Lapsus$ is an extortion group that grabbed headlines by breaching major technology companies through social engineering and insider recruitment rather than sophisticated malware.
Key facts
- Breached several major technology and software firms in 2022.
- Relied on social engineering, MFA fatigue and buying insider access.
- Focused on data theft and public extortion rather than encryption.
- Several alleged members, reportedly young, were arrested.
Why it matters
Lapsus$ showed how cheap social engineering can defeat well-resourced companies. Detecting leaked credentials and insider-sold access is a key early warning.
How DarkThreatX helps
DarkThreatX tracks threat-actor activity, leaked credentials and exposed data across the dark web so security teams can act on early warning. Run a free dark web scan or explore the platform.