LAPSUS$

LAPSUS$ — Threat Actor Profile | ObscureIQ
ObscureIQ Threat Intelligence · Actor Profile

LAPSUS$Confidence: High

Data theft / extortion
Also known as: DEV-0537, Strawberry Tempest (Microsoft)

Motivation: Financial; Notoriety

5Attributed Breaches Circulating
HighAttribution Confidence
Data theft / extortionActor Type
Part of the Scattered Lapsus$ Hunters coalition (41 combined breaches). Coalition breaches are tracked once on the coalition profile and cross-referenced here.

Overview

Notorious for its 2022 attacks on Microsoft, Nvidia, Samsung, Okta, Uber, Rockstar Games, T-Mobile, and the Brazilian Ministry of Health, using pure data theft and extortion rather than conventional ransomware. Several teenage members were arrested in the UK and Brazil in 2022; a lineage actor in the later Scattered Lapsus$ Hunters branding. Signature TTPs: social engineering, MFA fatigue, SIM swapping, insider recruitment.

Tactics, Targeting & TTPs

TTPs: social engineering, MFA fatigue, SIM swapping, insider recruitment, supplier targeting. Members (several teenagers) arrested in the UK and Brazil in 2022. A lineage actor in the later Scattered Lapsus$ Hunters branding.

Related Clusters & Actors

Scattered Lapsus$ Hunters

Source

Attribution draws on public threat-intelligence reporting · Established (multi-source). Primary source →

Were you exposed in one of these breaches?

Check your exposure privately, or request a tailored exposure audit.

Request Consultation