ShellCodeX
Tools β€’ Events β€’ News β€’ Insights
Threat Group Profile

lapsus$

Dormant / historical
Victim claims 7
First seen Apr 2026
Last activity 23 Jun 2026
Tracked since Mar 2026

Group overview

Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members β€” predominantly teenagers β€” were arrested in the UK.

Preferred targets

Financial Services Β· 2 Technology Β· 2 Consumer Services Β· 1 Telecommunication Β· 1 Business Services Β· 1

Most targeted countries

US Β· 3 MM Β· 1 SE Β· 1 DE Β· 1 ES Β· 1

Tactics & techniques (MITRE ATT&CK)

Initial Access

Valid Accounts Valid Accounts: Cloud Accounts External Remote Services Trusted Relationship

Execution

User Execution

Persistence

Valid Accounts Valid Accounts: Cloud Accounts Account Manipulation: Additional Cloud Roles External Remote Services Create Account: Cloud Account

Privilege Escalation

Exploitation for Privilege Escalation Valid Accounts Valid Accounts: Cloud Accounts Account Manipulation: Additional Cloud Roles

Stealth

Valid Accounts Valid Accounts: Cloud Accounts Social Engineering: Impersonation

Credential Access

OS Credential Dumping: NTDS OS Credential Dumping: DCSync Multi-Factor Authentication Interception Unsecured Credentials: Chat Messages Credentials from Password Stores: Credentials from Web Browsers Credentials from Password Stores: Password Managers Multi-Factor Authentication Request Generation

Discovery

Permission Groups Discovery: Domain Groups Account Discovery: Domain Account

Collection

Data from Local System Email Collection: Email Forwarding Rule Data from Information Repositories: Confluence Data from Information Repositories: Sharepoint Data from Information Repositories: Code Repositories Data from Information Repositories: Messaging Applications

Victim Claims Timeline

Back to radar
πŸ‡²πŸ‡² Myanmar

AYA BANK

ayabank.com

Everything for the main platform is there. Full dump and PII data's. If AYA Bank dont contact us or pay the ransom we will start sale

Financial Services
πŸ‡ΈπŸ‡ͺ Sweden

INGKA GROUP

ingka.com

Full mapping of global e-commerce architecture and internal coworker platforms. Supply chain logistics, cloud infrastructure, and AI/MLOps repositories

Consumer Services
πŸ‡ΊπŸ‡Έ United States

GITHUB INTERNAL

github.com

Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free.

Technology
πŸ‡ͺπŸ‡Έ Spain

MAPFRE ASSURANCE

This data has been acquired by a private party. No public leak will occur.

Financial Services
πŸ‡©πŸ‡ͺ Germany

VODAFONE

vodafone.com

Full Infrastructure, Source Code, GitHub Tree & Internal Network Maps

Telecommunication
πŸ‡ΊπŸ‡Έ United States

AXCERA TRADING

AXCERA.IO

Trading Algorithms, Client Portfolios, KYC Data & Financial Logs

Business Services
πŸ‡ΊπŸ‡Έ United States

CHECKMARX

checkmarx.com

Source Code, Employee DB, API Keys, MongoDB/MySQL Creds

Technology