HomeSecurityGoogle: Hackers created fake account in Law Enforcement Request System

Google: Hackers created fake account in Law Enforcement Request System

Google has once again found itself at the center of a cybersecurity debate after it was forced to confirm that hackers had created a fake account on its Law Enforcement Request System (LERS) , the internal system through which police and judicial authorities around the world submit requests for access to the company's user data.

Law Enforcement Request System

The case came to light after posts on Telegram channels, where a group calling itself “Scattered Lapsus$ Hunters” claimed to have gained access to both LERS and eCheck, the FBI’s background check system. The hackers even posted screenshots that they said proved the breach.

Google's answer

The company was quick to downplay the threat, noting in a statement that the account was detected and disabled immediately. “No requests were made and no data was accessed,” a Google spokesperson said. However, the very fact that an unauthorized account was able to be created on such a critical portal is enough to raise serious security questions.

See also: FinWise Bank: Data breach affects American First Finance customers

The FBI, for its part, declined to comment on the allegations, leaving a veil of mystery surrounding the case.

Why the Law Enforcement Request System is so important

LERS is one of Google's most sensitive tools, as it is used to transmit orders to disclose user data in the context of court orders or emergencies. If an attacker gained full access, they could impersonate law enforcement and demand information from user accounts - from emails and chats to location data.

Although Google assured that this did not happen in this case, the existence of the gap shows how fragile the foundations of trust between technology companies and governments can become.

Google: Hackers created fake account in Law Enforcement Request System

Who are the "Scattered Lapsus$ Hunters"?

The group appears to be made up of hacker-extortionists from the Shiny Hunters, Scattered Spider, and Lapsus$. In the past, they have targeted high-profile companies with social engineering methods, compromising tools and code repositories.

One of the most notable incidents was the attacks on the Salesforce. There, members of the group convinced employees to connect tools to corporate accounts, subsequently gaining access to data that was used for blackmail. They then exploited code on Salesloft's GitHub, finding exposed credentials that they used for further attacks.

These attacks were not theoretical. They affected giants like Google, Adidas, Qantas, Cisco, Louis Vuitton, Cloudflare, Proofpoint, Palo Alto Networks and dozens of others.

See also: Sidewinder APT exploits protests in Nepal to distribute malware

The industry's response

Mandiant , Google's threat unit, was among the first organizations to expose the group's techniques, giving early warning to many businesses. However, this appears to have angered the "Scattered Lapsus$ Hunters," who often publicly mock Google, the FBI , and security researchers on social media.

After the latest revelation, however, they posted a lengthy message on a domain associated with BreachForums, hinting that they were about to withdraw. “Silence will now be our strength,” they wrote, hinting that future incidents of corporate breaches could be linked to them, even if they themselves do not appear openly.

The substance behind the statements

Although hackers claim to be “retreating,” cybersecurity experts estimate that they are likely to continue their operations more discreetly. This strategy is not new: many threat groups maintain a low profile after a period of intense activity to avoid the attention of authorities and ensure that their next attacks are harder to detect.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Google: Hackers created fake account in Law Enforcement Request System

The broader message

The LERS incident highlights a critical issue: even the most advanced platforms can become vulnerable when faced with internal or external threats. The creation of a fake account may not have led to a data leak this time, but it confirms that systems used for judicial and police requests are attractive targets for cybercriminals.

See also: Mustang Panda develops SnakeDisk USB Worm to distribute Yokai Backdoor

For businesses, the lesson is clear: they need to strengthen access monitoring, implement stricter identity checks , and invest in ongoing security auditing. Governments, on the other hand, are called upon to push for transparency and ensure that citizens’ data is not compromised by process gaps.

The case of Google and the “Scattered Lapsus$ Hunters” is not just a technical security detail. It is a reminder that platforms that handle the most sensitive data must be protected with stricter rules than ever. The battle between technology companies and organized hacking groups shows no sign of stopping. On the contrary, it is becoming increasingly complex, with cybercriminals constantly finding new ways to cause disruption and companies being forced to invest relentlessly in defense.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS