Between December 2021 and March 2022, a group of hackers calling themselves LAPSUS$ compromised Microsoft, Nvidia, Samsung, Okta, T-Mobile, Vodafone, Ubisoft, and Globant - releasing source code, employee databases, and internal tools publicly on Telegram before taking ransom demands. The group communicated with the press. They held live Telegram Q&A sessions. They released source code "for fun." When arrests were made in March 2022, the primary suspect was a 16-year-old from Oxford, England.
The Attack Pattern
LAPSUS$ was not technically sophisticated in the traditional sense. They did not use novel zero-day exploits or develop custom malware. Their tradecraft was social engineering, credential theft via infostealer logs, SIM swapping, and the exploitation of MFA weaknesses. What made them effective was persistence, boldness, and the willingness to bribe insiders.
The group used a tool called "2easy" and similar telegram-based infostealer log markets to purchase large volumes of stolen credentials. They then attempted to use those credentials against corporate SSO portals - searching specifically for VPN access, Okta accounts, and corporate email. When MFA blocked direct credential use, they pivoted to several techniques: real-time phishing pages that proxied MFA tokens, repeated push notification bombing (sending repeated MFA push requests until the target approved one in frustration), and SIM swapping to take control of the target's phone number.
For targets with internal access, LAPSUS$ posted in underground forums offering to pay current employees $20,000 per week for continued access. In at least one documented case involving T-Mobile, they bribed employees of a telecom reseller to perform SIM swaps. Insider recruitment was not a backup plan - it was a primary vector.
Nvidia
In February 2022, LAPSUS$ announced they had stolen approximately 1TB of data from Nvidia, including source code for GPU drivers, internal documentation, and - most significantly - Nvidia's cryptographic signing certificates used to sign Windows kernel drivers. They demanded Nvidia remove the LHR (Lite Hash Rate) mining limiter from their GPU firmware, claiming this would allow cryptocurrency miners to use Nvidia cards at full hash rate.
Nvidia declined. LAPSUS$ released the stolen employee credentials, then the driver source code, then - provocatively - Nvidia's signing certificates. The certificates were subsequently used by other threat actors to sign malware as apparently legitimate Windows kernel drivers, bypassing Windows Driver Signature Enforcement. Microsoft eventually added the certificates to its revocation list.
Nvidia's response to the breach included what was widely reported as a counterattack: Nvidia allegedly deployed ransomware against a LAPSUS$ member's machine that was still connected to Nvidia's network. LAPSUS$ claimed the ransomware was ineffective because their data had already been exfiltrated and backed up. Nvidia did not confirm the counter-operation.
Microsoft and the Source Code
In March 2022, LAPSUS$ announced they had compromised Microsoft and published approximately 37GB of Bing, Cortana, and Bing Maps source code on Telegram. Microsoft confirmed the breach, attributing it to "a single account had been compromised, granting limited access." The company stated that no customer data or production systems had been accessed.
Simultaneously, LAPSUS$ announced they had accessed Okta - the identity and access management provider used by thousands of enterprises. The Okta disclosure was the most significant of the LAPSUS$ campaign in terms of second-order effects. Okta provides SSO and MFA to approximately 15,000 enterprise customers; a compromise of Okta's infrastructure could potentially provide access to those customers' systems. Okta's handling of the disclosure - initially minimizing the scope before acknowledging wider impact - became a case study in breach communication failures.
Samsung and Qualcomm
Samsung source code for Galaxy devices - including the bootloader, Knox security layers, and Qualcomm encryption algorithms - was published by LAPSUS$ in February 2022. The release included approximately 190GB of data. Samsung acknowledged the breach and stated no personal data of customers or employees had been stolen. The Qualcomm-related code in the Samsung dump raised supply chain concerns, as Qualcomm's cryptographic components are used in a large number of Android devices beyond Samsung.
Arrests
In March 2022, City of London Police arrested seven people aged 16-21 in connection with the LAPSUS$ investigation. The arrests were coordinated with international law enforcement. The primary suspect - identified by security researchers from KrebsOnSecurity and others as a teenager from Oxford using the handle "White" or "breachbase" - was subsequently identified as Arion Kurtaj.
Kurtaj was on bail from the March arrests when he continued attacking targets. He and an unnamed 17-year-old accomplice hacked Rockstar Games in September 2022 from a Holiday Inn room using only an Amazon Fire Stick TV and a mobile phone - his own devices having been confiscated by police. They leaked 90 Grand Theft Auto VI development clips and claimed to have the GTA V source code, demanding $5 million.
At his trial in 2023, Kurtaj was found guilty of multiple computer misuse and fraud offenses. A psychiatric evaluation found him to have severe autism; the judge determined he could not be tried but found him guilty. He was sentenced to an indefinite hospital order. A second LAPSUS$ member, the unnamed 17-year-old, was convicted and sentenced to an 18-month youth rehabilitation order.
The COM Connection
LAPSUS$ emerged from the same loosely organized English-speaking cybercriminal ecosystem as Scattered Spider - "The COM." The techniques overlap: SIM swapping, credential markets, helpdesk social engineering, MFA fatigue. Some LAPSUS$ members and affiliates appear to have moved between LAPSUS$, Scattered Spider, and unnamed other groups in this ecosystem.
What distinguished LAPSUS$ from Scattered Spider was the motivation: LAPSUS$ appeared primarily interested in notoriety and disruption rather than financial gain. The ransom demands were secondary to the public leak; the Telegram theater was the point. They were demonstrating what was possible against major enterprise targets - companies with substantial security budgets - using social engineering and purchased credentials rather than technical exploits.
The security industry's response to LAPSUS$ accelerated several changes: MFA push number matching became a deployment priority, insider threat programs were revised to address paid recruitment, and the combination of phishing-resistant MFA (FIDO2/passkeys) with device attestation was accelerated. LAPSUS$ proved that the credential-based perimeter could be walked through by a teenager in Oxford with a phone and a Telegram account.