LAPSUS$ — Hacktivist Profile
LAPSUS$ is cyber criminal threat group that has been active since at least mid-2021. LAPSUS$ specializes in large-scale social engineering and extortion operations, including destructive attacks without the use of ransomware. The group has targeted organizations globally, including in the government, manufacturing, higher education, energy, healthcare, technology, telecommunications, and media sectors.Also tracked as
DEV-0537, Strawberry Tempest
Tools & malware
- Mimikatz Credential Harvesting
Recent claimed victims
- AYA BANK 2026-06-23
- GITHUB INTERNAL 2026-06-13
- INGKA GROUP 2026-06-13
- MERCOR 2026-05-31
- MAPFRE ASSURANCE 2026-05-31
- VODAFONE 2026-05-29
- AXCERA TRADING 2026-05-10
- CHECKMARX 2026-04-25
- ASTRAZENECA CORP 2026-04-05
- AXCERA.IO 2026-04-05
- VirtaHealth 2026-04-05
- Eni Energy 2026-03-01
- FR Ministry of Agriculture 2026-03-01
- Lille University 2026-03-01
- Loozap 2026-03-01
- Lacoste 2026-03-01
- Adidas 2026-03-01
- Salesfloor 2026-03-01
- Eiffage 2026-03-01
- DreamUp 2026-03-01
- OSAC Aero 2026-03-01