A cybercrime alliance known as the Trinity of Chaos, comprising the threat groups LAPSUS$, Scattered Spider, and ShinyHunters, has recently disbanded, but intelligence reports indicate that its members are likely to continue their malicious activities. The alliance, also referred to as Scattered Lapsus$ Hunters, was formed to pool resources and expertise among these high-profile cybercriminal groups. Despite the formal dissolution of the collective, ShinyHunters have already claimed responsibility for new attacks targeting the financial services sector, demonstrating that the threat from these actors remains active. Security researchers from Resecurity and ReliaQuest have observed similar intrusion patterns attributed to Scattered Spider, suggesting ongoing operations by former alliance members. The groups involved in the Trinity of Chaos have previously been linked to significant breaches affecting major organizations such as Google, Qantas, and LVMH, which has bolstered their reputation within the cybercriminal ecosystem. Analysts believe that the disbandment is likely a strategic move, allowing the groups to reorganize and rebrand under new identities while evading law enforcement scrutiny. This tactic mirrors previous behavior seen in the cybercrime landscape, such as the Conti ransomware gang's public exit and subsequent reemergence under different names. The alliance's connection to The Com collective further underscores the collaborative nature of modern cybercrime, where threat actors share tools, tactics, and intelligence. Security experts warn that the credibility and experience gained from past high-profile intrusions will make these groups even more formidable as they resurface. The ongoing threat is compounded by the likelihood that these actors will adopt new monikers and operational structures, making detection and attribution more challenging for defenders. The financial services industry remains a primary target, but the groups' history suggests that other sectors could also be at risk. The use of distributed denial-of-service (DDoS) attacks and sophisticated intrusion techniques has been a hallmark of their operations. Organizations are advised to remain vigilant and update their threat models to account for the evolving tactics of these adversaries. The dissolution of the Trinity of Chaos does not signal a reduction in cyber risk; rather, it marks a transition to a new phase of activity by its constituent groups. Intelligence sharing and proactive defense measures are critical to mitigating the impact of future attacks. The cybercrime landscape continues to evolve, with alliances forming and dissolving as threat actors adapt to law enforcement pressure and shifting opportunities. The legacy of the Trinity of Chaos is likely to influence cybercriminal collaboration and operational strategies for the foreseeable future.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
The Guardian reported that the cybercrime network known as The Com was behind a recent hack affecting Pornhub. This adds a new publicly identified victim to the broader campaign associated with The Com and its linked actors.
ZeroFox published a flash report describing a powerful new ransomware-as-a-service operation linked to actors associated with Scattered Spider, LAPSUS$, and ShinyHunters. The report suggests the alliance's restructuring evolved into a more formalized ransomware capability beyond the previously reported attacks.
Resecurity said the full scale of the campaign is only beginning to surface because the actors often use private extortion to keep incidents out of public view. The report also noted Tata Consultancy Services' connection as an IT provider to several targeted companies.
Following the disruptive attack on Jaguar Land Rover, the UK government responded with substantial financial support to the company. The move underscored the severity of the incident and the broader national concern around the campaign.
The latest wave of attacks was reported to have hit Jaguar Land Rover, Marks & Spencer, and Co-op, causing significant operational and financial impact. Security researchers said many additional victims and breaches tied to the campaign have not yet been publicly disclosed.
Resecurity and ReliaQuest reported new intrusions and assessed that Scattered Spider, LAPSUS$, and ShinyHunters-linked actors were actively reorganizing and launching fresh attacks despite claims of disbandment or retirement. The activity included new attacks claimed by ShinyHunters against the financial services sector.
Before the latest reporting, ShinyHunters had indicated it was stepping back from ransomware activity. Researchers later assessed this apparent exit as likely tactical rather than a genuine end to operations.
Researchers cited prior attacks attributed to actors tied to the alliance, including intrusions affecting Google, Qantas, and LVMH. These incidents were presented as part of the group's broader campaign history before the latest restructuring disclosures.
Resecurity reported that members associated with LAPSUS$, ShinyHunters, and Scattered Spider forged a collaborative cybercrime alliance later dubbed the 'Trinity of Chaos.' Researchers linked the grouping to The Com collective and assessed it as a coordinated criminal partnership rather than isolated actors.
Cyber Daily reported that ShinyHunters had joined with Scattered Spider in a new hacking 'supergroup' and was teasing major forthcoming leaks. The report marked an earlier public indication of collaboration between the actors before later 'Trinity of Chaos' reporting expanded the alliance to include additional members.
ReliaQuest reported that ShinyHunters was likely collaborating with, or significantly overlapping with, Scattered Spider based on converging tactics, infrastructure, and victimology. The researchers cited shared use of IT-support impersonation vishing, Okta-themed phishing pages, Salesforce Data Loader abuse, Mullvad VPN, and similar sector targeting.
CBS News reported that Scattered Spider had teamed up with the BlackCat/ALPHV ransomware gang, marking a notable collaboration between the social-engineering-focused group and an established Russian-speaking ransomware operation. This reflects an earlier stage in Scattered Spider's evolution before the later 'Trinity of Chaos' reporting.
16 references tracked. Mallory keeps watching after this page renders.
darkreading.com
Open sourcetheguardian.com
Open sourcehalcyon.ai
Open sourcecyfirma.com
Open sourcetheregister.com
Open sourcefalconfeeds.io
Open sourcecomputerweekly.com
Open sourcecbsnews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.