Threat actor · all actors
LAPSUS$ (persona)HACK-LAPSUS-HACKTIVIST criminal
aka LAPSUS$, Lapsus, WhiteDoxbin
Last updated:
0attributed CVEs
0ATT&CK techniques
0.0IDF score (tooling uniqueness)
0exclusive CVEs
—years active
About this actor
A 2021-2022 international data-extortion crew that operated with hacktivist-style public messaging on Telegram, claiming high-profile breaches at Microsoft, NVIDIA, Samsung, Okta, and Brazilian state targets. Several UK-based teenage members were arrested in 2022 and convicted in 2023; FBI continues to pursue additional members.
How we know this
- Data origin
- Curated overlay Hacktivist entry synthesised from public reporting — not a MITRE-tracked intrusion set.
- Techniques
- No ATT&CK techniques mapped.
- Named victims
- 4 extracted from reporting.
Thin data: No ATT&CK techniques are mapped yet — the behavioural profile is empty.
See how actor data is built for the full pipeline.
Activity timeline
No activity events recorded.
Profile
| CVE | Risk | CVSS | EPSS | Published | Products |
|---|---|---|---|---|---|
| No attributed CVEs. | |||||
No techniques attributed.
Co-occurring actors
None.