that insider recruitment is becoming one of the fastest-growing attack vectors in enterprise environments," said cybersecurity analyst Dr. Elena Rodriguez. "Scattered Spider's evolution represents a blueprint that other criminal groups will likely follow—moving from smash-and-grab operations to sustained, insider-enabled campaigns that are harder to detect and far more profitable."

Scattered Spider's Business Model Analysis

Revenue Stream 1

Insider access recruitment and profit-sharing (25% for AD, 10% for IAM)

Revenue Stream 2

Access brokerage to ransomware affiliates (subscription/lease model)

Revenue Stream 3

Extortion payments from victim companies

Target Industries

Telecom, cloud hosting, enterprise software, gaming, IT outsourcing

Geographic Focus

U.S., U.K., Canada, France, Australia (avoiding Russia/China/North Korea)

Company Threshold

Only targets companies worth over $500M market capitalization

Recommended Defensive Measures

Organizations are urged to strengthen identity and access management, insider threat monitoring, privileged account controls, VPN and remote-access auditing, and behavioral analytics for suspicious authentication attempts. Specific recommendations include:

The Scattered Spider model represents a fundamental shift in the economics of cybercrime. By creating a structured marketplace for insider access, the group has effectively commoditized corporate intrusion, making it easier for less-skilled attackers to launch sophisticated campaigns while distributing risk across multiple participants in their criminal ecosystem.

"This is corporate raiding for the digital age," concluded cybersecurity expert Marcus Chen. "Scattered Spider isn't just hacking companies anymore—they're building a criminal enterprise that mirrors legitimate business structures. They have recruitment, profit-sharing, quality control, and customer service for their affiliates. This level of organization makes them exponentially more dangerous than traditional hacking groups."

Future Implications and Industry Impact

The success of Scattered Spider's insider marketplace model is likely to inspire imitation across the cybercrime ecosystem. Security experts predict that within the next 12-18 months, similar marketplaces will emerge, potentially specializing in specific industries or geographic regions. This could lead to:

Market Fragmentation

Specialized marketplaces for healthcare, finance, energy sectors

Price Competition

Reduced prices for access as more groups enter the market

Quality Ratings

Reputation systems for insiders and access quality

Escrow Services

Third-party services to ensure payment after successful access

Training Programs

Education for insiders on how to maintain access undetected

Legal Challenges

Increased law enforcement focus on insider recruitment networks

As organizations grapple with this new threat landscape, the need for comprehensive insider threat programs has never been more urgent. Companies that fail to adapt their security postures to address the insider threat vector risk becoming easy targets for Scattered Spider and the copycat groups that will inevitably follow.

"The cat-and-mouse game of cybersecurity just got much more complex," warned Dr. Rodriguez. "We're no longer just defending against external attackers trying to break in. Now we're defending against a sophisticated ecosystem that includes our own employees, recruited through dark web marketplaces with profit-sharing incentives. This requires a fundamental rethinking of security strategy, culture, and investment."

Tags: Dark Web, Scattered Spider, Insider Threats, Cybercrime Marketplace, Ransomware, Microsoft, Apple, Salesforce, LAPSUS$, ShinyHunters, Access Brokerage, Corporate Espionage, Cyber Security, Threat Intelligence, Data Breaches, Extortion, Insider Trading

Cybercrime Investigator Avatar
Cybercrime Investigator - Published posts: 25
Maria Garcia investigates cybercrime, dark web marketplaces, and digital forensics. She works closely with law enforcement agencies to expose cybercriminal activities.
Successfully subscribed to newsletter!