Security researchers have observed a surge in new phishing infrastructure that closely tracks the tactics, techniques, and procedures of “SLSH,” a loose alliance of Scattered Spider, LAPSUS$, and ShinyHunters.
Unlike broad, automated phishing, this is a human‑driven vishing operation where attackers actively guide each victim through the login process in real time.
Their main focus is Okta SSO and similar identity providers, because compromising a single SSO session can unlock access to dozens or even hundreds of internal and SaaS applications at once.
Who Is SLSH and How They Operate
SLSH (short for “Scattered LAPSUS$ Hunters”) grew out of “The Com” ecosystem, combining Scattered Spider’s social‑engineering skills with LAPSUS$‑style data theft and extortion playbooks.
The group is financially motivated and focuses on gaining initial access to large enterprises by abusing their SSO and identity stacks rather than attacking individual applications.
At the heart of the campaign is a new “live phishing panel” that lets an attacker sit between the victim and the real identity provider, intercepting usernames, passwords, and MFA prompts as they are entered.
This live‑in‑the‑middle approach allows immediate session hijacking and persistent access to corporate dashboards and admin consoles.
High-value Targets Across Industries
Silent Push reports active targeting or infrastructure preparation against more than 100 organizations over the last 30 days, cutting across technology, fintech, healthcare, real estate, energy, and more.
Notable technology and software companies on the list include Canva, Atlassian, Epic Games, HubSpot, RingCentral, ZoomInfo, and Iron Mountain.
Other impacted sectors include:
- Fintech and payments: firms such as Adyen, Jack Henry, Shift4 Payments, and SoFi.
- Biotech and pharma: companies including Amgen, Biogen, Gilead Sciences, and Moderna.
- Financial services and banking: organizations like Apollo Global Management, Blackstone, RBC, State Street, and TPG Capital.
- Real estate and REITs: major names such as CBRE, Redfin, RE/MAX, Simon Property Group, Public Storage, and WeWork.
Additional targets span infrastructure and energy providers, healthcare and MedTech firms, HR tech platforms, logistics providers, manufacturers, retailers, insurers, law firms, and telecom operators such as Telstra.
Why This campaign Is So Dangerous
Traditional security awareness training often falls short against SLSH because the attackers are skilled callers who adapt on the fly and tailor their script to each help desk agent or employee.
While they are on the phone, they direct victims to a phishing site that closely mimics their SSO login portal, updating the page in real time to match any unexpected prompts or MFA challenges.
The risks to organizations are severe:
- Total SSO account takeover: Once the attacker hijacks a session, they effectively gain a “skeleton key” into every app linked to that identity provider.
- Rapid data exfiltration and extortion: Following the LAPSUS$ model, they prioritize stealing sensitive data and then threatening public leaks to force payment.
- Lateral movement through collaboration tools: Compromised Slack or Teams accounts are used to impersonate staff and trick admins into granting higher privileges.
- Possible data encryption and ransomware: After stealing data, SLSH may encrypt critical systems and demand ransom for both decryption and non‑disclosure.
Immediate Defensive Steps For Enterprises
Enterprises should assume they may already be in scope and act before any official breach notification arrives.
First, security teams must warn help desks and employees that targeted vishing against identity and SSO accounts is active, and set a clear rule that any call requesting MFA codes or password resets must be treated as suspicious and escalated.
Second, organizations should intensively review Okta and other SSO logs, looking for patterns such as “new device enrolled” events followed quickly by logins from unusual or foreign IP addresses.
Finally, proactive domain‑level intelligence such as monitoring for look‑alike or newly registered domains that mimic corporate login portals can help block live phishing panels before they are used in calls.
Together, these measures can significantly reduce the chance that ShinyHunters and their SLSH partners turn an SSO login into full enterprise compromise.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.