Lapsus$ Explained | The Hacking Group Behind Okta, Uber, Nvidia and Its Return 

Lapsus$

Lapsus$ is a hacking and extortion group first known for breaching Okta, Microsoft, Nvidia, Samsung, and Uber in 2021 and 2022 using social engineering rather than malware, and it has since reemerged as part of a larger collective called Scattered Lapsus$ Hunters. Unlike ransomware gangs that rely on encryption, Lapsus$ built its reputation on stealing source code and internal data, then threatening to leak it publicly unless the victim paid or complied with its demands. This tactic made it one of the most disruptive threat actors of the past few years despite reportedly being run largely by teenagers.

That threat hasn’t gone away; it’s evolved. In late 2025, the rebranded Scattered Lapsus$ Hunters collective, combining the tactics of Lapsus$, Scattered Spider, and ShinyHunters, claimed responsibility for a sweeping Salesforce-linked breach that hit enterprises through compromised OAuth tokens, ultimately publishing a leak site naming 39 companies, including Google, Cisco, FedEx, and Disney/Hulu, and claiming close to 1 billion stolen records. This guide breaks down who Lapsus$ is, what they’ve done, and how the group operates today under its new name.

What Is Lapsus$?

Lapsus$ is an extortion-focused hacking group that broke into corporate networks not by exploiting software flaws, but by tricking employees into handing over access, then threatened to leak stolen data unless companies paid up. Formed in 2021, the group built its reputation by stealing source code and internal files from major tech companies and publicly posting proof of the theft, without ever deploying ransomware.

Origins and Founding

Lapsus$ formed in mid-2021, when a UK teenager operating under the alias “White”, later identified as Arion Kurtaj, a then-16-year-old from Oxford, began collaborating online with a Brazilian teenager who would become the group’s other core member. The pair’s first confirmed attack hit Brazil’s Ministry of Health in December 2021, where they exfiltrated and deleted roughly 50 terabytes of internal data and defaced the ministry’s website with a ransom message. Weeks earlier, the same duo had already demanded a $4 million payment from UK telecom providers BT and EE after breaching their servers, a pattern of high-profile extortion that would define the group’s next year. By March 2022, Lapsus$’s public Telegram channel had grown to nearly 50,000 subscribers, and City of London Police had arrested seven people, aged 16 to 21, tied to the investigation.

How Lapsus$ Operates (Social Engineering, SIM Swapping, Extortion)

Lapsus$ rarely relied on malware or zero-day exploits. Instead, the group used social engineering to obtain legitimate employee credentials, buy stolen logins, bribe or recruit insiders through social media, and bombard targets with MFA push notifications until someone approved a fraudulent login (a tactic known as MFA fatigue). SIM swapping was also a core technique: by hijacking a victim’s phone number, Lapsus$ could intercept one-time passcodes and reset accounts protected by SMS-based two-factor authentication, as one UK case tied to nearly £100,000 stolen directly from victims’ cryptocurrency wallets. Once inside a network, the group exfiltrated data and used Telegram, publicly and often in real time, to announce breaches, threaten leaks, and pressure victims into paying rather than negotiate quietly through a dark web portal.

Lapsus

Lapsus$ vs. Traditional Ransomware Gangs

Lapsus$ differs from ransomware operators like LockBit or Qilin in almost every structural way. Traditional ransomware gangs encrypt a victim’s systems, demand payment for a decryption key, and typically operate as organized, profit-driven criminal enterprises with affiliate networks. Lapsus$ never encrypted anything; its leverage came purely from stealing and threatening to publish data, a model closer to pure extortion than ransomware. The group was also unusually public and undisciplined for a cybercrime operation: members were largely teenagers, techniques were comparatively unsophisticated, and the group openly taunted victims and law enforcement on Telegram rather than operating quietly in the shadows. That combination of low technical sophistication and outsized real-world impact is a large part of why Lapsus$ became a case study in why social engineering, not malware, is often an organization’s biggest blind spot.

Lapsus$ Timeline: Major Breaches and Attacks

Lapsus$’s most damaging period ran from December 2021 through September 2022, during which the group breached identity provider Okta, leaked source code from three of the world’s largest tech companies, and hit Uber and Rockstar Games within days of each other. What made this run notable wasn’t technical sophistication; it was how consistently social engineering alone got a small group of teenagers into some of the best-defended networks in tech.

Lapsus

Okta Breach

In January 2022, Lapsus$ gained access to Okta’s internal systems not by attacking Okta directly, but by compromising a support engineer at Sitel, a third-party customer service vendor Okta relied on. The group used a compromised remote desktop session to control the engineer’s machine for five days, from January 16 to 21. However, the breach didn’t become public until March 22, when Lapsus$ posted screenshots of the intrusion, including what appeared to be Okta’s Slack channels and admin console, to its Telegram channel. Okta later confirmed that 366 of its corporate customers, about 2.5% of its customer base at the time, could have been affected, even though the compromised account’s actual privileges were limited to basic support functions.

Microsoft, Nvidia, and Samsung Source Code Leaks

Within weeks of the Okta incident, Lapsus$ turned to source code theft as its signature move. The group claimed to have breached Microsoft’s internal Azure DevOps server and leaked roughly 37GB of source code for Bing, Cortana, and other internal projects. Nvidia was hit even harder: Lapsus$ stole around 1TB of internal data, including employee credentials and code-signing certificates, then tried to extort the chipmaker into open-sourcing its GPU drivers rather than demanding money outright. Samsung followed soon after, losing close to 190GB of source code covering Galaxy device firmware, bootloader code, and authentication mechanisms for its Trusted Applets. In each case, the pattern was the same: steal proprietary code, post samples publicly on Telegram, and use the threat of a full leak as leverage.

Uber and Rockstar Games (GTA 6) Breach

In September 2022, Lapsus$ breached Uber by bombarding a contractor with repeated multi-factor authentication push notifications and then posing as Uber IT support over WhatsApp until the contractor approved a login. That access let the attacker reach Uber’s internal Slack, Google Workspace, and AWS console, where they posted a message to company-wide Slack channels announcing the breach. Days later, the same core member, Arion Kurtaj, hacking from a Travelodge hotel room while out on bail, breached Rockstar Games and leaked more than 90 videos and clips of then-unreleased gameplay footage from Grand Theft Auto 6, one of the most anticipated games in the industry, directly to public forums and Telegram.

T-Mobile, MITRE, and CrowdStrike Incidents

Lapsus$ breached T-Mobile in March 2022 after members bought VPN credentials for compromised employee accounts on dark web marketplaces, then used SIM-swapping to defeat two-factor authentication whenever an employee reset their password. That access let the group into T-Mobile’s Slack and Bitbucket repositories, where they downloaded more than 30,000 source code repositories. However, T-Mobile maintains that no customer or government data was exposed. MITRE, by contrast, was never a Lapsus$ victim; it formally tracks Lapsus$ in its ATT&CK framework as threat group G1004 (also known as DEV-0537 and Strawberry Tempest), cataloging the group’s techniques for defenders. CrowdStrike had its own scare in late 2025, when a malicious insider photographed internal systems and passed the images to actors tied to the Scattered Lapsus$ Hunters collective; CrowdStrike confirmed its systems and customer data were never actually compromised, but the incident underscored how far the group’s influence had reached by the time of its 2025 resurgence.

Who’s Behind Lapsus$? Members, Leadership, and Arrests

Lapsus$ was never a large, professionalized criminal enterprise; investigators eventually traced its core activity to a handful of teenagers, with the alleged ringleader operating out of his mother’s house near Oxford, England. That gap between the group’s outsized impact and its unusually young, small membership is one of the most studied aspects of the Lapsus$ case.

Lapsus

Known Members and Alleged Leadership

Security researchers identified the group’s apparent ringleader as a UK teenager operating under the aliases “White,” “Breachbase,” and later “WhiteDoxbin,” publicly named in court proceedings as Arion Kurtaj, who was 16 to 17 during the group’s peak activity and is autistic. A second core member, believed to be a teenager based in Brazil, was tied to several of the same intrusions, and researchers working on behalf of breached companies eventually traced seven unique accounts associated with Lapsus$ operations, suggesting a small but active roster beyond its two most visible members. Kurtaj was reportedly outed by rivals after purchasing Doxbin, a site used to publish other people’s personal information, and the BBC estimated he stole roughly $14 million through the group’s various schemes before his arrest.

UK and Brazilian Law Enforcement Action

In March 2022, the City of London Police arrested seven people connected to Lapsus$, ranging in age from 16 to 21, though most were released under investigation rather than immediately charged. Kurtaj and a 17-year-old co-defendant were later charged in April 2022 and, after a seven-week trial at Southwark Crown Court, were convicted in August 2023 on charges including unauthorized computer access, fraud, and blackmail tied to the Nvidia, Uber, and Rockstar Games attacks; because Kurtaj was found unfit to stand trial due to his autism, he was ordered to remain indefinitely in a secure psychiatric hospital rather than sentenced to prison. Brazilian authorities separately investigated members connected to the group’s first attack against Brazil’s Ministry of Health, running a parallel track to the UK case given the group’s dual UK-Brazil membership.

FBI, CISA, and International Response

Lapsus$’s reach across UK, Brazilian, and U.S. corporate networks pulled in federal law enforcement on both sides of the Atlantic. The FBI issued a public alert in March 2022 seeking tips on the group and its members, while the U.S. Department of Homeland Security’s Cyber Safety Review Board, a body created to investigate major cyber incidents, selected Lapsus$ as the subject of its second-ever formal review, following its inaugural report on the Log4j vulnerability. The resulting CISA-backed recommendations pushed regulators like the FCC and FTC to mandate stronger anti-SIM-swapping protections at telecom carriers, treating Lapsus$’s low-tech, high-impact playbook as a template other threat actors were likely to copy. This prediction proved accurate when the group resurfaced in 2025 as part of Scattered Lapsus$ Hunters.

From Lapsus$ to Scattered Lapsus$ Hunters

Lapsus$ didn’t disappear after its 2022 arrests; it resurfaced in August 2025 as part of a larger, more aggressive collective called Scattered Lapsus$ Hunters, responsible for some of the year’s costliest corporate breaches. What started as a scrappy teenage extortion group has become a coalition capable of disrupting a major automaker’s entire global production line.

Lapsus

The Scattered Spider–Lapsus$–ShinyHunters Merger

In August 2025, remnants of Lapsus$ formally aligned with two other English-speaking cybercrime collectives, Scattered Spider and ShinyHunters, to form Scattered Lapsus$ Hunters, a name researchers at Resecurity separately dubbed the “Trinity of Chaos.” The alliance combined each group’s specialty: Scattered Spider’s advanced cloud and identity-provider exploitation, ShinyHunters’ large-scale credential and data-dump networks, and Lapsus$’s public, chaotic Telegram-driven extortion playbook. Within weeks of forming, the coalition had stood up at least 16 separate Telegram channels, cycling through new ones as old ones were reported and taken down, a pattern that would define the group’s entire 2025 run. Rather than developing new intrusion techniques, the merged group leaned on the same core tactic each founding group had already perfected: compromising legitimate user identities through social engineering rather than exploiting software vulnerabilities.

The 2025 Salesforce Breach and Extortion Campaign

Scattered Lapsus$ Hunters’ defining campaign began with the theft of OAuth tokens from Salesloft’s Drift AI chat integration in August 2025, giving the group direct API access to the Salesforce instances of companies that used the tool. On October 3, 2025, the group launched a public data leak site naming 39 companies, including Google, Cisco, FedEx, Disney/Hulu, Toyota, and Adidas, and claiming to hold close to 1 billion stolen records, giving Salesforce until October 10 to negotiate. Salesforce refused to pay, calling the group’s claims unsubstantiated. The campaign kept expanding: in November 2025, a related breach of Gainsight’s Salesforce-connected apps let Google’s Threat Intelligence Group confirm more than 200 additional Salesforce instances had potentially been compromised, with the group claiming victims like Atlassian, CrowdStrike, and LinkedIn.

Jaguar Land Rover, Qantas, and Other Recent Targets

Scattered Lapsus$ Hunters’ most economically damaging attack targeted Jaguar Land Rover, disrupting the automaker’s systems on August 31, 2025, and forcing a five-week global production halt. The UK’s Cyber Monitoring Center later estimated the total cost to the broader UK economy at £1.9 billion (about $2.5 billion), making it the most expensive cyberattack in British history and a factor the Bank of England cited in weaker-than-expected UK GDP growth that quarter. The group also claimed responsibility for a data breach at Australian airline Qantas, which began with a Salesforce-linked contact-center compromise in June 2025 and was later confirmed to have affected 5.7 million individuals, with samples of the stolen data appearing on the group’s October 2025 leak site alongside dozens of other victims.

Telegram Channels, Leak Sites, and Current Status

Scattered Lapsus$ Hunters’ public presence has followed an erratic on-again, off-again pattern rather than a single continuous operation. The group announced it was “going dark” in September 2025 shortly after the Jaguar Land Rover attack, resurfaced to launch its Salesforce leak site in October, announced another temporary dissolution in mid-October to reduce law enforcement pressure, and then returned via a new Telegram channel in late November 2025; each shutdown announcement met with skepticism from researchers who’ve watched the group repeatedly rebrand and reappear. That instability makes “current status” a moving target: at any given time, the safest assumption for defenders is that the group’s infrastructure and personnel persist even when a specific channel or leak site goes dark, since its data leak sites and Telegram presence have consistently reappeared within weeks of each claimed shutdown.

Lapsus$ Tactics, Techniques, and Warning Signs

Lapsus$’s toolkit was never about exploiting unknown vulnerabilities; MITRE’s ATT&CK framework, which catalogs the group as G1004, documents more than 25 distinct techniques the group relied on, and nearly all of them target people and process gaps rather than software flaws. Understanding that pattern is the fastest way for a security team to recognize a Lapsus$-style intrusion before it escalates.

Lapsus

Social Engineering and Help-Desk Exploitation

Lapsus$’s signature move was calling an organization’s IT help desk directly, impersonating a legitimate employee using personal details gathered in advance, and convincing support staff to reset that employee’s password or MFA settings on the spot. Microsoft’s own incident response team documented the group researching targets on LinkedIn, company org charts, and public employee directories before making these calls, then following up by targeting employees at their personal email addresses and phone numbers rather than corporate ones, where security controls are weaker. When social engineering alone didn’t work, the group paid for access: it recruited employees, contractors, and business-partner staff directly, reportedly offering up to $20,000 a week to anyone willing to hand over credentials or approve a fraudulent MFA prompt.

SIM Swapping and MFA Fatigue Attacks

Once Lapsus$ had a target’s phone number, it used SIM swapping to redirect that number to a device the group controlled, sometimes by bribing or tricking mobile carrier store employees, allowing it to intercept SMS-based one-time passcodes and take over accounts protected by that second factor. In parallel, the group used MFA fatigue (also called MFA bombing): repeatedly triggering push-notification approval requests on a victim’s phone, sometimes alongside a direct message or phone call posing as IT support, until the target approved one out of frustration or confusion. MITRE ATT&CK formally tracks both behaviors as distinct techniques, MFA Request Generation and MFA Interception, because Lapsus$ used them so consistently that they became a reliable behavioral signature for the group.

Indicators of Compromise (IOCs) to Watch

Security teams tracking Lapsus$-style activity should watch for a specific cluster of tools and behaviors documented by Microsoft and NCC Group researchers: use of AD Explorer and RVTools to enumerate Active Directory users and groups, the Redline password stealer to harvest browser-stored credentials, and NordVPN as an egress point to mask the attacker’s location. On the identity side, warning signs include new global admin accounts appearing in a cloud tenant, a new mail transport rule silently forwarding all inbound and outbound email to an unfamiliar account, and use of the built-in ntdsutil tool or DCSync-style requests to extract the Active Directory database. Because Lapsus$ often escalated to destructive action once discovered, treat unexplained shutdowns of on-premises VMware ESXi virtual machines or bulk deletion of cloud resources as a potential extortion attempt already in its final stage, not an early warning; by that point, data has typically already left the network.

How Organizations Can Defend Against Lapsus$-Style Attacks

Defending against Lapsus$ and its successor, Scattered Lapsus$ Hunters, isn’t primarily a technology problem; it’s a visibility and process problem, since almost every attack in the group’s history started with a stolen credential, a manipulated help-desk agent, or a bought insider rather than a software exploit. Verizon’s 2024 Data Breach Investigations Report found that 68% of all breaches involve the human element through error, stolen credentials, or social engineering, which is exactly the terrain Lapsus$-style groups operate on.

Lapsus

Dark Web and Telegram Monitoring

Because Lapsus$ and Scattered Lapsus$ Hunters announce breaches, sell access, and negotiate extortion publicly on Telegram and dark web leak sites, organizations that monitor those channels often learn about a compromise before the group’s public leak site goes live, turning a surprise disclosure into a heads-up with time to respond. This kind of monitoring needs to extend beyond traditional dark web marketplaces to include the specific Telegram channels and leak-site infrastructure these groups cycle through, since that’s where they post proof of access, name upcoming targets, and set extortion deadlines well before mainstream media picks up the story. DeXpose’s dark web monitoring tracks exactly these sources, flagging mentions of an organization’s name, domains, or employees across breach forums, marketplaces, and Telegram in near real time.

Credential Exposure Monitoring

Since stolen and purchased credentials are the entry point for nearly every Lapsus$-style intrusion, the single highest-leverage defense is knowing when an employee’s login has already leaked, through a stealer-log dump, a third-party breach, or an underground marketplace listing, before an attacker gets the chance to use it. Running a routine credential exposure check across an organization’s employee email domains catches compromised accounts early enough to force a password reset and MFA re-enrollment before attackers weaponize them in a help-desk social engineering call. Tools like DeXpose’s Free Darkweb Report and Email Data Breach Scan give security teams a fast, no-cost way to check whether company domains or specific employee accounts are already circulating in breach data, which is often the first sign a Lapsus$-style actor has already started building a target profile.

Identity and Access Hardening

Because Lapsus$’s core techniques- MFA fatigue, SIM-swap-enabled SMS interception, and help-desk impersonation- specifically target weak points in identity verification, the most effective structural defense is moving away from SMS and simple-approval push notifications toward phishing-resistant MFA methods like FIDO2 security keys or passkeys, which can’t be approved by mistake or intercepted through a hijacked phone number. Help desks should also require a verification step that can’t be answered from publicly available information or a spoofed phone number, a callback to a pre-registered number, or a manager confirmation, for example, since Lapsus$’s entire help-desk playbook depended on support staff accepting whatever the caller could convincingly claim to know. Finally, limiting standing global-admin and cloud-admin privileges, and alerting on any new admin role assignment or mail-forwarding rule the moment it’s created, closes off the exact persistence techniques the group has relied on since 2022.

Frequently Asked Questions (FAQ’s) 

Is Lapsus$ still active?

Not under its original name, but its core techniques and some members live on through Scattered Lapsus$ Hunters, a 2025 alliance with Scattered Spider and ShinyHunters. That collective has repeatedly announced shutdowns only to resurface weeks later, so treating the threat as dormant would be a mistake.

Is Lapsus$ a ransomware group?

No. Unlike ransomware gangs, it never encrypted victims’ systems; it stole data. It threatened to leak it publicly, relying on extortion and reputational pressure rather than a decryption ransom to get paid.

Who is the leader of Lapsus$?

Researchers and UK prosecutors identified a teenager operating as “White” or “Breachbase,” later named Arion Kurtaj, as the group’s core figure, working alongside a second teenage member believed to be based in Brazil.

How did Lapsus$ hack Rockstar Games and leak GTA 6?

A core member breached Rockstar’s internal Slack using the same social engineering tactics the group used elsewhere, then leaked more than 90 clips of unreleased Grand Theft Auto 6 footage while out on bail in September 2022.

What’s the difference between Lapsus$ and Scattered Lapsus$ Hunters?

Lapsus$ was the original 2021-2022 group; Scattered Lapsus$ Hunters is a broader 2025 coalition that merged Lapsus$’s remnants with Scattered Spider and ShinyHunters, combining their techniques into a single, more active threat collective.

How can a company tell if it’s been targeted?

Warning signs include a spike in help-desk password reset requests, unexpected MFA push notifications, new admin accounts or mail-forwarding rules appearing without explanation, and employee credentials surfacing in dark web breach monitoring.

Did anyone go to prison for the Lapsus$ attacks?

No, its most prominent UK member was found unfit to stand trial due to autism and was ordered into indefinite secure psychiatric care rather than sentenced to prison. At the same time, a co-defendant was convicted as a minor and also not named publicly.

More from the knowledge hub

All guides