Skip to main content
Back to Ransomware Database
Ransomware Group

lapsus$

Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.

Known victims25

Threat Level

MEDIUM

Tactics, Techniques & Procedures (TTPs)

CredentialTheft

  • Mimikatz

DiscoveryEnum

  • ADExplorer

LOLBAS

  • NTDS Utility (ntdsutil)

RMM-Tools

  • AnyDesk
0

Check If You’re Affected

Search our database to see if your organization appears in lapsus$’s victim list.

Try it nowFree⌘K
Try

risk score · threat categories · sources · age · confidence — in one request