Desk live·
ForensicPost
Breaches/Extortion/File 22-0322

Lapsus$ Took Source Code From Nvidia, Samsung and Microsoft Without Encrypting Anything

Nvidia, Samsung and Microsoft in five weeks. Lapsus$ ran no ransomware payload — it took code and threatened to publish it, and in Microsoft’s case announced the theft on Telegram while the download was still running.

Constructed geometry · not a chart of case data
JurisdictionUSAthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetNvidia, Samsung, Microsoft
ActorLapsus$
D. Kennedy12 min readConfidence: medium2 sources reviewed

Between late February and late March 2022 the group calling itself Lapsus$ published material taken from a series of technology companies. Reporting describes around 20GB from Nvidia including employee credential hashes, around 190GB from Samsung including Galaxy device source code — reported to cover biometric authentication and bootloader components — and material from Microsoft’s internal Azure DevOps, described as source code for Bing and Cortana among other projects.

Microsoft reported that it interrupted the exfiltration mid-transfer, having learned of the intrusion because the group discussed its access publicly on Telegram while the download was in progress.

Extortion Without A Payload

There is no encryption in this campaign and no recovery problem to solve. The threat is publication, and the asset is whatever the company would least like read.

We have recorded the same model maturing across the following years — at 22-1024, where a refusal was answered with a targeted release, and throughout the ShinyHunters files. Lapsus$ is early evidence that the encryption step was always optional, and that operations which drop it lose the recovery leverage but keep the reputational one and shed most of the engineering.

Source Code Is Not A Customer Database

Almost every file in this corpus counts affected people. Here there is no such number for the main harm, because the stolen material was code.

Published source for biometric authentication or a bootloader does not expose an individual; it lowers the cost of finding the next flaw for everyone who runs the product. That harm is diffuse, deferred and uncountable, which is why no disclosure regime addresses it and why this file carries no affected-population figure.

The Operational Security Was The Defence

Microsoft learned it was being robbed because the robbers said so publicly, in real time, and the transfer was cut off before it finished.

That is not a control anyone can design for. We have recorded at 22-0227 that an operation of this kind is held together by the agreement of its members, and this is the same fragility from a different angle: a group that runs on public spectacle is a group whose spectacle is an intelligence feed. It is a defence that works exactly once per adversary, and only against the loud ones.

How we reported this

Built on contemporaneous reporting of the group’s successive claims and on the affected companies’ statements. The approximate volumes, the categories of material, and Microsoft’s account of interrupting the transfer after the group discussed its access publicly are as reported. Figures published by an extortion group about its own haul are claims, not counts, and are carried as such — which is the principal reason this file is graded medium. No individual is named: reporting at the time identified a minor as central to the group, and this desk names individuals only after conviction and does not name minors. Subsequent proceedings are outside the scope of this file. Corrections: corrections@forensicpost.com.

Sources
  1. A Closer Look at the LAPSUS$ Data Extortion GroupKrebs on Security
  2. Samsung confirms hackers stole source codeTechCrunch
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary