Hackers associated with the group “Scattered Lapsus$ Hunters” (SLH) claim to have breached the systems of cybersecurity firm Resecurity and stolen internal data. For its part, Resecurity responds that the attackers only gained access to a deliberately installed honeypot, which contained fake information and was used to monitor their activity.
See also: Hackers stole $3.9 million from Unleash Protocol

The perpetrators posted screenshots of the alleged breach on Telegram, claiming to have obtained employee data, internal emails, threat intelligence reports, and customer details. As evidence, they released images they said came from Resecurity, including a Mattermost collaboration environment showing communications between Resecurity employees and Pastebin executives regarding malicious content hosted on the platform.
The perpetrators, who call themselves “Scattered Lapsus$ Hunters” due to the alleged overlap of the ShinyHunters, Lapsus$, and Scattered Spider groups, said the attack was in retaliation for what they claim are ongoing attempts by Resecurity to socially manipulate them and extract information about their activities.
According to them, Resecurity employees posed as buyers during the sale of a supposed database of the Vietnamese financial system, requesting free samples and additional information.
See also: Careto team returns after 10 years with new tactics

After the article was published, a ShinyHunters spokesperson told BleepingComputer that they had no involvement in the incident. Although ShinyHunters has previously claimed to be part of the Scattered Lapsus$ Hunters, they clarified that they were not involved in this specific attack.
Resecurity disputes the threat actors' claims, arguing that the systems allegedly compromised were not part of its actual production infrastructure, but were a honeypot designed to attract and monitor attackers.
After BleepingComputer contacted Resecurity about the allegations, the company shared a report published on December 24th, stating that it first detected a threat actor probing its publicly exposed systems on November 21st, 2025.
According to the company, the DFIR team identified early reconnaissance signals and recorded multiple IP addresses linked to the perpetrator, including those originating from Egypt and Mullvad VPN services.
See also: Cybercrime: Hackers are more organized than IT

Resecurity said it responded by creating a “honeypot” account in an isolated environment, which allowed the threat actor to connect to and interact with systems containing fake employee, customer and payment data, while being under constant monitoring by researchers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
