Lapsus$ is a financially motivated cybercriminal extortion group best known for high-profile intrusions into large enterprises and for publicly taunting victims after successful compromises. Reporting has described the group as composed largely of teenagers. The actor has been associated with the broader cybercrime ecosystem through relationships or overlap with groups such as Scattered Spider and ShinyHunters, and has been referenced in connection with access purchased from credential and access brokers such as TeamPCP. Lapsus$ is notable for intrusion and extortion activity centered on stealing data and abusing valid access rather than relying exclusively on traditional ransomware encryption. The group has been linked to breaches of major companies and is known for aggressive post-compromise behavior, including public bragging and coercive pressure. Available reporting in the supplied material supports credential-based intrusion and data theft, but does not provide high-confidence detail on specific malware, exploit chains, or victimology beyond large-company targeting. Although one mention labels Lapsus$ a ransomware group, the supplied facts more directly support characterization as an extortion-focused cybercriminal actor operating within a collaborative criminal ecosystem.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
1 distinct technique observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware/extortion group that allegedly obtained access credentials from TeamPCP and is known for breaching large companies.
Named as part of a claimed collaboration within 'Scattered Lapsu$ Hunters' activity on Telegram.
Lapsu$ is a ransomware-as-a-service group that has collaborated with Scattered Spider in cybercrime operations, likely providing ransomware capabilities or operational support.
Lapsu$ is a ransomware-as-a-service group that has collaborated with Scattered Spider in cybercrime operations.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.