Microsoft said DEV-0537, also tracked as LAPSUS$ and later Strawberry Tempest, ran a broad campaign of identity-driven intrusions that led to data theft, extortion, and destructive actions against organizations in government, technology, telecom, media, retail, healthcare, manufacturing, energy, and higher education. The group reportedly gained access through stolen credentials, session token replay, MFA fatigue, SIM swapping, help-desk social engineering, and recruiting insiders or suppliers, then moved to reconnaissance, privilege escalation, data exfiltration, and deletion of cloud and on-premises resources. Microsoft also disclosed that the actor accessed a single Microsoft account with limited permissions and viewed some source code, but said no customer code or customer data was affected.
The reporting and Microsoft guidance underscore that push-based MFA abuse was a key part of the actor’s playbook, prompting stronger controls around authentication workflows. Microsoft’s Entra documentation says number matching is now enabled for Authenticator push notifications to replace weaker approve/deny prompts, extending across Entra MFA, self-service password reset, combined registration, and supported AD FS deployments, while older or unsupported environments may still require updates or alternate methods such as TOTP. The company recommended hardening identity protections, restricting access to trusted devices, improving cloud security posture, and preparing incident-response teams for adversaries that may monitor or interfere with response communications.

Get the infrastructure and lures behind it.
6 events from the most recent confirmed update back to the earliest known activity.
In the same disclosure, Microsoft said DEV-0537 compromised a single Microsoft account with limited access and viewed some source code. Microsoft stated no customer code or customer data was involved.
Microsoft disclosed a large-scale social engineering, data theft, destructive attack, and extortion campaign by DEV-0537, also known as LAPSUS$. The company said the actor targeted organizations globally after initially focusing on the United Kingdom and South America.
Microsoft says Windows Server 2019 supports AD FS adapter number matching after update KB5007206 and Windows Server 2022 after KB5007205. Both updates are cited as prerequisites for number matching support.
Microsoft says Windows Server 2016 supports AD FS adapter number matching after update KB5006669 (OS Build 14393.4704). This update is identified as enabling number matching support on that platform.
Unit 42 says the first attack activity using the Lapsus$ handle was observed in August 2021, when some U.K. mobile phone customers reported threatening text messages. The report presents this as the earliest observed activity tied to the group’s public handle.
Microsoft states that number matching is now enabled for all Authenticator push notifications as a security improvement over Approve/Deny prompts. The guidance says the feature applies across Microsoft Entra MFA and related workflows.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
4 references tracked. Mallory keeps watching after this page renders.
docs.microsoft.com
Open sourcemichaelkoczwara.medium.com
Open sourceunit42.paloaltonetworks.com
Open sourcemicrosoft.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.