The hackers claim to possess the personal information of 22,000 federal employees, allegedly obtained during the Salesforce breach in the summer of 2025.

The cybercriminal collective Scattered Lapsus$ Hunters threatened, in an interview with 404 Media on October 20, 2025, to release the personal data of 22,000 U.S. government employees. The hackers say they obtained this information during the Salesforce compromise in mid-2025.

The company’s refusal to pay the ransom—announced in early October—reportedly prompted the group to act on its threats. According to 404 Media, Scattered Lapsus$ Hunters had already leaked, in mid-October, the personal details of hundreds of officials via its Telegram channel. This first act of doxing targeted employees from the Department of Homeland Security (DHS), the Immigration and Customs Enforcement (ICE) agency, the FBI, and the Department of Justice (DoJ). The outlet says it has verified the authenticity of the leaked data.

Scattered Lapsus$ Hunters brings together members of Scattered Spider, Lapsus$, and ShinyHunters. These three English-speaking groups are all affiliated with The Com, a networked cybercriminal ecosystem active across North America and the United Kingdom.

Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.
Stay tuned in real time
Subscribe to
the newsletter
By providing your email address you agree to receive the Incyber newsletter and you have read our privacy policy. You can unsubscribe at any time by clicking on the unsubscribe link in all our emails.