Back to Ransomware Database
Ransomware Group
lapsus$
Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.
Known victims25
Threat Level
MEDIUM
Tactics, Techniques & Procedures (TTPs)
CredentialTheft
- Mimikatz
DiscoveryEnum
- ADExplorer
LOLBAS
- NTDS Utility (ntdsutil)
RMM-Tools
- AnyDesk
Check If You’re Affected
Search our database to see if your organization appears in lapsus$’s victim list.
Try it nowFree⌘K
Try
risk score · threat categories · sources · age · confidence — in one request