Between late February and late March 2022 the group calling itself Lapsus$ published material taken from a series of technology companies. Reporting describes around 20GB from Nvidia including employee credential hashes, around 190GB from Samsung including Galaxy device source code — reported to cover biometric authentication and bootloader components — and material from Microsoft’s internal Azure DevOps, described as source code for Bing and Cortana among other projects.
Microsoft reported that it interrupted the exfiltration mid-transfer, having learned of the intrusion because the group discussed its access publicly on Telegram while the download was in progress.
Extortion Without A Payload
There is no encryption in this campaign and no recovery problem to solve. The threat is publication, and the asset is whatever the company would least like read.
We have recorded the same model maturing across the following years — at 22-1024, where a refusal was answered with a targeted release, and throughout the ShinyHunters files. Lapsus$ is early evidence that the encryption step was always optional, and that operations which drop it lose the recovery leverage but keep the reputational one and shed most of the engineering.
Source Code Is Not A Customer Database
Almost every file in this corpus counts affected people. Here there is no such number for the main harm, because the stolen material was code.
Published source for biometric authentication or a bootloader does not expose an individual; it lowers the cost of finding the next flaw for everyone who runs the product. That harm is diffuse, deferred and uncountable, which is why no disclosure regime addresses it and why this file carries no affected-population figure.
The Operational Security Was The Defence
Microsoft learned it was being robbed because the robbers said so publicly, in real time, and the transfer was cut off before it finished.
That is not a control anyone can design for. We have recorded at 22-0227 that an operation of this kind is held together by the agreement of its members, and this is the same fragility from a different angle: a group that runs on public spectacle is a group whose spectacle is an intelligence feed. It is a defence that works exactly once per adversary, and only against the loud ones.
Built on contemporaneous reporting of the group’s successive claims and on the affected companies’ statements. The approximate volumes, the categories of material, and Microsoft’s account of interrupting the transfer after the group discussed its access publicly are as reported. Figures published by an extortion group about its own haul are claims, not counts, and are carried as such — which is the principal reason this file is graded medium. No individual is named: reporting at the time identified a minor as central to the group, and this desk names individuals only after conviction and does not name minors. Subsequent proceedings are outside the scope of this file. Corrections: corrections@forensicpost.com.
- A Closer Look at the LAPSUS$ Data Extortion GroupKrebs on Security
- Samsung confirms hackers stole source codeTechCrunch