Skip to content

lapsus$

Active

21 tracked victims · First seen Dec 10, 2021 · Last seen Jun 23, 2026

About

Aggregated threat-intel description

Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.

Sectors: Technology, Education, Consumer Services · Countries: FR, US, DE

Recent victims

View all →
VictimSectorCountryPostedStatus
AYA BANKFinancial ServicesMMJun 23, 2026
INGKA GROUPConsumer ServicesSEJun 13, 2026
GITHUB INTERNALTechnologyUSJun 13, 2026
MERCORNot FoundMay 31, 2026
MAPFRE ASSURANCEFinancial ServicesESMay 31, 2026
VODAFONETelecommunicationDEMay 29, 2026
AXCERA.IOTechnologyUSApr 5, 2026
FR MINISTRY AGRICULTUREPublic SectorFRApr 5, 2026
UNIV LILLEEducationFRApr 5, 2026
ASTRAZENECA CORPHealthcareGBApr 5, 2026
VirtaHealthHealthcareUSApr 5, 2026
EiffageConstructionFRMar 1, 2026
OSAC AeroNot FoundFRMar 1, 2026
SalesfloorTechnologyCAMar 1, 2026
AdidasConsumer ServicesDEMar 1, 2026
LoozapNot FoundMar 1, 2026
LacosteConsumer ServicesFRMar 1, 2026
DreamUpEducationUSMar 1, 2026
Lille UniversityEducationFRMar 1, 2026
FR Ministry of AgriculturePublic SectorFRMar 1, 2026
Eni EnergyEnergyITMar 1, 2026

All ransomware groups · Dark web intelligence