Krebs reports SLSH uses harassment alongside data extortion

THE BRIEF
Krebs on Security reports that a data-extortion group calling itself Scattered Lapsus ShinyHunters (SLSH) uses a pressure campaign that extends beyond demands for payment. The group is described as harassing, threatening, and sometimes swatting executives and their families while also notifying journalists and regulators about an intrusion’s reported scope. According to the report, some victims may be paying, potentially to contain stolen data and stop escalating personal attacks. A source identified as a top SLSH expert advises organizations not to engage beyond a clear “We’re not paying” response, arguing that further engagement encourages harassment. The report characterizes SLSH as an unruly, fluid, English-language extortion gang rather than a highly regimented Russia-based ransomware affiliate group. It also says the group has a fractious and unreliable history. These details are reported claims; the supplied excerpt does not independently establish the group’s membership, the incidents involved, or whether any particular organization paid.
WHY IT MATTERS
This report highlights how extortion pressure can target people as well as systems and data. Harassment, threats, swatting, and outreach to journalists or regulators can complicate an organization’s response, particularly when leaders and families become direct targets. The reported advice also underscores the importance of having a disciplined engagement policy before an incident occurs. Organizations should distinguish verified facts from claims, avoid assuming that payment ends the pressure, and prepare for communications that may involve executives, employees, legal teams, regulators, and media. The excerpt does not establish how often these tactics succeed, so it should inform preparedness rather than predict outcomes.
WHO SHOULD CARE
Security leaders, incident-response teams, executive-protection and corporate communications staff, legal counsel, and organizations handling sensitive data should care. The report is especially relevant to firms that may face data-extortion demands accompanied by personal pressure on executives or their families.
WHAT TO DO NOW
- Set a documented incident rule for who may communicate with an extortion group and what authority is required; include the option of a concise no-payment response.
- Build a response roster linking security, legal, communications, executive leadership, and appropriate authorities before an incident.
- Prepare procedures for handling threats, harassment, or swatting reports involving executives and families, including escalation and safety coordination.