Skip to content
Security Notes

Lapsus$: teenagers versus nine-figure security budgets

By Elias Lankinen11 min read

Now I have everything. Here is the post.

The Fire Stick in the Travelodge

In September 2022, a 17-year-old sat in a Travelodge hotel room in Oxfordshire. He was on bail, under police protection, and his laptop had been confiscated. What he had instead was an Amazon Fire TV Stick plugged into the hotel television, a mobile phone, and a cheap keyboard and mouse. With that setup, according to evidence heard at Southwark Crown Court, he broke into Rockstar Games, walked out with roughly 90 videos of the unreleased Grand Theft Auto VI, and posted them online. It was one of the largest leaks in the history of video games, and it was pulled off with about the same hardware you would use to stream a movie. The teenager was Arion Kurtaj, and the crew he belonged to was called Lapsus$. Over roughly a year, this loose collective of teenagers and young adults breached Nvidia, Microsoft, Samsung, Okta, Uber, and Rockstar. These are companies whose combined security spending runs into the billions. Microsoft alone pledged $20 billion over five years to cybersecurity in 2021, the year before Lapsus$ walked off with 37 gigabytes of its source code.

Source: Coolcaesar, Wikimedia Commons
Source: Coolcaesar, Wikimedia Commons

The story is not really about clever code. It is about what happens when a group of young people decides to attack the one part of a security system that no budget has ever fully fixed: the human being at the help desk, and the phone in their pocket.

The common misconception: this was not sophisticated hacking

When a name like Nvidia or Microsoft appears in a breach headline, the mental image is usually of shadowy state-backed operatives deploying zero-day exploits, meaning attacks that use software flaws no one has discovered or patched yet. Lapsus$ did almost none of that. The Cyber Safety Review Board, a US government body that convenes experts to dissect major cyber incidents in the way the National Transportation Safety Board dissects plane crashes, published its post-mortem on the group in August 2023. Its central conclusion was blunt: Lapsus$ used "simple techniques, like stealing cell phone numbers and phishing employees, to gain access to companies and their proprietary data." The board went out of its way to note that some of the people doing this were teenagers, and that they succeeded against organizations "with robust cybersecurity programs." That is the uncomfortable part. Lapsus$ did not out-engineer these companies. They went around the engineering entirely. Their toolkit was social, not technical: convince a person, buy a person, or hijack a person's phone number. Each of those attacks costs almost nothing and defeats controls that cost a fortune.

Who they actually were

Lapsus$ was not a corporate crime syndicate. It was closer to a group chat that got dangerously good at what it did. Security journalist Brian Krebs traced the apparent leader to a 17-year-old from Oxford, England, who used names like "White," "WhiteDoxbin," and earlier "Breachbase." Before Lapsus$, this person had been a founding member of a group called the Recursion Team, which specialized in SIM swapping and "swatting" (calling in fake emergencies to send armed police to a victim's home). Krebs reported that the teenager had at one point amassed close to $14 million in Bitcoin from trading in stolen data and hacking tools, a figure that should be treated as a reported estimate rather than an audited number. In March 2022, UK police arrested seven people aged between 16 and 21 in connection with the group. What made Lapsus$ unusual was how loudly it operated. Instead of hiding on dark-web forums, it ran a public Telegram channel with tens of thousands of subscribers, announcing breaches, leaking samples, mocking victims, and even running polls asking followers which company to hit next. It behaved less like a covert intelligence operation and more like a chaotic online community chasing notoriety as much as money. That personality matters, because it shaped the tactics. A group that wants attention and quick cash does not spend six months developing an exploit. It looks for the fastest way in.

The playbook: four cheap doors

Strip away the specific victims and Lapsus$ used the same small handful of moves over and over. SIM swapping. A SIM swap is when an attacker convinces (or bribes) a mobile carrier to move your phone number to a SIM card they control. Once they have your number, every text-message security code and every "tap to approve" login prompt sent to that number goes to them instead of you. This is why the review board treated telecom companies as part of the problem: as long as a phone number can be stolen with a phone call to a carrier's support line, any security that relies on that number is only as strong as the least-trained call-center agent.

Source: Kirk, Wikimedia Commons
Source: Kirk, Wikimedia Commons

Buying insiders. Lapsus$ openly advertised for employees willing to sell access. Krebs documented recruitment posts offering up to "$20,000 a week" to insiders at telecom firms like AT&T, T-Mobile, and Verizon. In December 2021 the group offered $15,000 to potential insiders inside Brazil's Federal Police. For a fee, an accomplice could simply hand over their password, approve a login prompt, or install remote-access software on a work computer. No exploit required, just a willing employee. MFA fatigue. Multi-factor authentication (MFA) adds a second step to a login, usually a code or a push notification to your phone, so that a stolen password alone is not enough. Lapsus$ found a way through it that relies entirely on human exhaustion. Once they had a valid password, they would trigger login attempt after login attempt, sending a stream of approval prompts to the victim's phone until, worn down or confused, the person tapped "approve." Microsoft, which tracks the group under the label DEV-0537, described this as using stolen passwords to trigger "simple-approval MFA prompts," alongside replaying stolen session tokens. Phishing and help-desk deception. When all else failed, they called. Members would phone a company's IT help desk, pose as an employee locked out of their account, and talk the agent into resetting credentials or MFA. Microsoft noted the group used native-English-sounding callers to sound convincing and answer security questions. None of this shows up on a firewall.

A tour of the wreckage

Nvidia

Nvidia discovered the intrusion on February 23, 2022. Lapsus$ made off with roughly a terabyte of data. When the company refused to negotiate, the group leaked the usernames and password hashes of more than 71,000 Nvidia employees, along with proprietary material including source code for DLSS, Nvidia's AI image-upscaling system. The strangest part was the ransom demand. Rather than money, Lapsus$ demanded that Nvidia open-source its graphics drivers and remove a feature that throttled the chips' cryptocurrency-mining performance. But the most damaging fallout was technical. The leak included two of Nvidia's code-signing certificates, the digital signatures that tell Windows a piece of software is trustworthy. Both had expired years earlier (valid from 2011 to 2014 and 2015 to 2018), but Windows will still accept expired certificates for drivers. Within days, criminals were using them to sign malware, including Cobalt Strike beacons, Mimikatz, and various backdoors, so it would sail past security checks. A breach carried out with social engineering produced a technical weapon that outlived the breach itself.

Microsoft

Microsoft confirmed in March 2022 that Lapsus$ had leaked 37 gigabytes of source code pulled from an internal Azure DevOps server, covering more than 250 projects including Bing, Cortana, and Bing Maps. The company said a single account had been compromised and insisted no customer data was exposed.

Source: Atomic Taco, Wikimedia Commons
Source: Atomic Taco, Wikimedia Commons

There is a revealing detail in Microsoft's account. Its security team was already investigating the compromised account when Lapsus$ bragged about the intrusion publicly. That boast, meant to humiliate the company, actually helped it: the public disclosure escalated the response and let the team cut the attackers off mid-operation. The group's appetite for attention was, in this one case, its undoing.

Okta

The Okta breach shows how far a small intrusion can ripple. Okta sells identity management: it is the login layer that thousands of other companies use to control who gets into their systems. Compromise Okta and you potentially compromise everyone downstream. In late January 2022, Lapsus$ got into a laptop belonging to a support engineer working for Sykes, a subcontractor of Sitel, which handled customer support for Okta. Okta's own timeline shows its security team was alerted on January 20 when a new MFA factor was added to the contractor's account from an unfamiliar location. The attacker's actual window of control over the machine lasted, by Okta's final forensic account, just 25 minutes, touching two customer tenants. But customers did not learn any of this until March 22, when Lapsus$ posted screenshots of Okta's internal systems. Okta ultimately notified 366 customers whose data might have been affected. The damage was less about the 25 minutes and more about the two months of silence, and the discovery that a company selling trust could be reached through a subcontractor's subcontractor.

The finale: Uber and Rockstar

By September 2022, several members had been arrested, but the attacks kept coming. An 18-year-old using the handle "Tea Pot" broke into Uber. The method was pure Lapsus$. The attacker had a contractor's password, likely bought online, and then bombarded the contractor with roughly 40 push notifications over more than an hour. When those were ignored, the attacker messaged the contractor on WhatsApp, posed as Uber IT support, and told them to accept the prompt to make it stop. They did. Once inside Uber's network, the attacker found a PowerShell script containing admin credentials, which unlocked deep access to systems including Uber's AWS accounts, Google Workspace, and its own security tooling. A single approved notification cascaded into near-total access. Days later came Rockstar and the GTA VI leak described at the top of this piece. Kurtaj got in through Rockstar's internal Slack workspace. The cleanup reportedly cost Rockstar at least $5 million and countless staff hours, though parent company Take-Two publicly downplayed any lasting financial impact and its stock recovered. Estimates of the total damage Lapsus$ inflicted across all its victims run toward $10 million, a figure that is inherently rough given how differently companies account for these losses.

What the review board actually recommended

The Cyber Safety Review Board's report is worth reading precisely because it refuses to treat Lapsus$ as a freak event. Its recommendations target the structural weaknesses the group exploited. The headline advice is to move past passwords and phone-based MFA toward phishing-resistant, passwordless authentication, specifically FIDO2-compliant methods. FIDO2 is a standard behind hardware security keys and passkeys, where the "second factor" is a cryptographic key tied to a physical device and the specific website, rather than a code that can be read aloud, phished, or intercepted through a hijacked SIM. Crucially, this defeats MFA fatigue, because there is no prompt to wear someone down into approving. There is nothing to approve by mistake. The board also pointed directly at the telecom industry, urging the Federal Communications Commission and Federal Trade Commission to standardize and enforce anti-SIM-swapping practices and require carriers to report how often it happens. And it made a point rarely found in a government cyber report: because several perpetrators were juveniles, the usual deterrents (arrest, prosecution) work poorly. It suggested the US study international programs that identify at-risk young hackers early and steer their skills toward legitimate outlets like competitions and bug-bounty work. That last point landed hard in the Kurtaj case. He has severe autism and was deemed unfit to stand trial; the jury was asked only whether he committed the acts, not whether he was guilty of them. In December 2023 he was found to have committed a series of hacks and given an indefinite hospital order, with the judge noting he remained determined to return to cybercrime at the first opportunity. His co-defendant, 17 at the time of the offenses, received an 18-month youth rehabilitation order. As of 2026, Kurtaj's case is heading back toward a retrial, a reminder that the legal system is still improvising its response to this kind of offender.

The lesson nobody wants

The tempting takeaway is that these companies were careless. They were not. They were, by any normal measure, extremely well defended. That is exactly what makes Lapsus$ instructive. A nine-figure security budget buys world-class encryption, threat detection, and network segmentation. What it cannot buy is a guarantee that a tired contractor will not tap "approve," that a call-center agent will not reset the wrong account, or that an underpaid employee will not sell their password for a week's wages. The most expensive parts of a security program defend the machine. The cheapest attacks target the person operating it. Lapsus$ understood that asymmetry better than the companies spending billions to be safe. The shift to passkeys and hardware-based logins is, slowly, closing the specific doors Lapsus$ walked through. Push-notification fatigue does not work against a security key, and a stolen SIM is useless if no code is ever sent to it. But the deeper pattern is not going anywhere. The successors to Lapsus$, groups like Scattered Spider, have used the same social-engineering-first approach to hit casinos, insurers, and retailers since. The question worth watching is not whether companies will finally out-spend the teenagers. It is whether they will finally stop trying to, and instead redesign the systems so that no single human, tired or bribed or fooled, can hand over the keys.

Sources

  1. Cybersecurity and Infrastructure Security Agency, "Review of the Attacks Associated with Lapsus$ and Related Threat Groups Report", 2023.
  2. Krebs on Security, "A Closer Look at the LAPSUS$ Data Extortion Group", 2022.
  3. Flashpoint, "All About LAPSUS$: What We Know About the Extortionist Group", 2022.
  4. BleepingComputer, "Microsoft confirms they were hacked by Lapsus$ extortion group", 2022.
  5. BetaNews, "Microsoft confirms it was hacked as Lapsus$ leaks 37GB of source code", 2022.
  6. Anvilogic, "Microsoft Confirms Lapsus$ Hack: Detailed Analysis of Tactics and Impact", 2022.
  7. Quorum Cyber, "NVIDIA breached, code signing certificates stolen", 2022.
  8. BleepingComputer, "Malware now using NVIDIA's stolen code signing certificates", 2022.
  9. Analytics India Magazine, "Lapsus$ hack leaves NVIDIA in a tight spot", 2022.
  10. TechCrunch, "Okta says hundreds of companies impacted by security breach", 2022.
  11. BleepingComputer, "Okta: Lapsus$ breach lasted only 25 minutes, hit 2 customers", 2022.
  12. Dark Reading, "Okta Says 366 Customers Impacted via Third-Party Breach", 2022.
  13. The Hacker News, "Uber Blames LAPSUS$ Hacking Group for Recent Security Breach", 2022.
  14. Ace Cloud Hosting, "Uber Hack 2022 – The Lapsus$ Breach Cyberattack", 2022.
  15. Optimum Specialty Risks, "Anniversary of the Lapsus$ Hack on Rockstar", 2023.
  16. PC Gamer, "Grand Theft Auto 6 leaker who was given an indefinite sentence... is now out of hospital and awaiting retrial", 2026.
  17. The Record, "Autistic teen behind spate of Lapsus$ hacks sentenced to indefinite hospital stay", 2023.
  18. GeekWire, "Microsoft to quadruple cybersecurity investments, spending $20B over five years", 2021.
  19. IT Pro, "CISA urges organizations to adopt passwordless security in LAPSUS$ report", 2023.
  20. Industrial Cyber, "CSRB reports on global extortion-focused Lapsus$ hacker group, provides list of recommendations", 2023.
  21. Entrepreneur, "GTA Hacker Gets Life Sentence for Stealing $10 Million Data", 2023.
  22. Bleap, "How Much Did the GTA 6 Leaks Cost? The Fallout", 2024.