An underground group of teenage hackers has gained notoriety for crippling some of the UK’s largest brands. Jaguar Land Rover was forced to close factories after a cyberattack, the Co-op faced empty shelves for months, and Marks & Spencer shut down online shopping following a hack that reportedly cost up to £300 million. Last week, the group claimed to have stolen nearly a billion customer records from Salesforce, affecting major clients like Disney, Toyota, McDonald’s, and Adidas.
The hackers, calling themselves Scattered Lapsus$ Hunters, emerged from three loosely connected groups: Scattered Spider, ShinyHunters, and Lapsus$, all part of a broader underground network known as “The Com.” According to cybersecurity experts, members are predominantly 16 to 21 years old, English-speaking, and recruited via gaming platforms and dark web forums. Their primary motivation is financial gain, but there is also a competitive “gamification” aspect, with hackers seeking to hit bigger companies and maximize disruption.
The group’s attacks rely heavily on social engineering, particularly “vishing” (voice phishing), where members impersonate company IT departments to gain credentials or remote access. They often exploit stolen log-ins for software such as Jira, then demand ransom via encrypted channels or public dark web messages. Salesforce has refused to negotiate with the group.
Tracking the hackers is difficult due to the constantly shifting landscape of Telegram channels and dark web forums. The National Crime Agency says it has moved from proactive monitoring to reactive investigations because of the sheer volume of attacks. Recent arrests of four teenagers in the UK did little to slow the group, which has continued operations and launched the Salesforce attack despite claiming to have “gone dark.”

