LAPSUS$ is a loosely organized, financially and reputation-motivated eCrime extortion collective, first observed in mid-2021, that became one of the most disruptive threat actors of 2022 despite relying almost entirely on social engineering rather than custom malware or zero-day exploits. In under six months it publicly breached Microsoft, Nvidia, Samsung, Okta, Vodafone, Ubisoft, T-Mobile, Uber, and Rockstar Games (Krebs on Security; Microsoft MSTIC, Mar–Apr 2022), stealing source code, employee credentials, and internal data, and using the threat of public leak — not ransomware encryption — as its extortion lever. Core members, several of them minors based in the UK and Brazil, were identified and prosecuted by 2023, yet the tradecraft and brand did not die with the arrests.
LAPSUS$ matters now because it functions less as a single static group and more as a durable playbook and brand within a broader, largely English-speaking cybercriminal ecosystem known as "The Com." Its signature techniques — help-desk vishing to reset credentials, MFA-prompt bombing, and recruitment of insiders and contractors via direct payment offers — were subsequently adopted near-verbatim by Scattered Spider (UNC3944) in the 2023 MGM/Caesars casino intrusions and the 2025 UK retail attacks against Marks & Spencer, Co-op, and Harrods, illustrating rapid TTP diffusion across affiliated clusters (Resecurity, Aug 2025). In 2025–2026, remnants and affiliates of LAPSUS$ merged branding with Scattered Spider and ShinyHunters to form "Scattered LAPSUS$ Hunters," which remains active as of this writing despite a wave of arrests and infrastructure seizures in late 2025.
Operationally, the group's defining characteristic is that it consistently defeated some of the best-resourced security organizations in the world (Microsoft, Okta, Nvidia) using techniques any mature identity and access management program should be able to detect or prevent — MFA fatigue, help-desk impersonation, and purchased or leaked credentials — rather than sophisticated exploitation. This makes LAPSUS$ and its successor collectives a disproportionate risk indicator for organizational identity-hygiene and third-party/BPO access-control maturity rather than a purely technical detection problem.
[HIGH] confidence that the 2021–2022 LAPSUS$ core was a loosely organized, non-state-sponsored collective of young hackers based principally in the UK and Brazil — supported by City of London Police arrests (Mar 2022) and a seven-week Southwark Crown Court trial that convicted two UK teenagers, including alleged ringleader Arion Kurtaj (BleepingComputer; The Register, 2023). [MEDIUM] confidence regarding continuity between that original core and the 2025–2026 "Scattered LAPSUS$ Hunters" brand — vendor reporting (Resecurity, DataBreach.io) treats the latter as a rebrand/alliance of personas across LAPSUS$, Scattered Spider, and ShinyHunters rather than a confirmed reconstitution of the original membership; law enforcement has not publicly confirmed specific individual overlap.
Entry vectors. LAPSUS$ almost never relies on exploit development. Its preferred entry points are: (1) commodity infostealer logs (chiefly RedLine Stealer) purchased or scraped from underground marketplaces, containing already-valid VPN, Citrix, and SSO session credentials; (2) direct recruitment of insiders, contractors, and BPO/help-desk staff via public Telegram ads offering payment for VPN or remote-access credentials; and (3) telephone- and chat-based social engineering of an organization's own IT help desk, impersonating an employee to trigger a password or MFA reset (CISA CSRB, Aug 2023; Microsoft MSTIC, Mar 2022). The Okta (via Sitel) and Uber (via an EXT contractor) intrusions are direct examples of the BPO/contractor vector; T-Mobile and Nvidia are examples of the purchased-credential vector.
Toolchain & C2. The group is notable for its almost total absence of bespoke malware. Post-access, operators use Mimikatz and native Windows utilities (ntdsutil, ntds.dit extraction via DCSync) to dump domain credentials, and the legitimate Sysinternals utility AD Explorer to enumerate Active Directory for privileged accounts. Command-and-control is achieved not through custom implants but through legitimate remote-access software (e.g., AnyDesk) and direct interactive logon with stolen credentials, which blends with normal administrative activity and defeats malware-signature-based defenses.
Lateral movement & persistence. Once inside, the group systematically targets internal collaboration and development platforms — SharePoint, Confluence, Jira, Slack, Microsoft Teams, GitHub, and Bitbucket — searching for hardcoded credentials, API keys, and secrets that enable movement to higher-value systems (Microsoft MSTIC, Mar 2022). Where cloud tenant administrative access (Azure AD/Microsoft 365 or AWS) is obtained, LAPSUS$'s signature persistence move is to create a new Global Administrator account, add a tenant-wide mail transport rule forwarding all inbound and outbound mail to that account, and then remove every other legitimate Global Admin — achieving sole, durable control of the tenant and locking out the victim's own IT staff.
Exfiltration & extortion. Data is exfiltrated directly via bulk downloads from the compromised collaboration and code-repository platforms (e.g., 30,000+ Bitbucket repositories at T-Mobile) rather than through covert channels. LAPSUS$ does not deploy ransomware to encrypt victim data; its leverage is purely the threat — and follow-through — of public release via its Telegram channel, combined in several cases with destructive actions (deleting victim systems/resources) once extortion demands are rejected or access is revoked, consistent with T1485/T1490 impact behavior.
| Type | Value / Description | Source | Date |
|---|---|---|---|
| NOTE | No persistent, publicly attributable C2 IP addresses, domains, or malware file hashes are durably associated with LAPSUS$ core operations as of 2026-08-29. The group relies on commodity stealer logs, purchased/leaked credentials, and living-off-the-land or legitimate remote-access tooling rather than fixed, custom infrastructure — consistent with CISA CSRB's finding that the group used "primarily simple techniques." | CISA CSRB | 2023-08-10 |
| BEHAVIOR | Burst of 10+ MFA push notifications to a single user within minutes, often outside normal business hours ("MFA fatigue" / prompt-bombing pattern) | Microsoft MSTIC | 2022-03-22 |
| BEHAVIOR | Help-desk contact requesting password or MFA-method reset for a privileged account without standard out-of-band identity verification | CISA CSRB | 2023-08-10 |
| BEHAVIOR | New Global Administrator account created in an Azure AD / Microsoft 365 tenant, followed shortly by removal of pre-existing Global Admin accounts | Microsoft MSTIC | 2022-03-22 |
| BEHAVIOR | New Exchange Online mail-transport/forwarding rule created that routes all inbound and outbound mail to an external or newly created mailbox | Microsoft MSTIC | 2022-03-22 |
| BEHAVIOR | Bulk, scripted-pattern cloning or download activity against source-code repositories (Bitbucket / GitHub / Confluence / Jira) from a single account within a short time window | Krebs on Security | 2022-04-22 |
| PROTOCOL | Outbound sessions to consumer/commercial remote-access software domains (e.g., AnyDesk) initiated from privileged administrative workstations shortly after anomalous authentication | NCC Group | 2022 |
| PROTOCOL | Directory-replication (DCSync-pattern) LDAP/RPC requests to a domain controller originating from a non-domain-controller host | Vectra AI | 2022 |
LAPSUS$'s core significance is that it demonstrated — repeatedly, against some of the best-resourced security organizations in the world — that unsophisticated, socially engineered tradecraft executed quickly and without regard for operational security could outpace technically sophisticated ransomware crews. [HIGH] confidence assessment, grounded in UK court proceedings against Arion Kurtaj and a co-defendant, is that the operational core was young (several members minors), UK/Brazil-based, and motivated by a mixed blend of financial gain and community status within "The Com" rather than financial gain alone — a profile the CISA Cyber Safety Review Board explicitly flagged as complicating deterrence, since notoriety-seeking actors are less responsive to purely financial disincentives.
The group's most dangerous capability is not any piece of malware but its help-desk-vishing-plus-MFA-fatigue chain for acquiring privileged access, which exploits human and process trust rather than a technical control gap, leaving conventional endpoint and network defenses with limited direct purchase on the initial-access stage. This exact playbook has since proliferated well beyond LAPSUS$ itself — most visibly in Scattered Spider's near-identical help-desk vishing campaigns against MGM and Caesars (2023) and the 2025 UK retail wave (M&S, Co-op, Harrods) — which raises a competing hypothesis worth stating explicitly: it is not yet established whether Scattered Spider directly learned this tradecraft from LAPSUS$ operators, or whether both groups independently converged on the same techniques as a natural product of shared origin within the same underground forums and Discord/Telegram communities. [MEDIUM] confidence is assigned to a direct tradecraft lineage rather than parallel evolution.
On forward trajectory: the emergence of "Scattered LAPSUS$ Hunters" in 2025–2026 — persisting despite UK arrests (Sep 2025) and a joint US/French seizure of extortion-site and BreachForums infrastructure (Oct 2025) — demonstrates that arrests of individual members do not reliably kill the underlying brand or tradecraft within Com-affiliated collectives; the community, playbook, and "brand equity" of the LAPSUS$ name outlive any specific defendant. [LOW–MEDIUM] confidence should be placed on the raw scale of 2026 claims (e.g., "60 million records," the earlier "91 organizations" Salesforce-campaign figure) absent independent victim confirmation, consistent with the group's established pattern of inflating breach scope for extortion leverage — Okta's confirmed impact of two customer tenants versus LAPSUS$'s initial public claims of a much broader compromise is the clearest historical precedent for this gap. What would raise attribution confidence for the 2025–26 continuity question: law-enforcement charging documents or forensic overlap (shared infrastructure, negotiation writing style, or leak-site TTPs) explicitly tying named 2025–26 arrestees to verified 2021–22 LAPSUS$ core membership.
ntdsutil/DCSync replication, and commercial remote-access software (AnyDesk) — no bespoke implant, loader, or C2 framework has been publicly attributed to the group across any of its major intrusions (Microsoft MSTIC, 2022; CISA CSRB, 2023). CSRB explicitly cited this as the group's defining characteristic: high-impact outcomes achieved through "well-known and available" techniques rather than novel tradecraft.