Cybercrime Mergers
A newly formed hacking collective calling itself Scattered LapSus Hunters has issued an ultimatum to Google: fire two senior members of its Threat Intelligence Group or face a massive data leak. The group claims to be a coalition of notorious cybercriminal factions, Scattered Spider, Lapsus$, and ShinyHunters, each infamous for high-profile breaches and sophisticated tactics.
Organized cybercrime has been professionalizing for many years. But the conglomeration of threat actor groups has intensified. Just as companies merge to pool resources, talent, and market share, cybercriminals are now combining their specialized skill sets.
This “supergroup” model mirrors the evolution of legitimate business ecosystems. Scattered Spider, for example, has acted as an initial access broker, while ShinyHunters specializes in data breaches and resale. By joining forces, these groups can streamline operations, share infrastructure, and coordinate attacks with increased efficiency. I guess even threat actors have KPIs.
But the professionalization doesn’t stop there.
Cybercriminal organizations are increasingly adopting corporate organizational structures. Some now post recruitment ads on dark web forums, offering competitive salaries, bonuses, and even affiliate programs. In one investigation, researchers posed as applicants and were interviewed by ransomware operators affiliated with REvil and Ragnar Locker. The job came with a revenue share of up to 80% and required technical vetting and cultural alignment—including trivia tests to verify Russian fluency.
This shift toward professionalism is fueled by the rise of Cybercrime-as-a-Service (CaaS). Ransomware-as-a-Service (RaaS), Initial Access Brokers (IABs), and Crypter-as-a-Service models have lowered the barrier to entry, allowing even low-skilled actors to participate in sophisticated campaigns. The underground economy now resembles a thriving marketplace, complete with customer support, product demos, and service-level agreements.
For defenders, this evolution presents a sobering challenge. The adversary is no longer a lone hacker in a basement. Now we face well-funded, well-organized syndicates with specialized roles and scalable infrastructure. As threat actors become more professional, so must we.
Investment in modern threat intelligence, cross-functional security teams, and strategic partnerships with cybersecurity experts are quickly becoming mandatory expenditures for businesses interested in using the internet in any capacity. Just as attackers collaborate across borders and specialties, defenders must break down silos and adopt a proactive, intelligence-driven approach.
Cybersecurity is no longer just an IT issue. It’s a business imperative. And in this new era of cybercrime conglomerates, cybersecurity professionalism and evolution is no longer optional.