A threat actor using the LAPSUS$ name has claimed an alleged breach of AstraZeneca and is offering a purported 3GB compressed dump of internal data for sale rather than releasing it publicly. Posted samples and screenshots were used to support the claim, with reports describing a pay-to-access extortion model and password-protected links containing redacted material as proof of access. The allegedly stolen data includes source code, cloud infrastructure configurations, employee and contractor-related records, and access material such as cryptographic keys, Vault credentials, and GitHub and Jenkins tokens.
Analysis of the shared samples suggested that some data, including GitHub Enterprise-style user information and third-party contractor access records, appeared plausibly authentic and internally sourced, while at least one financial dataset looked generic and possibly unrelated. Public references to an internal repository tied to AstraZeneca’s supply-chain portal indicate possible exposure of systems supporting forecasting, inventory tracking, SAP integration, and OTIF delivery metrics. The most serious risk would come from any genuine secrets, private keys, or cloud configuration data, but the breach claim and full scope of the exposed material remained unverified, and AstraZeneca had not publicly confirmed the incident at the time of reporting.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
By the time the reports were published, AstraZeneca had been contacted for comment but had not issued a public statement confirming the alleged breach. Both reports noted that the claims and attribution remained unverified at that stage.
Review of the shared samples indicated that some materials, including GitHub Enterprise-style user data, contractor access records, and references to an internal supply-chain repository, appeared plausibly authentic and internally sourced. Reported sample content also pointed to possible exposure of source code, cloud configurations, and secrets such as keys and tokens, though direct verification remained incomplete.
A threat actor using the LAPSUS$ name claimed responsibility for an alleged breach of AstraZeneca and said it had stolen about 3GB of internal data. The actor reportedly began marketing the data for sale using teaser samples, screenshots, and restricted links rather than releasing the material publicly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcecybersecuritynews.com
Open sourcehackread.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.