The US Cyber Safety Review Board (CSRB) has published a comprehensive analysis of the Lapsus$ hacker group’s cyber extortion activities. The report highlighted simple but effective tactics the Lapsus$ hackers used to compromise organizations and the existing security gaps enabling them.
Lapsus$ hackers repeatedly accessed T-Mobile's internal systems, including Atlas account management system capable of SIM swapping, and downloaded thousands of source code repositories.
Globant SAS confirmed a data breach affecting a "limited" number of customers after Lapsus$ hackers published 70GB of source code allegedly stolen from the company. Screenshots suggested that the leaked customer source code belonged to companies like Apple, Facebook and DHL.
Lapsus$ hackers compromised Microsoft's Azure DevOps Server, exfiltrated and published source code for the company's web infrastructure, websites, and mobile apps.
Lapsus$ hackers appeared to be reckless – posting about their activities on Twitter and other social media sites, and reportedly broke into Zoom conference calls at the companies they had just breached to taunt employees.





