The well-known cybercriminal group called Scattered Lapsus$ Hunters issued a surprising farewell statement on BreachForums.
See also: Scattered Spider: When Browsers Become an Attack Surface

This manifesto, a combination of confession and strategic deception, provides vital information about the evolving landscape of modern cybercrime and the increasing pressure from global law enforcement authorities. The statement reveals advanced operational security practices that far exceed the typical behavior of cybercriminals.
Scattered Lapsus$ Hunters claim that their 72-hour silence was intentionally orchestrated to “speak with their families, relatives, and confirm the effectiveness of their contingency plans and intentions.” This calculated approach demonstrates a level of strategic planning typically associated with state actors rather than financially motivated cybercriminals.
They describe these spectacular breaches as a tactical deception designed to “distract the attention of the FBI, Mandiant, and a few others” while real contingency plans were activated. This reveals a sophisticated understanding of how law enforcement and incident response teams allocate resources, suggesting that the group has studied defense methodologies as carefully as attack routes.
The Scattered Lapsus$ Hunters’ claim thatthey were “deliberately left in the dark” after infiltrating systems is particularly significant. The restraint they showed in Google Workspace, Person Finder, and older parts of Gmail suggests that the group may have had more access than they disclosed, but chose not to fully utilize it. This decision goes against what is typical for ransomware groups, which typically seek to cause as much damage and make as much money as possible.
See also: Scattered Spider: Core member sentenced to 10 years in prison

Perhaps most worrying is the group’s insinuations about critical infrastructure vulnerabilities. Their statement suggests that data from companies including Kering, Air France, American Airlines and British Airlines may have been compromised, with some organizations unaware they were facing potential exploitation. This aligns with documented attacks throughout 2025, with Air France and KLM confirming breaches in August, and several incidents in the aviation sector attributed to related groups.
Scattered Lapsus$ Hunters’ question, “Are they exploiting their data right now while the US, UK, Australian and French authorities are filled with the illusion that they have the situation under control?” reveals a deep cynicism about international law enforcement coordination. This statement takes on particular significance given the group’s recent arrests and apparent ability to monitor investigative activities, including their claim that they are “being watched as they painfully try to upload their HD logos to BF’s servers.”
The statement directly refers to the human cost of their businesses, acknowledging eight arrests linked to the Scattered Spider and ShinyHunters operations since April 2024, with four individuals currently being detained in France. These arrests include the capture of four alleged members of ShinyHunters in France in June 2025, highlighting the effectiveness of international cooperation between French authorities, the FBI, and other agencies.
The group’s expression of regret “for the four now in custody in France” and their assurance that the investigations will “progressively collapse” suggests that they believe the arrested individuals were sacrifices. Their claim that they “manipulated evidence to mislead investigators” demonstrates sophisticated counterintelligence capabilities designed to protect key operators while allowing regional members to face legal consequences.
See also: Scattered Spider carries out massive attack on VMware ESXi

The emergence of Scattered Lapsus$ Hunters represents an unprecedented unification within cybercrime, combining the tactics of Scattered Spider, Lapsus$ and ShinyHunters.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
