Cybercrime’s Gig Economy: Inside SLH’s Vishing Recruitment Drive

    Subscribe to our newsletter

    By submitting this form, you agree to the Allure Security privacy policy.

    Share Article

    Rows of call center agents conducting vishing attacks with red glowing screens in a dark cybercrime operation

    A threat group is hiring contractors for scripted phone attacks, paying up to $1,000 per call and providing everything they need to start.

    In late February 2026, threat intelligence firm Dataminr detected recruitment posts on a public Telegram channel from the Scattered Lapsus$ Hunters collective. The group was advertising paid work for voice phishing operations, offering $500 to $1,000 per call with scripts provided. What caught analyst attention was the specificity: SLH was recruiting women.

    The recruitment drive reflects something broader than a tactical adjustment. SLH has built what it internally calls the “SLH Operations Centre,” a vishing operation designed for volume and speed. The model outsources scripted social engineering to paid contractors while core operators retain control of the technical exploitation that follows a successful call. It is, in effect, a cybercrime call center.

    Who is SLH? The supergroup behind the campaign

    SLH is a coalition of three groups that have individually compromised some of the largest companies in the world: Scattered Spider, LAPSUS$, and ShinyHunters. Past victims include Google, Cisco, Adidas, Salesforce, and Disney. The collective has been linked to the theft of over 1.5 billion records.

    What makes SLH distinctive is its reliance on social engineering rather than technical exploitation for initial access. The approach complements the voice cloning attacks that have targeted executives in recent years, extending social engineering pressure to help desk staff who control access to corporate systems. The group’s primary tactic involves calling IT help desks and convincing staff to reset passwords, enroll new MFA devices, or install remote monitoring tools. Once inside, operators move laterally through cloud environments, escalate privileges, and exfiltrate data, often without deploying malware at all.

    Dataminr’s analysis characterized the recruitment as a “calculated evolution” aimed at bypassing the attacker profiles that help desk staff are trained to identify. Security awareness training often emphasizes what attackers sound like: aggressive, technically confused, or operating from scripts that don’t quite fit. A confident, professional female voice reading a polished script may not trigger those same pattern-matching instincts.

    The SLH Operations Centre: Vishing at scale

    What SLH calls the “Operations Centre” represents a specific kind of professionalization. According to ReliaQuest, ShinyHunters is scaling vishing-driven intrusions by outsourcing scripted tasks to paid contractors while also purchasing disruption services like email bombing, call flooding, and SMS spamming. Payments are made in cryptocurrency, and the volume-based incentives suggest a model built to apply pressure cheaply and at scale.

    The call center analogy is apt. Contractors follow scripts. The organization optimizes for which caller personas yield the highest compliance rates. High-volume, low-cost pressure campaigns coerce targets into fast compliance. The core operators focus on the technical work that creates access and leverage once a call succeeds.

    This mirrors the specialization seen in ransomware-as-a-service programs, where initial access brokers, affiliate operators, and core developers each handle different phases of an attack. SLH appears to be applying similar division of labor to vishing, industrializing a technique that has historically depended on individual operator skill.

    Why scaled vishing changes help desk defense

    The recruitment activity matters because it signals intent to scale. A single skilled social engineer can only make so many calls. An organization paying contractors $500 to $1,000 per successful call, with scripts and targeting data provided, can generate far more pressure on far more targets simultaneously.

    Help Net Security reported that Dataminr advises organizations to brief help desk staff specifically about this recruitment trend. The goal is not to make staff suspicious of female callers in general but to reinforce that attackers deliberately optimize their approach, and today’s attacks may not resemble yesterday’s training scenarios.

    The tactical recommendations follow from the underlying technique. Help desks should enforce out-of-band identity verification for any request involving password resets, MFA changes, or remote access tool installation. SMS and voice-call MFA remain vulnerable to the group’s established TTPs, including SIM swapping and MFA fatigue bombing. Organizations should audit logs for new user creation or privilege escalation immediately following help desk interactions.

    Cybercrime Professionalization: Social engineering as a service

    SLH’s approach sits within a larger trend of cybercrime professionalization that has reshaped the threat landscape over the past several years. Operations that once required end-to-end technical skill now decompose into specialized roles with their own labor markets. Phishing kits are sold as services. Initial access is brokered. Ransomware is licensed. The fraud-as-a-service ecosystem that emerged in criminal marketplaces has expanded to include social engineering as a contracted specialty.

    The Bottom Line

    When the adversary’s capacity is no longer bounded by the skills of a single operator, the constraint becomes capital, not capability. SLH can recruit callers at $500 to $1,000 per successful call, and experts who have listened to Scattered Spider calls describe the tactics as sophisticated and highly effective. The downstream result is account takeover at scale — and adding volume to that effectiveness is exactly the evolution SLH appears to be pursuing.

    Key Takeaways

    Who is SLH?

    Scattered Lapsus$ Hunters is a coalition of Scattered Spider, LAPSUS$, and ShinyHunters. The supergroup has compromised major corporations including Google, Cisco, Adidas, and Salesforce, primarily through social engineering rather than technical exploitation.

    What is the "SLH Operations Centre"?

    A vishing operation built for volume and speed. The model outsources scripted phone calls to paid contractors, who are provided scripts and paid in cryptocurrency. Core operators handle the technical exploitation after successful calls.

    Why recruit women specifically?

    SLH is optimizing caller personas. Security training often profiles attackers in ways that may not match a professional, confident female voice. Diversifying the caller pool increases the success rate of help desk impersonation.

    What defenses are most relevant?

    Out-of-band identity verification for sensitive help desk requests, phishing-resistant MFA (hardware keys over SMS), and audit logging for identity workflow changes immediately following help desk interactions.

    What does this signal about cybercrime evolution?

    Social engineering is being industrialized. Like ransomware-as-a-service, vishing is decomposing into specialized roles with gig workers handling scripted tasks while operators retain technical control.

    Categories:

    See the threats targeting your brand right now

    Get a customized assessment showing active impersonation, phishing infrastructure, and exposed credentials specific to your organization. No commitment required.