CrowdStrike fires ‘suspicious insider’ who passed information to hackers

CrowdStrike fires ‘suspicious insider’ who passed information to hackers

In a significant security breach, CrowdStrike, a leading cybersecurity firm, has reported the termination of an employee suspected of leaking sensitive information to a notorious hacker group. This action took place last month, triggered by allegations that the insider provided access details to the Scattered Lapsus$ Hunters, a collective known for its aggressive cyber tactics. Screenshots were shared on a public Telegram channel by the hacking group, purportedly showcasing unauthorized access to CrowdStrike's internal systems. TechCrunch has verified these images, which include links to various company resources and an employee's Okta dashboard, commonly used for accessing internal applications. The hackers claimed their entry into CrowdStrike originated from a recent breach at Gainsight, a customer relationship management platform that services Salesforce customers. They asserted that they exploited stolen information from Gainsight to infiltrate CrowdStrike's systems. However, CrowdStrike has firmly rejected these claims, emphasizing that their systems were not compromised. The spokesperson, Kevin Benacci, clarified that the company acted swiftly to revoke the insider's access upon discovering that he had shared images of his monitor externally. "Our systems were never compromised, and customers remained protected throughout this incident. We have handed the matter over to the appropriate law enforcement authorities," Benacci stated. This incident is part of a broader campaign, as multiple tech companies have reportedly been targeted under similar circumstances. The Scattered Lapsus$ Hunters group, which comprises various hacking factions including ShinyHunters and Scattered Spider, is known for employing social engineering strategies to deceive employees into granting system access. Just last month, the group boasted about acquiring over a billion records from major corporations that utilize Salesforce for customer data management, creating a data leak site that listed numerous victims, including Allianz Life, Qantas, Stellantis, TransUnion, and Workday.

Sources : TechCrunch

Published On : Nov 21, 2025, 19:05

Mobile
WhatsApp's New Cloud Backup Feature: A Game-Changer for iPhone Users

WhatsApp is reportedly in the process of creating a cloud storage solution tailored for iPhone users, allowing them to b...

Business Today | Jul 15, 2026, 08:05
WhatsApp's New Cloud Backup Feature: A Game-Changer for iPhone Users
Cybersecurity
New Social Media Measures Proposed for UK Teens to Enhance Online Safety

The U.K. government has unveiled a set of new proposals aimed at safeguarding older teenagers on social media platforms....

CNBC | Jul 15, 2026, 10:15
New Social Media Measures Proposed for UK Teens to Enhance Online Safety
Startups
Emergent Soars to Unicorn Status with $130M Funding Boost

Emergent, an Indian startup specializing in AI coding solutions, has successfully secured $130 million in a Series C fun...

TechCrunch | Jul 15, 2026, 12:30
Emergent Soars to Unicorn Status with $130M Funding Boost
AI
Alibaba's Shares Surge Following Apple Integration of Qwen AI

Shares of Alibaba, the Chinese multinational conglomerate, experienced a notable 4% increase in premarket trading on Wed...

CNBC | Jul 15, 2026, 12:05
Alibaba's Shares Surge Following Apple Integration of Qwen AI
Cybersecurity
Cybersecurity Alert: Kudankulam Nuclear Power Plant Faces Data Breach Crisis

The Kudankulam Nuclear Power Plant, located in Tamil Nadu, has reportedly fallen victim to a cyberattack by a ransomware...

Business Today | Jul 15, 2026, 12:20
Cybersecurity Alert: Kudankulam Nuclear Power Plant Faces Data Breach Crisis
View All News