[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/new-shinysp1d3r-ransomware/)
* [Spanish (LATAM)](https://unit42.paloaltonetworks.com/es-la/new-shinysp1d3r-ransomware/)
* [French](https://unit42.paloaltonetworks.com/fr/new-shinysp1d3r-ransomware/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/new-shinysp1d3r-ransomware/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Insights](https://unit42.paloaltonetworks.com/category/insights/ "Insights")
* [Hospitality Hacks and Retail Reality Checks](https://unit42.paloaltonetworks.com/category/industry-insights-retail-hospitality/ "Hospitality Hacks and Retail Reality Checks")  
  [Hospitality Hacks and Retail Reality Checks](https://unit42.paloaltonetworks.com/category/industry-insights-retail-hospitality/)

# The Golden Scale: 'Tis the Season for Unwanted Gifts

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 6 min read  
Related Products  
[![Unit 42 Incident Response icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Incident Response](https://unit42.paloaltonetworks.com/product-category/unit-42-incident-response/ "Unit 42 Incident Response")[![Unit 42 Ransomware Readiness Assessment icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/unit42_RGB_logo_Icon_Color.png)Unit 42 Ransomware Readiness Assessment](https://unit42.paloaltonetworks.com/product-category/ransomware-readiness-assessment/ "Unit 42 Ransomware Readiness Assessment")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Matt Brady](https://unit42.paloaltonetworks.com/author/matt-brady/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:November 26, 2025

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Hospitality Hacks and Retail Reality Checks](https://unit42.paloaltonetworks.com/category/industry-insights-retail-hospitality/)
  * [Insights](https://unit42.paloaltonetworks.com/category/insights/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/)
  * [Lapsus$](https://unit42.paloaltonetworks.com/tag/lapsus/)
  * [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/)
  * [RaaS](https://unit42.paloaltonetworks.com/tag/raas/)
  * [Salesforce](https://unit42.paloaltonetworks.com/tag/salesforce/)
  * [Scattered LAPSUS$ Hunters](https://unit42.paloaltonetworks.com/tag/scattered-lapsus-hunters/)
  * [ShinySp1d3r](https://unit42.paloaltonetworks.com/tag/shinysp1d3r/)
  * [Telegram](https://unit42.paloaltonetworks.com/tag/telegram/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/new-shinysp1d3r-ransomware/?pdf=download&lg=en&_wpnonce=252a1929a6 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/new-shinysp1d3r-ransomware/?pdf=print&lg=en&_wpnonce=252a1929a6 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=The%20Golden%20Scale:%20'Tis%20the%20Season%20for%20Unwanted%20Gifts&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fnew-shinysp1d3r-ransomware%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnew-shinysp1d3r-ransomware%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnew-shinysp1d3r-ransomware%2F&title=The%20Golden%20Scale:%20'Tis%20the%20Season%20for%20Unwanted%20Gifts "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnew-shinysp1d3r-ransomware%2F&text=The%20Golden%20Scale:%20'Tis%20the%20Season%20for%20Unwanted%20Gifts "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fnew-shinysp1d3r-ransomware%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=The%20Golden%20Scale:%20'Tis%20the%20Season%20for%20Unwanted%20Gifts%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fnew-shinysp1d3r-ransomware%2F "Share in Mastodon")
  In October 2025, we published [two Insights blogs](https://unit42.paloaltonetworks.com/scattered-lapsus-hunters/) on threat activity affiliated with the cybercriminal alliance known as Scattered LAPSUS$ Hunters (SLSH). After a few weeks of apparent inactivity, the threat actors have returned with a vengeance based on open-source reporting and conversations obtained from a new Telegram channel (scattered LAPSUS$ hunters part 7). This latest Insights threat blog will detail several notable observations made by Unit 42 since mid-November, and prepares organizations as we head into the holiday season.

## New Data Theft Allegations and Imposed Deadline

On Nov. 20, 2025, Salesforce released a [security advisory](https://status.salesforce.com/generalmessages/20000233) acknowledging that they had detected "unusual activity involving Gainsight-published applications." This led the company to revoke "all active access and refresh tokens associated with Gainsight-published applications" while also temporarily removing such applications from their AppExchange while they conduct an investigation.

At the time of this writing time, Salesforce assesses that the activity was not a result of any vulnerability in their platform and that "this activity may have enabled unauthorized access to certain customers' Salesforce data through the app's connection." The company has notified all impacted customers and issued an additional advisory on Nov. 22, 2025 with a number of indicators of compromise (IoCs) related to this activity.

Based on [BleepingComputer's reporting](https://www.bleepingcomputer.com/news/security/salesforce-investigates-customer-data-theft-via-gainsight-breach/), Bling Libra (aka ShinyHunters) claimed to have gained access to an additional 285 Salesforce instances by breaching Gainsight. The threat group asserted they accomplished this using secrets obtained via their supply chain attack targeting Salesloft Drift in August 2025, which Unit 42 previously [reported](https://unit42.paloaltonetworks.com/threat-brief-compromised-salesforce-instances/) on Sep. 10, 2025.

Gainsight [acknowledged](https://www.gainsight.com/security/) on Sept. 3, 2025 that they were breached via stolen OAuth tokens linked to the Salesloft Drift attack. In this security alert the company confirmed the following types of information were likely accessed by the threat actors:

* Names
* Business email addresses
* Phone numbers
* Regional/location details
* Gainsight product licensing information
* Plain text content from certain support cases (not including attachments)

On Nov. 20, 2025, SLSH representatives posted a message within their newly created Telegram channel. It included an image that appears to represent a new dedicated leak site (DLS) with text reading "24 November 2025, stay tuned" as shown in Figure 1. This seemingly implies a deadline set for any companies affected by this latest data theft campaign to pay a ransom.
![Dark themed image displaying a screen with the text "SHINYHUNTERS" at the top. Below, a teaser message reads "24 November 2025, stay tuned." The image features engagement icons, a red heart with 4 likes, a clap with 1 like, and a message indicating 1.7K views. Time stamp reads "unc 3944, 11:21 PM."](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/word-image-324005-167198-1.jpeg) Figure 1. Screenshot of Telegram post to scattered LAPSUS$ hunters part 7 channel on Nov. 20, 2025. Source: Telegram.

On Nov. 21, 2025, SLSH posted another message shown in Figure 2, which functions as a warning to companies that have not yet been affected by their Salesforce data theft campaigns.
![Image displaying a text message discussing security incidents affecting Salesforce by hackers named ShinyHunters, Scattered Spider, and Lapsus$. The sender expresses confidence in resolving these issues and signs off as "SLH Newsroom." The message includes emojis and reactions from viewers.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/word-image-327618-167198-2.jpeg) Figure 2. Screenshot of Telegram post to scattered LAPSUS$ hunters part 7 channel on Nov. 21, 2025. Source: Telegram.

## Emergence of ShinySp1d3r Ransomware-as-a-Service

On Nov. 19, 2025, BleepingComputer [reported on a new ransomware-as-a-service (RaaS)](https://www.bleepingcomputer.com/news/security/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters/) program dubbed "ShinySp1d3r" which is allegedly still under active development by SLSH. The ransomware currently only works on Windows systems but representatives for the criminal syndicate told reporters that they are close to producing versions for Linux and ESXi systems.

[Unit 42 previously alluded to the development of ShinySp1d3r ransomware](https://unit42.paloaltonetworks.com/scattered-lapsus-hunters-updates/) in our last Insights blog on SLSH. Additionally, last week, we also published [timely threat intelligence](https://github.com/PaloAltoNetworks/Unit42-timely-threat-intel/blob/main/2025-11-21-IOCs-for-ShinySp1d3r-ransomware.txt) on our research into IoCs likely associated with this form of ransomware. Figures 3 and 4 provide further information on the encryptor portion of ShinySp1d3r upon successful execution.
![A computer screen displaying a ransomware notice titled "ShinySp1d3r Ransomware." The notice informs the user that their files have been encrypted and includes instructions to open an instructional file for further steps. Icons like the Recycle Bin and other typical desktop items are visible.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/word-image-330845-167198-3.png) Figure 3. Screenshot of ShinySp1d3r wallpaper. Source: Unit 42. ![Screenshot of a computer desktop displaying an open Notepad document titled "Ransom Note" with a message claiming a security breach. The desktop also shows other opened applications like SQL Server Management Studio and a network connections folder. The ransom note includes an overview for coordinating recovery.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/word-image-335325-167198-4.png) Figure 4. Screenshot of ShinySp1d3r ransom note. Source: Unit 42.

On Nov. 21, 2025, SLSH posted another Telegram message shown in Figure 5 where they threaten to deploy ShinySp1d3r ransomware for all of New York City and the State of New York.
![Text displayed in a social media post stating, "We are going to lock down the entire New York State and City with ShinySp1d3r. Mark. My. Words." followed by various emoji reactions including a clown face, a face with glasses, a thumbs up, and a flame.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/word-image-338829-167198-5.jpeg) Figure 5. Screenshot of Telegram post to scattered LAPSUS$ hunters part 7 channel on Nov. 21, 2025. Source: Telegram.

## Latest Insider Access Recruitment Attempts

On Nov. 21, 2025, CrowdStrike [confirmed](https://www.bleepingcomputer.com/news/security/crowdstrike-catches-insider-feeding-information-to-hackers/) to BleepingComputer that an employee had shared screenshots of internal systems with SLSH which were then posted to the group's Telegram channel. CrowdStrike asserted that the individual was terminated last month and that none of its systems were breached as a result of this activity. Bling Libra confirmed to reporters that they agreed to pay the insider $25,000 for access to CrowdStrike's network.

On the same day, SLSH posted several more Telegram messages further illustrated in Figures 6 and 7. The first image shown below highlights the industries that the threat actors were looking to solicit insiders from, which includes retail and hospitality organizations.
![Screenshot of a social media post discussing sectors targeted by the hacking group Scattered LAPSUS$ Hunters, listing various industries such as insurance, finance, automotive, hotels, telecom, gasoline companies, and investment companies, as well as reference to Five Eyes.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/word-image-341837-167198-6.jpeg) Figure 6. Screenshot of Telegram post to scattered LAPSUS$ hunters part 7 channel on Nov. 20, 2025. Source: Telegram.

The second image shown below illustrates how the threat actors are attempting to calm any unease that potential insiders may be feeling in the aftermath of CrowdStrike's insider detection.
![Text on a mobile screen displaying a message from the hacker group Scattered LAPUS$ Hunters that warns employees to cooperate with them to gain insider access, highlighting their method to bypass security with discretion and responsibility.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/word-image-345511-167198-7.jpeg) Figure 7. Screenshot of Telegram post to scattered LAPSUS$ hunters part 7 channel on Nov. 21, 2025. Source: Telegram.

## Looking Ahead to 2026

On Nov. 24, 2025, Gainsight [announced](https://www.cybersecuritydive.com/news/gainsight-applications-hold-salesforce/806277/) that connections to other SaaS platforms such as HubSpot and Zendesk were being temporarily suspended due to the supply chain attack. The company also encouraged customers to rotate their S3 keys as a precautionary measure.

At time of publication, Unit 42 had yet to identify any communications by the threat actors claiming to have leaked information related to their alleged Gainsight data theft campaign. However, they did post the following message to their Telegram channel on Nov. 24, 2025:

"pretty sure the 2025 victim count by us in total is ~1.5k (1000 already publicly reported) and still increasing"

My overall prediction when it comes to these financially-motivated threat actors in 2026 and beyond is more of the same: unwavering chaos. We previously expected SLSH to take a break and reemerge at the beginning of the new calendar year with the aforementioned activities, but they have seemingly decided to expedite that timeline based on these latest observations. The emergence of a RaaS program, in conjunction with an EaaS offering, makes SLSH a formidable adversary in terms of the wide net they can cast against organizations using multiple methods to monetize their intrusion operations. Additionally, the insider recruitment element adds yet another layer for organizations to defend against.

The timing of these developments could not be worse for most organizations, especially retailers, as they ramp up for the biggest shopping weeks of the calendar year. Figure 8 provides more insight on how the threat actors plan to operate in the coming weeks, which seemingly alludes to more customer data potentially being leaked to their DLS.
![Screenshot of a social media post warning that all the IR people should monitor their logs over the holidays due to #ShinyHuntazz targeting customer databases, with various emoji reactions including a distressed face, fire, smiley, alien, and detective. Posted at 5:43 PM with 1.3K interactions.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/11/word-image-349430-167198-8.jpeg) Figure 8. Screenshot of Telegram post to scattered LAPSUS$ hunters part 7 channel on Nov. 23, 2025. Source: Telegram.

Palo Alto Networks recently [predicted](https://www.paloaltonetworks.com/company/press/2025/palo-alto-networks-forecasts-6-predictions-on-securing-the-new-ai-economy-for-2026) that 2026 will be the "Year of the Defender" with regards to applying AI-driven defenses to combat AI-powered attacks. I strongly believe that this sentiment of 2026 being the year of the defender also needs to hold true if we are to collectively defeat the many fronts that SLSH is targeting organizations from.

One of the best gifts you can give your organization this time of year is joining and actively participating in an industry-specific Information Sharing and Analysis Center --- this enables your network defenders to learn from other peer institutions and collectively shift the outcome to "left of bang."

Unit 42 is ready to help support your organization with an active compromise or to provide a proactive assessment to lower your organization's risk related to this evolving threat activity.
Back to top

### Tags

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")
* [Lapsus$](https://unit42.paloaltonetworks.com/tag/lapsus/ "Lapsus$")
* [Leak site](https://unit42.paloaltonetworks.com/tag/leak-site/ "Leak site")
* [RaaS](https://unit42.paloaltonetworks.com/tag/raas/ "RaaS")
* [Salesforce](https://unit42.paloaltonetworks.com/tag/salesforce/ "Salesforce")
* [Scattered LAPSUS$ Hunters](https://unit42.paloaltonetworks.com/tag/scattered-lapsus-hunters/ "Scattered LAPSUS$ Hunters")
* [ShinySp1d3r](https://unit42.paloaltonetworks.com/tag/shinysp1d3r/ "ShinySp1d3r")
* [Telegram](https://unit42.paloaltonetworks.com/tag/telegram/ "Telegram")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: "Shai-Hulud" Worm Compromises npm Ecosystem in Supply Chain Attack (Updated November 26)](https://unit42.paloaltonetworks.com/npm-supply-chain-attack/ "\"Shai-Hulud\" Worm Compromises npm Ecosystem in Supply Chain Attack (Updated November 26)")

### Table of Contents

* 

### Related Articles

* [The Permanent Threat: Analyzing Aeternum's Blockchain-Based C2 Operations and Communications](https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/ "article - table of contents")
* [No Manners Here: The Ruthless Rise of The Gentlemen Ransomware](https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/ "article - table of contents")
* [Out of the Crypt: The Evolving Cyber Extortion Economy](https://unit42.paloaltonetworks.com/cyber-extortion-economy/ "article - table of contents")

## Related Hospitality Hacks and Retail Reality Checks Resources

![A board room against a backdrop of windows showing a cityscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/05_Opinion_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) July 10, 2026 [#### No Manners Here: The Ruthless Rise of The Gentlemen Ransomware](https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/)

* [Howling Scorpius](https://unit42.paloaltonetworks.com/tag/howling-scorpius/ "Howling Scorpius")

* [RaaS](https://unit42.paloaltonetworks.com/tag/raas/ "RaaS")

* [Spikey Scorpius](https://unit42.paloaltonetworks.com/tag/spikey-scorpius/ "Spikey Scorpius")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/the-gentlemen-ransomware/ "No Manners Here: The Ruthless Rise of The Gentlemen Ransomware")  
  ![Pictorial representation of a command center featuring glowing wireframe figures standing on a reflective circular pattern.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/12_Myth-Busting_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) March 20, 2026 [#### Who's Really Shopping? Retail Fraud in the Age of Agentic AI](https://unit42.paloaltonetworks.com/retail-fraud-agentic-ai/)

* [Agentic AI](https://unit42.paloaltonetworks.com/tag/agentic-ai/ "Agentic AI")

* [E-commerce](https://unit42.paloaltonetworks.com/tag/e-commerce/ "e-commerce")

* [Retail](https://unit42.paloaltonetworks.com/tag/retail/ "Retail")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/retail-fraud-agentic-ai/ "Who’s Really Shopping? Retail Fraud in the Age of Agentic AI")  
  ![Pictorial illustration of the libra sign on a purple, starry background with orange highlights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/Libra-Cybercrime-A-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) October 20, 2025 [#### The Golden Scale: Notable Threat Updates and Looking Ahead](https://unit42.paloaltonetworks.com/scattered-lapsus-hunters-updates/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Lapsus$](https://unit42.paloaltonetworks.com/tag/lapsus/ "Lapsus$")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/scattered-lapsus-hunters-updates/ "The Golden Scale: Notable Threat Updates and Looking Ahead")  
  ![Pictorial illustration of Bling Libra on a purple, starry background with orange highlights.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/10/03-2-Bling-Libra-1920x900-1-786x368.png)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) October 10, 2025 [#### The Golden Scale: Bling Libra and the Evolving Extortion Economy](https://unit42.paloaltonetworks.com/scattered-lapsus-hunters/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Lapsus$](https://unit42.paloaltonetworks.com/tag/lapsus/ "Lapsus$")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/scattered-lapsus-hunters/ "The Golden Scale: Bling Libra and the Evolving Extortion Economy")  
  ![Pictorial representation of individuals looking at computer monitors with large, glowing world map on a screen behind them.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/06_General_Category_1505x922-718x440.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) September 9, 2025 [#### Data Is the New Diamond: Latest Moves by Hackers and Defenders](https://unit42.paloaltonetworks.com/data-is-the-new-diamond-latest-moves-by-hackers-and-defenders/)

* [Muddled Libra](https://unit42.paloaltonetworks.com/tag/muddled-libra/ "Muddled Libra")

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/data-is-the-new-diamond-latest-moves-by-hackers-and-defenders/ "Data Is the New Diamond: Latest Moves by Hackers and Defenders")  
  ![Pictorial representation of a man silhouetted against a background of towering skyscarpers covered in colorful data and abstract code.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/03_Resize_Myth-Busting_Overview_1920x900-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 26, 2025 [#### Data Is the New Diamond: Heists in the Digital Age](https://unit42.paloaltonetworks.com/retail-hospitality-heists-in-the-digital-age/)

* [Bling Libra](https://unit42.paloaltonetworks.com/tag/bling-libra/ "Bling Libra")

* [Extortion](https://unit42.paloaltonetworks.com/tag/extortion/ "Extortion")

* [Social engineering](https://unit42.paloaltonetworks.com/tag/social-engineering/ "social engineering")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/retail-hospitality-heists-in-the-digital-age/ "Data Is the New Diamond: Heists in the Digital Age")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/content/pan/en_US/cortex/managed-detection-and-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
