{"id":441,"count":0,"description":"<div class=\"actor-dossier\" style=\"display:flex;flex-wrap:wrap;gap:12px;margin-bottom:20px\">\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Year Established<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">2021<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Attribution<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">UK \/ Brazil \/ International (Teenagers)<\/div>\n  <\/div>\n  <div style=\"flex:1;min-width:160px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Motivation<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Notoriety, Financial<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Modus Operandi (MO)<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">Social engineering, SIM swapping, insider recruitment, targeting major tech companies<\/div>\n  <\/div>\n  <div style=\"flex:2;min-width:200px;background:#0d1117;border:1px solid #30363d;border-radius:8px;padding:12px\">\n    <span style=\"color:#8b949e;font-size:11px;text-transform:uppercase;letter-spacing:1px\">Primary Aliases<\/span>\n    <div style=\"color:#e6edf3;font-weight:600;margin-top:4px\">DEV-0537, Strawberry Tempest<\/div>\n  <\/div>\n<\/div>\n<p>Lapsus$ is a threat actor group that shocked the cybersecurity industry between 2021 and 2022 by successfully breaching some of the world's most security-conscious technology companies ,  including Microsoft, NVIDIA, Samsung, Ubisoft, T-Mobile, and Okta ,  using primarily social engineering rather than sophisticated technical exploits. Perhaps most remarkably, the group was largely composed of teenagers operating from their homes in the United Kingdom and Brazil.<\/p>\n<p>Lapsus$'s operational methodology demonstrated that advanced technical capability is not always the primary barrier to successful enterprise intrusion. The group excelled at recruiting or coercing corporate insiders ,  sometimes paying employees directly for access credentials or VPN tokens ,  and conducting telephonic social engineering against IT helpdesk staff to reset credentials and bypass multi-factor authentication protections. Their success exposed systemic weaknesses in how major corporations handle insider threats and identity verification.<\/p>\n<p>The group's breach of Okta ,  a leading identity and access management provider ,  was particularly consequential, as Okta's platform is used by thousands of organisations worldwide for single sign-on services. By compromising a third-party customer support contractor with access to Okta's administrative tools, Lapsus$ gained visibility into multiple major Okta customers' environments. The incident highlighted the systemic risk posed by compromising identity providers within the software supply chain.<\/p>\n<p>Law enforcement in the United Kingdom arrested multiple Lapsus$ members, including a 16-year-old identified as the group's primary leader (\"White\"), and a 17-year-old with autism who was subsequently convicted on multiple charges. The arrests and prosecutions highlighted the growing problem of juvenile cybercrime and the need for earlier intervention programs to redirect technically gifted young people away from criminal activity.<\/p>\n\n<p><strong>Threat Mitigation and Strategic Hardening:<\/strong> Network defense against campaigns linked to <strong>Lapsus$<\/strong> requires continuous threat surface management, dark web monitoring for stolen employee credentials, and automated telemetry correlation. Organizations should reference our <a href=\"https:\/\/cyberasia.io\/cyber-risk-checker\/\" style=\"color: #facc15; text-decoration: none;\">Cyber Risk Checker<\/a> and report critical indicators via <a href=\"https:\/\/cyberasia.io\/secure-drop\/\" style=\"color: #facc15; text-decoration: none;\">Secure Drop<\/a>.<\/p>","link":"https:\/\/cyberasia.io\/actor\/lapsus\/","name":"Lapsus$","slug":"lapsus","taxonomy":"threat_actor","parent":0,"meta":[],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors\/441","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/taxonomies\/threat_actor"}],"wp:post_type":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts?threat_actors=441"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}