Ransomware Intelligence

lapsus$

Ransomware group profile

24Victims
United KingdomSource country
105Impact score
Also Known As
Strawberry Tempest
Slippy Spider
DEV-0537
G1004

Description

Lapsus$ is a financially motivated cybercrime group that emerged in late 2021, known for employing unconventional data extortion tactics. The group leverages social engineering, SIM swapping, and insider recruitment to gain access to sensitive information from high-profile organizations across various sectors.

Key insights

  • Employs social engineering techniques, including phishing and bribery, to gain initial access.
  • Targets major technology, telecommunications, and gaming companies globally.
  • Utilizes legitimate tools for credential theft instead of deploying custom malware.
  • Publicly threatens victims with data leaks via Telegram to extort ransom.
  • Operates a recruitment program for insiders to facilitate access to internal networks.
  • Often causes disruptions by deleting systems and resources in compromised environments.

Threat Level & Status Breakdown

For lapsus$ · Based on incidents in selected period

2.4threat level
Aggressiveness5/ 10
Lethality0.2/ 10
Criticality1.9/ 10

Status Breakdown

Data Leaked12.5%3
Claimed29.2%7
First seenMar 2026
Last seenJun 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 20, 2026

Recent activity

Monthly attack count for lapsus$ in the selected period

24Total attacks
13peak in Mar
6avg / month
↓ 11 vs first month
MarAprMayJun0481216

Intelligence

IOCs, YARA/Sigma rules, and related families for lapsus$

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for lapsus$

Other

T1078

T1078

T1056

T1056

T1486

T1486

T1490

T1490

T1562

T1562

T1021

T1021

T1021.001

T1021.001

T1003

T1003

T1203

T1203

T1080

T1080

T1557

T1557

Victims(72)

CompanyDomainCountryIndustryStatusDiscovered
INGKA GROUPingka.comSE SwedenRetail & E-Commerce
Claimed
8 days ago
GITHUB INTERNALgithub.comUS United StatesTechnology
Data Leaked
8 days ago
VODAFONEDE GermanyTechnology
Unknown
22 days ago
AXCERA TRADINGUS United StatesProfessional Services
Unknown
about 1 month ago
CHECKMARX.COMcheckmarx.comUS United StatesTechnology
Claimed
about 1 month ago
MAPFRE ASSURANCEES SpainFinancial Services
Data Leaked
21 days ago
CHECKMARXUS United StatesTechnology
Claimed
about 2 months ago
AXCERA.IOaxcera.ioAE United Arab EmiratesTechnology
Claimed
3 months ago
UNIV LILLEFR FranceEducation
Claimed
3 months ago
ASTRAZENECA CORPGB United KingdomHealthcare
Claimed
3 months ago
VirtaHealthUS United StatesHealthcare
Claimed
3 months ago
MERCORUS United StatesProfessional Services
Data Leaked
21 days ago
FR MINISTRY AGRIFR FranceGovernment & Defense
Unknown
4 months ago
ADIDAS EXTRANETRetail & E-Commerce
Unknown
4 months ago
Eiffageeiffage.comFR FranceOther
Unknown
4 months ago
OSAC Aeroosac.aeroFR FranceManufacturing
Unknown
4 months ago
Salesfloorsalesfloor.comCA CanadaTechnology
Unknown
4 months ago
Adidasadidas.deDE GermanyRetail & E-Commerce
Unknown
4 months ago
Loozaploozap.comCH SwitzerlandRetail & E-Commerce
Unknown
4 months ago
Lacostelacoste.comFR FranceRetail & E-Commerce
Unknown
4 months ago

Page 1 of 4