Lapsus$

Description

(Flashpoint) LAPSUS is focused on monetizing their operations exclusively through data leaks advertised on Telegram without the use of ransomware.

Initially, the group focused on data breaches against Latin American and Portuguese targets but in late February 2022, LAPSUS has continued to focus on large-scale international technology companies, including Microsoft, Okta, and Samsung, as the financial incentive for stealing source code and extorting companies for sensitive proprietary technical data is high.

Names

NameName-Giver
Lapsus$self given
DEV-0537Microsoft
Strawberry TempestMicrosoft
Slippy SpiderCrowdStrike

Country

Motivation

  • Financial gain

First Seen

2021

Observed Countries

Operations

Counter Operations

Information

Mitre Attack

Other Information

Uuid

ffca877d-5411-419c-ba3b-31924cc4e4af

Last Card Change

2025-06-28