logo

Meet Lapsus$: An Unusual Group in the Cyber Extortion Business

ID: f31a433a-7989-5b8c-a18c-aa2e7aad2038

STIX ID: report--f31a433a-7989-5b8c-a18c-aa2e7aad2038

Feed Name: ReliaQuest Blog

Threat Score
75/100

Date Published: 2022-03-17

Date Updated: 2026-04-29

...
...

The report profiles Lapsus$, an active cyber extortion group since late 2021 that has targeted high-profile organizations (including NVIDIA and Samsung) by gaining access through RDP, phishing, purchased access, or recruited insiders and publicly leaking exfiltrated data via Telegram rather than traditional leak sites; it notes no evidence of deployed ransomware and recommends mitigations such as MFA, securing VPN/RDP, employee security training, and monitoring for insider threats.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.