Meet Lapsus$: An Unusual Group in the Cyber Extortion Business
ID: f31a433a-7989-5b8c-a18c-aa2e7aad2038
STIX ID: report--f31a433a-7989-5b8c-a18c-aa2e7aad2038
Feed Name: ReliaQuest Blog
The report profiles Lapsus$, an active cyber extortion group since late 2021 that has targeted high-profile organizations (including NVIDIA and Samsung) by gaining access through RDP, phishing, purchased access, or recruited insiders and publicly leaking exfiltrated data via Telegram rather than traditional leak sites; it notes no evidence of deployed ransomware and recommends mitigations such as MFA, securing VPN/RDP, employee security training, and monitoring for insider threats.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
