Cybercrime

CrowdStrike Insider Helped Hackers Falsely Claim System Breach

The company has confirmed that it terminated an insider who shared screenshots of his computer with cybercriminals.

CrowdStrike insider fake hack

Cybersecurity firm CrowdStrike has fired an insider caught selling screenshots of their computer to cybercriminals.

The screenshots, which were posted by the financially motivated hacking group Scattered Lapsus$ Hunters on its Telegram channel, include images of the company’s dashboards, including a link to an Okta Single Sign-On (SSO) panel.

The hackers initially claimed that the screenshots were proof that they had gained access to CrowdStrike’s systems through the exploitation of Gainsight, a third-party vendor typically used for customer management.

Last week, the threat actors said they compromised numerous Salesforce customers through their Gainsight integrations, and Salesforce disconnected Gainsight-published applications from its platform.

In a statement to SecurityWeek, CrowdStrike denied being compromised and confirmed that an ‘insider’ was responsible for the leak.

“We identified and terminated a suspicious insider last month following an internal investigation that determined he shared pictures of his computer screen externally,” a company spokesperson said.

Advertisement. Scroll to continue reading.

“Our systems were never compromised and customers remained protected throughout. We have turned the case over to relevant law enforcement agencies,” the representative added.

It’s unclear whether the insider is an employee, contractor, consultant, or business partner with authorized access to the company’s internal systems.

Scattered Lapsus$ Hunters reportedly claimed paying $25,000 to the CrowdStrike insider for the leaked data, for access to the company’s systems, and for authentication cookies.

The threat actor recently claimed to have made over 1,000 victims in multiple data theft campaigns targeting Salesforce customers, including high-profile brands and cybersecurity companies.

Related: Mazda Says No Data Leakage or Operational Impact From Oracle Hack

Related: Spanish Airline Iberia Notifies Customers of Data Breach

Related: 146,000 Impacted by Delta Dental of Virginia Data Breach

Related: Cox Confirms Oracle EBS Hack as Cybercriminals Name 100 Alleged Victims

Related Content

Vulnerabilities

The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.

Cybercrime

Thalha Jubair and Owen Flowers were prosecuted over a 2024 cyberattack targeting Transport for London (TfL).

Cybercrime

The D1R cybercrime group claimed to have stolen valuable data from Synopsys and Bosch, threatening to leak it unless a ransom is paid. 

Cybercrime

Prosecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100...

ICS/OT

Mandiant has helped the California water utility investigate the cyberattack launched by Iranian hacker group Handala.

Data Breaches

Someone posted fake VRChat and Discord data breach reports on the system, prompting the Maine AG to take action.

Artificial Intelligence

An AI hacker claims to have achieved a prompt-based jailbreak shortly after Fable 5’s launch, but Anthropic says it’s not a real jailbreak.

Endpoint Security

CrowdStrike has fixed a critical LogScale vulnerability, while Tenable addressed a high-severity Nessus flaw.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version