Google has confirmed that cybercriminals successfully created a fraudulent account within its Law Enforcement Request System (LERS), a critical platform used by police and intelligence agencies worldwide to request user data from the tech giant.
## The Security Breach
“We have identified that a fraudulent account was created in our system for law enforcement requests and have disabled the account,” Google told cybersecurity publication BleepingComputer. The company emphasized that no actual requests were submitted through the fake account and no user data was compromised.
The incident came to light after a hacker group called “Scattered Lapsus$ Hunters” claimed on Telegram to have infiltrated both Google’s LERS portal and the FBI’s eCheck background verification system. The group posted screenshots as evidence of their alleged access before announcing they were “going dark” on Thursday.
## Why This Matters
The LERS platform and FBI’s eCheck system are essential tools that allow law enforcement agencies to submit legitimate subpoenas, court orders, and emergency data requests. Unauthorized access to these systems could enable attackers to impersonate police officers and obtain sensitive user information that should remain protected.
## The Threat Group Behind the Attack
“Scattered Lapsus$ Hunters” claims connections to several notorious cybercriminal organizations, including Shiny Hunters, Scattered Spider, and Lapsus$. This year, the group has orchestrated widespread data theft campaigns primarily targeting Salesforce platforms.
Their attack methods have evolved from simple social engineering tricks—convincing employees to connect data tools to corporate systems—to more sophisticated techniques involving GitHub repository breaches and automated secret scanning tools.
## Major Companies Affected
The group’s Salesforce-focused attacks have impacted numerous high-profile organizations, including:
– Technology companies: Google, Cisco, Cloudflare, Zscaler
– Fashion brands: Louis Vuitton, Dior, Tiffany & Co
– Airlines: Qantas
– Insurance: Allianz Life
– Sportswear: Adidas
## Ongoing Threat
Despite the group’s recent announcement about “going dark,” cybersecurity experts believe they will continue operating covertly. The hackers suggested in their farewell message that additional breaches at major corporations and government agencies may still be disclosed, indicating their activities are far from over.
Google’s Threat Intelligence division (Mandiant) has been instrumental in exposing these attacks and helping organizations strengthen their defenses against such sophisticated cyber threats.
This incident highlights the critical importance of securing systems that bridge law enforcement and private sector data sharing, as any compromise could have far-reaching implications for user privacy and security.
