Microsoft confirmed that LAPSUS$ compromised a single employee account and used that foothold to gain limited access to internal source-code repositories, leading to the leak of code tied to projects including Bing, Cortana, and Bing Maps. The company said no customer code or customer data was affected and that the compromised account was remediated, but the incident reinforced the group’s ability to turn relatively simple access methods into high-impact breaches at globally recognized targets.
Reporting across multiple investigations describes LAPSUS$ as a fast-moving data extortion actor that relied heavily on social engineering, SIM swapping, credential theft, session-token abuse, MFA fatigue, help-desk manipulation, and purchases or solicitation of insider access rather than advanced malware or ransomware deployment. The group publicly used Telegram to leak stolen data, pressure victims, and recruit access brokers, and it was linked to intrusions affecting organizations including NVIDIA, Okta, Samsung, Microsoft, Vodafone Portugal, Ubisoft, LG, and Brazil’s Ministry of Health; researchers said its behavior mixed financial motives with disruption, publicity, and notoriety, suggesting the threat could persist through remaining members or copycat actors even after arrests.

Get the infrastructure and lures behind it.
18 events from the most recent confirmed update back to the earliest known activity.
Security Affairs reported that LAPSUS$ shared a torrent for a 7zip archive containing 9 GB of Microsoft source code, reportedly expanding to 37 GB uncompressed across hundreds of projects. The leaked material allegedly included code from Bing, Cortana, and Bing Maps.
S2W reported that LAPSUS$ leaked dump files containing LG employee and service-account hashes. The group claimed it had hacked LG twice within a year.
S2W reported that Ubisoft disclosed an incident that temporarily disrupted some games, systems, and services and prompted a company-wide password reset. The report said LAPSUS$ referenced Ubisoft on its Telegram channel and likely attempted a real intrusion.
S2W reported that LAPSUS$ leaked Samsung data including TrustZone applet source code, biometric unlock algorithms, bootloader code, Qualcomm-related code, and account-related source code. The group distributed about 190 GB via torrents and claimed to use more than 10 Azure servers as seeders.
S2W reported that LAPSUS$ previewed screenshots of Samsung source code before the full leak. This preceded publication of a much larger Samsung data set.
S2W reported that NVIDIA disclosed a cybersecurity incident affecting IT resources and said it had notified law enforcement and incident response experts. The report said LAPSUS$ claimed to have stolen 1 TB of data including employee email addresses, password hashes, source code, circuit designs, drivers, firmware, and internal tools.
S2W reported that Vodafone Portugal disclosed a cyberattack that disrupted 4G/5G, fixed voice, television, SMS, and voice/digital response services, while saying customer data was not affected. The report added that LAPSUS$ claimed to have stolen 500 GB of sensitive information and referenced Vodafone Global/UK data.
S2W reported that Localiza Rent a Car SA's website redirected users to a pornographic site for about two hours and later became inaccessible due to a DNS error. The incident was attributed to suspected DNS spoofing, and LAPSUS$ claimed responsibility without mentioning data theft.
S2W reported that LAPSUS$ continued attacks against Brazilian government websites after the Ministry of Health incident. The activity was said to continue through late December 2021.
S2W said LAPSUS$ claimed to have hacked Brazil's Ministry of Health, accessed its AWS environment, stolen about 50 TB of data, and deleted internal system data. The group also defaced ministry websites and later claimed access to SisReg, vCenter, and ConecteSUS-related systems.
S2W reported that LAPSUS$ created its own Telegram channel and used it to publicize attacks and leaks. CYFIRMA described Telegram as the group's only official communication method for publishing stolen data and interacting with followers.
CYFIRMA stated that LAPSUS$ was using insider-solicitation techniques as early as November 2021, publicly seeking employees of target companies to provide access. This tradecraft later became associated with intrusions including Microsoft.
S2W reported the earliest traced LAPSUS$ activity on RaidForums, where the group allegedly offered stolen Schlumberger customer and employee records for sale. The report also assessed that the actor had previously used the names APT 777 and GoldFish Team before adopting LAPSUS$.
Microsoft confirmed that LAPSUS$ compromised a single employee account and used it to gain limited access to source code repositories. The company said no customer code or customer data was affected and that response teams remediated the account to prevent further activity.
CYFIRMA reported that a 16-year-old and a 17-year-old appeared in court in the UK charged with cyber offenses tied to the broader LAPSUS$ story. The article emphasized that the group remained active despite these arrests and public exposure of alleged members.
Both CYFIRMA and S2W reported that after hacking NVIDIA, LAPSUS$ demanded removal of Lite Hash Rate restrictions on GPUs and later demanded that NVIDIA open source its GPU drivers. CYFIRMA assessed these demands as aimed more at notoriety and pleasing followers than direct profit.
S2W reported that LAPSUS$ hacked Grupo Impresa, affecting SIC and Expresso, including compromise of Expresso's Twitter account and SMS messages sent to customers. CYFIRMA also identified Impresa as one of the group's early public victims.
S2W reported that LAPSUS$ claimed to have stolen data from Claro, Embratel, and NET, asserting access to AWS, GitLab, vCenter, storage systems, inboxes, telecom infrastructure, and customer-management systems. The group claimed to possess between 10,000 TB and 10 PB of data including customer information, legal documents, source code, and emails.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
3 references tracked. Mallory keeps watching after this page renders.
medium.com
Open sourcecyfirma.com
Open sourcesecurityaffairs.co
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.