October 6, 2025
Updated: August 31, 2026
Unmasking the cyber criminals redefining digital warfare
Khaled Hassan

The most dangerous hackers of 2026 are not lone geniuses in hoodies; they are organized crews and state-backed units that run like businesses, a ransomware cartel with a help desk, a teenage social-engineering gang that talks its way past IT, a nation-state unit siphoning billions in crypto, and espionage groups sitting silently inside critical infrastructure. This guide profiles the most notorious hackers and hacking groups of 2026, the record-breaking attacks they pulled off, what changed since 2025, and the defenses that actually blunt them.
Updated: August 2026. Reflects the record 2025 ransomware year (Qilin), the ShinyHunters Salesforce campaign, Lazarus's $1.5B Bybit heist, Cl0p's Oracle EBS extortion, and the Scattered Spider arrests.

| Group | Type | Known for |
|---|---|---|
| Scattered Spider | Social-engineering crew | Talking past help desks; MGM, UK retail, insurers, airlines |
| ShinyHunters | Data-theft extortion | The Salesforce/Salesloft Drift campaign, 1.5B records |
| Lazarus Group | North Korean state | The $1.5B Bybit crypto heist, the largest ever |
| Qilin | Ransomware-as-a-service | The most active ransomware operation of 2025 |
| Cl0p | Mass-exploitation extortion | MOVEit, Cleo, and the 2025 Oracle EBS zero-day wave |
| Salt Typhoon | Chinese espionage APT | Breaching US telecoms and wiretap systems |
| Volt Typhoon | Chinese disruption APT | Pre-positioning in US critical infrastructure |
| Predatory Sparrow | Israel-linked destructive | Burning $90M at Iran's Nobitex exchange |
The one-line theme of 2026: cybercrime is industrialized and specialized, and the line between financially-motivated gangs and state operations keeps blurring.
Notoriety today is measured in impact and reach, not technical mystique. The groups below earn the label because they caused record financial losses, breached the systems the rest of the internet depends on, or demonstrated capabilities that redraw the threat model. Three profiles dominate: ransomware and extortion crews chasing money at scale, state-sponsored units pursuing espionage or strategic disruption, and hybrid social-engineering gangs that weaponize people rather than exploits. Understanding who they are is the first step to defending against them, which is why this sits alongside our broader threat coverage like ransomware groups.
Scattered Spider (also tracked as UNC3944, Octo Tempest) is the crew that proved you don't need zero-days when you can just call the help desk. Made up largely of English-speaking teenagers and young adults in the US and UK, it specializes in social engineering: impersonating employees to IT support, abusing MFA reset workflows, and SIM-swapping to hijack accounts, then pivoting to ransomware or extortion. The FBI and CISA document these techniques in a joint Scattered Spider advisory, and the wider pattern shows up in our social engineering statistics.
After the infamous 2023 MGM and Caesars casino breaches, the group tore through 2025, hitting UK retailers (Marks & Spencer, Co-op, Harrods), insurers, and airlines. Law enforcement has landed real blows, multiple alleged members were arrested and charged across 2024-2026, including extraditions to the US, yet the group kept operating, partly by merging efforts with other crews under the "Scattered LAPSUS$ Hunters" banner. It is the clearest proof that the human layer, not the firewall, is the modern soft target.
ShinyHunters (UNC6040/UNC6395) ran one of the largest data-theft campaigns in history in 2025. Rather than breach each victim directly, the group compromised Salesloft's GitHub, stole OAuth tokens for the Salesloft Drift integration, and used them to reach into hundreds of downstream Salesforce environments. The result: an estimated 1.5 billion records from 760+ organizations, with confirmed victims including Cloudflare, Zscaler, Palo Alto Networks, Tenable, Proofpoint, and Grubhub, followed by extortion demands. The campaign was documented by Google Threat Intelligence, which tracks the actor as UNC6395.
It is the defining SaaS supply-chain attack of the era: one trusted integration became a skeleton key to a thousand tenants. The lesson for defenders is that your third-party OAuth grants are attack surface, exactly the third-party risk problem, and that data-theft extortion is now as damaging as encryption-based ransomware.

Lazarus (with sub-clusters like TraderTraitor) is North Korea's state hacking apparatus, and its mission is to steal money to fund the regime, especially cryptocurrency. In February 2025 it pulled off the largest crypto heist ever, exploiting a third-party signing weakness in Bybit's cold-wallet workflow to steal roughly $1.5 billion in Ethereum. The FBI attributed the theft to North Korean actors it tracks as TraderTraitor. Lazarus has been behind a long string of exchange and DeFi thefts, and it laundered the Bybit proceeds through mixers at blistering speed.
Lazarus matters because it shows a nation-state running cybercrime at industrial scale for revenue, blurring the line between espionage and theft, a dynamic we track in our crypto crime coverage.
If 2025 had a ransomware king, it was Qilin. The ransomware-as-a-service operation became the most active on the planet, claiming more victims than any rival, over a thousand attacks in the year and a reported ~29% of all ransomware activity by late 2025, and it surged further into 2026 as competitors like RansomHub faded. Its victim list is indiscriminate: courts, school districts, healthcare practices, water utilities, and manufacturers (a Qilin attack reportedly shut down dozens of factories at one beverage maker).
Qilin embodies the RaaS model that dominates the ransomware economy: the operators build and rent the malware and leak site, affiliates do the breaking in, and everyone shares the payout, which lowers the skill barrier and multiplies the volume.
Cl0p perfected a different model: mass exploitation of a single zero-day for bulk extortion. Instead of encrypting one victim at a time, Cl0p finds a vulnerability in a widely-used enterprise product, exploits it across every exposed instance at once, steals data, and extorts everyone. It ran this playbook through MOVEit (2023), Cleo (2024), and the Oracle E-Business Suite zero-day (CVE-2025-61882) in 2025, quietly harvesting data from 100+ organizations before the extortion emails went out. We covered the Oracle EBS zero-day patch when it landed. Our dedicated Cl0p ransomware profile covers the group in depth.
Cl0p is why patch cadence on internet-facing enterprise software is a survival issue: the group turns one unpatched appliance into a mass-breach event.
The two most consequential state actors of the period are China's "Typhoon" units, and they do opposite jobs. Salt Typhoon ran an espionage campaign that breached major US telecom carriers and even the lawful-intercept (wiretap) systems, the subject of a CISA joint advisory and detailed in our Salt Typhoon vs Volt Typhoon comparison. Volt Typhoon is not spying at all, it is pre-positioning inside energy, water, and transportation infrastructure to enable disruption in a future conflict, covered in CISA's Volt Typhoon advisory and our state-sponsored APT threats overview. Together they represent the most strategically serious hacking of the decade: one listens, the other prepares to break things.
Not all notorious hackers chase money. Predatory Sparrow (Gonjeshke Darande), a group widely assessed as Israel-linked, conducts destructive attacks against Iran. In June 2025, amid rising tensions, it disrupted Iran's state-owned Bank Sepah and then hit the crypto exchange Nobitex, stealing about $90 million and deliberately burning it by sending it to unrecoverable addresses to make a political point rather than a profit. It is a marquee example of destructive, politically-motivated hacking, the hacktivist-meets-state model that defines a growing slice of the threat landscape.
| Attack | Group | Impact |
|---|---|---|
| Bybit heist (Feb 2025) | Lazarus | ~$1.5B in Ethereum stolen, the largest crypto heist ever |
| Salesforce / Salesloft Drift (2025) | ShinyHunters | ~1.5B records from 760+ orgs via stolen OAuth tokens |
| Oracle EBS extortion (2025) | Cl0p | 100+ organizations breached via a single zero-day |
| Nobitex (June 2025) | Predatory Sparrow | ~$90M stolen and destroyed to make a political point |
| US telecom breaches | Salt Typhoon | Carrier core networks and wiretap systems compromised |

No single control stops a list this varied, but a consistent program raises the cost for all of them.
| Control | Which threat it blunts |
|---|---|
| Phishing-resistant MFA (FIDO2/passkeys) | Scattered Spider social engineering, credential theft |
| Help-desk identity-verification hardening | Scattered Spider's help-desk and MFA-reset abuse |
| Rigorous patching of internet-facing software | Cl0p mass exploitation, APT edge-device access |
| Audit and limit third-party OAuth/SaaS grants | ShinyHunters-style SaaS supply-chain theft |
| Network segmentation (IT/OT) and monitoring | Volt Typhoon pre-positioning, ransomware lateral movement |
| Immutable backups and a tested IR plan | Qilin and all ransomware; speeds recovery |
| Dark-web and credential monitoring | Data-theft extortion and initial-access sales |
| Continuous penetration testing | Validates that all of the above actually hold |
Two priorities cut across every group on this list. First, harden identity and the help desk, phishing-resistant MFA plus strict verification defeats the social engineering that so many of these crews rely on. Second, patch and test the perimeter relentlessly, because Cl0p and the state APTs get in through exposed, unpatched software. A rehearsed incident response plan then decides how much damage any successful intrusion actually causes.
The 2026 roster makes one thing clear: you are not defending against a stereotype, you are defending against organizations, each with a specialty. A social-engineering gang, a RaaS cartel, a mass-exploitation crew, and a nation-state require overlapping but distinct defenses, and the common threads, identity, patching, third-party exposure, segmentation, and rehearsed response, are exactly where most programs have gaps. Knowing who the adversaries are is only useful if it drives you to test whether your defenses hold against how they actually operate.
DeepStrike's penetration testing emulates the real techniques these groups use, social engineering, edge-device exploitation, lateral movement, and SaaS abuse, and shows you where a Scattered Spider, a Cl0p, or a Salt Typhoon could actually get in. To scope an engagement, see our penetration testing services.
The most notorious groups of 2026 include Scattered Spider (social engineering), ShinyHunters (data-theft extortion), North Korea's Lazarus Group (crypto theft), the Qilin and Cl0p ransomware operations, China's Salt Typhoon and Volt Typhoon espionage and infrastructure units, and the Israel-linked destructive group Predatory Sparrow. They span financially-motivated crime, state espionage, and destructive politics.
Two stand out. Lazarus Group's February 2025 theft of roughly $1.5 billion in Ethereum from the Bybit exchange was the largest cryptocurrency heist ever. In parallel, ShinyHunters' Salesloft Drift campaign stole an estimated 1.5 billion records from more than 760 organizations by abusing stolen OAuth tokens, one of the largest data-theft campaigns on record.
Yes. Despite multiple arrests and US charges against alleged members across 2024-2026, Scattered Spider continued operating through 2025 and into 2026, partly by collaborating with other crews under the "Scattered LAPSUS$ Hunters" banner. Its reliance on social engineering rather than a fixed toolset makes it resilient to individual arrests.
Qilin was the most active ransomware operation of 2025, claiming more victims than any competitor, over a thousand attacks and a large share of all ransomware activity, and it accelerated further into 2026 as rivals like RansomHub disappeared. It runs a ransomware-as-a-service model, renting its malware and infrastructure to affiliates.
Cl0p specializes in mass exploitation rather than one-victim-at-a-time attacks. It finds a zero-day in a widely-used enterprise product, MOVEit, Cleo, and Oracle E-Business Suite in successive years, exploits every exposed instance at once, steals data, and extorts all victims. This makes a single unpatched appliance a potential mass-breach event.
Both are Chinese state-sponsored groups. Salt Typhoon is an espionage operation that breached US telecom carriers and wiretap systems to intercept communications. Volt Typhoon pre-positions inside energy, water, and transportation infrastructure to enable disruptive attacks during a future conflict. Salt listens; Volt prepares to break things.
Focus on the common threads: deploy phishing-resistant MFA and harden help-desk identity verification against social engineering, patch internet-facing software fast to counter mass exploitation, audit third-party OAuth and SaaS access, segment networks, keep immutable backups with a tested incident response plan, and validate all of it with continuous penetration testing.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us