> CLASSIFIED_DOSSIER :: THREAT_ACTOR_PROFILE
LAPSUS$
/actor/lapsus/ · 0 intel reports
Lapsus$ is a threat actor group that shocked the cybersecurity industry between 2021 and 2022 by successfully breaching some of the world's most security-conscious technology companies , including Microsoft, NVIDIA, Samsung, Ubisoft, T-Mobile, and Okta , using primarily social engineering rather than sophisticated technical exploits. Perhaps most remarkably, the group was largely composed of teenagers operating from their homes in the United Kingdom and Brazil.
Lapsus$'s operational methodology demonstrated that advanced technical capability is not always the primary barrier to successful enterprise intrusion. The group excelled at recruiting or coercing corporate insiders , sometimes paying employees directly for access credentials or VPN tokens , and conducting telephonic social engineering against IT helpdesk staff to reset credentials and bypass multi-factor authentication protections. Their success exposed systemic weaknesses in how major corporations handle insider threats and identity verification.
The group's breach of Okta , a leading identity and access management provider , was particularly consequential, as Okta's platform is used by thousands of organisations worldwide for single sign-on services. By compromising a third-party customer support contractor with access to Okta's administrative tools, Lapsus$ gained visibility into multiple major Okta customers' environments. The incident highlighted the systemic risk posed by compromising identity providers within the software supply chain.
Law enforcement in the United Kingdom arrested multiple Lapsus$ members, including a 16-year-old identified as the group's primary leader ("White"), and a 17-year-old with autism who was subsequently convicted on multiple charges. The arrests and prosecutions highlighted the growing problem of juvenile cybercrime and the need for earlier intervention programs to redirect technically gifted young people away from criminal activity.
Threat Mitigation and Strategic Hardening: Network defense against campaigns linked to Lapsus$ requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our Cyber Risk Checker and report critical indicators via Secure Drop.
> LINKED_INTEL_REPORTS (0)
[NULL] No intel reports found for this actor.