LAPSUS$ is a financially motivated cybercrime and extortion group best known for high-profile intrusions against major technology, telecommunications, gaming, and identity-management organizations. The group is widely associated with aggressive social engineering, credential theft, insider recruitment or bribery, and abuse of legitimate remote access and identity workflows rather than reliance on bespoke malware. Commonly cited aliases include DEV-0537, Slippy Spider, Strawberry Tempest, Lapsus, and Lapsus Group. LAPSUS$ gained prominence through intrusions affecting organizations such as Nvidia, Microsoft, Samsung, Ubisoft, Okta, Globant, and Rockstar Games, and has also been linked in reporting to attacks involving BT/EE. Its operations have often centered on stealing source code, internal communications, authentication data, and other sensitive corporate information, then using public leak channels and extortion pressure to coerce victims. The group has demonstrated a willingness to publicize stolen data rapidly and to blend data theft with reputational pressure. Tradecraft attributed to LAPSUS$ consistently emphasizes human-centric intrusion methods. Reported techniques include vishing and other social-engineering pretexts against help desks and employees, exploitation of authentication and account-recovery processes, privilege escalation after initial access, and use of compromised or insider-enabled credentials to move through enterprise environments. The actor has been associated with abuse of identity infrastructure and with attacks that illustrate the systemic risk posed by compromise of SaaS and identity providers. LAPSUS$ is frequently described as part of, or overlapping with, the broader English-speaking cybercriminal ecosystem known as The Com. Reporting also notes operational intersections or collaboration claims involving Scattered Spider, ShinyHunters, TeamPCP, and Vect. In particular, LAPSUS$ has been described as partnering with other extortion actors to monetize stolen data, including joint sale activity and leak-site amplification. Some individuals publicly tied to LAPSUS$ have also been linked to Scattered Spider and The Com, underscoring the loose, decentralized, and personnel-overlapping nature of this ecosystem. Law-enforcement actions in the United Kingdom have tied several young offenders to LAPSUS$, including individuals connected to the Nvidia and Rockstar-related intrusions. Despite arrests and prosecutions, the LAPSUS$ name continues to appear in extortion and breach claims, though some later attributions and victim claims remain unconfirmed. Overall, LAPSUS$ is best characterized as a high-impact cyber extortion actor whose hallmark is rapid, socially engineered compromise of prominent targets followed by theft and coercive disclosure of sensitive data.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
43 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
18 malware families attributed to this actor across reporting.
13 additional families tracked in Mallory.
10 CVEs this actor has used in observed campaigns. 10 of them exploited in the wild.
The CVE-2025-61882 campaign is particularly instructive. CrowdStrike assessed with moderate confidence that GRACEFUL SPIDER was involved in mass exploitation of that vulnerability... Exploitation had begun nearly two months earlier on August 9, 2025, well before Oracle's public disclosure.
BleepingComputer reported that threat actors leveraged credentials stolen through the Trivy supply chain compromise (CVE-2026-33634) to breach Cisco's internal development environment... The CISA KEV remediation deadline for CVE-2026-33634 is today, April 8, 2026... Beyond patching Trivy to v0.69.2+, trivy-action to v0.35.0, or setup-trivy to v0.2.6, organizations must also complete credential rotation.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
This analytic identifies potential exploitation attempts of ProxyShell (CVE-2021-34473, CVE-2021-34523, CVE-2021-31207) and ProxyNotShell (CVE-2022-41040, CVE-2022-41082) vulnerabilities in Microsoft Exchange Server.
5 more CVEs tied to this actor tracked in Mallory.
14 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as another cybercriminal group to which one of the convicted individuals was linked; not the primary actor discussed for the TfL incident.
A financially motivated hacking group linked here to the 2022 GTA 6 leak and other intrusions against major technology and gaming companies. The content says its methods included social engineering, insider bribery, and exploiting authentication systems.
Mentioned as Jubair's prior cybercrime affiliation in an earlier case, not as the primary subject of this article.
Named as the threat actor associated with a hacking incident affecting Virta Medical PC in the May 2026 healthcare breach report.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.