TrollEye Security

Cyber News

CrowdStrike Confirms Insider Fed Information to Hackers

CrowdStrike has confirmed an employee shared internal screenshots with external threat actors after the images surfaced on Telegram channels tied to Scattered Lapsus$ Hunters, though the company says no systems

Insider Incident Involved Leaked Internal Screenshots via Telegram Channels

CrowdStrike has confirmed that an internal employee shared screenshots from company systems with external threat actors after the images surfaced on Telegram channels linked to the Scattered Lapsus$ Hunters collective. The company stated that no systems were breached and that customer data and environments were not impacted.

The employee was identified through internal monitoring, removed from their role, and the matter has been referred to law enforcement, with the activity contained before any broader compromise could occur.

How the Incident Unfolded

Screenshots from internal CrowdStrike environments were published by threat actors associated with ShinyHunters, Scattered Spider, and Lapsus$, now loosely grouped under the Scattered Lapsus$ Hunters label. These images were captured by an employee with authorized access and shared externally.

Based on available information, the insider attempted to facilitate further access by passing along authentication-related artifacts connected to single sign-on activity. CrowdStrike detected the behavior early and revoked access before these assets could be used to gain operational or system-level access.

The group also stated that they agreed to pay $25,000 in exchange for access to CrowdStrike’s network, characterizing the incident as a financially motivated insider exploitation attempt. In addition, they claimed efforts to purchase internal CrowdStrike reports referencing ShinyHunters and Scattered Spider, though those materials were reportedly not received.

Coordinated Threat Actor Activity

The incident aligns with ongoing campaigns linked to Scattered Lapsus$ Hunters, a collective known for leveraging social engineering and insider exploitation rather than direct infrastructure compromise. Throughout 2025, the group has targeted organizations via voice phishing focused on Salesforce environments, affecting companies across technology, finance, retail, aviation, and luxury sectors.

They’ve also claimed responsibility for high-impact operational disruptions, including the Jaguar Land Rover incident that resulted in significant financial loss and operational downtime.

These actors are consolidating their operations under a new ransomware-as-a-service platform, ShinySp1d3r, reflecting a shift toward more centralized, scalable extortion tactics. This change enables faster access monetization and more aggressive targeting across global enterprises.

Defending Against Insider Threats

While CrowdStrike successfully prevented systemic compromise, this incident reinforces a persistent reality: insider misuse remains one of the most difficult and least predictable threat vectors, even for mature security programs. When attackers exploit trusted access and legitimate credentials, traditional perimeter-focused controls quickly lose effectiveness.

Reducing this exposure requires a deliberate shift toward identity-centric defense. Organizations must prioritize continuous behavior monitoring, strict privilege governance, and real-time validation of user activity, treating access and identity as active attack surfaces rather than static permissions. Without this approach embedded into a broader threat exposure management strategy, even well-defended environments remain vulnerable to risks that originate from within.

Share:

Live Webinar

From Discovery to
Risk Reduction

Operationalizing CTEM in Modern Security Programs

Date September 24, 2026
Time 2:00 PM Eastern

Learn how modern security teams can move beyond finding exposures and operationalize every stage of Continuous Threat Exposure Management.

01 Scope
02 Discover
03 Prioritize
04 Validate
05 Mobilize
Reserve Your Spot

Free registration · Live discussion and Q&A

This Content Is Gated