Lapsus$

Active
Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.
25 Victims
Dec 9, 2021 First Discovered
Jun 23, 2026 Last Discovered
85 Days Inactive
0% Infostealer
1/4 Sites Online
Known Locations (4)
LAPSUS$
lapsus.bz
LAPSUS$ | DATA REPOSITORY
lapsus.by
Directory listing for /
mwojud552brg7rl3obqjvv2funhwpg6acdsuuoeytq7365kmaeoi4gqd.onion
Origin DNS error | lapsus.cz | Cloudflare
lapsus.cz
Tools Used
CredentialTheft
Mimikatz
DiscoveryEnum
ADExplorer
LOLBAS
NTDS Utility (ntdsutil)
RMM-Tools
AnyDesk
Victims (25)

Detailed victim list temporarily unavailable

This group has 25 victims. The victim list API is currently responding slowly for this dataset. Country, sector, and infostealer breakdowns are not available at this time. Basic stats (victim count, first/last seen) are shown above from a faster data source.