HackerFeeds
All ransomware groups

lapsus$

25 tracked victims
·first seen 2021-12-10·last activity 2026-06-23

Group profile

Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.

Recent victims

DateWebsite / victimSectorCountry
2026-06-23
A
AYA BANK
Financial ServicesMM
2026-06-13
ingka.com
INGKA GROUPingka.com
Consumer ServicesSE
2026-06-13
github.com
GITHUB INTERNALgithub.com
TechnologyUS
2026-03-31
M
MERCOR
Not Found
2026-04-26
M
MAPFRE ASSURANCE
Financial ServicesES
2026-05-28TelecommunicationDE
2026-05-10
axcera.io
AXCERA TRADINGAXCERA.IO
Business ServicesUS
2026-04-24TechnologyUS
2026-03-22
axcera.io
AXCERA.IOAXCERA.IO
TechnologyUS
2026-03-25
astrazeneca.co.uk
ASTRAZENECA CORPastrazeneca.co.uk
HealthcareGB
2026-03-29
virtahealth.com
VirtaHealthvirtahealth.com
HealthcareUS
2026-03-01ConstructionFR
2026-03-01
osac.aero
OSAC Aeroosac.aero
ManufacturingFR
2026-03-01
salesfloor.com
Salesfloorsalesfloor.com
TechnologyCA
2026-03-01Consumer ServicesDE
2026-03-01Consumer ServicesCH
2026-03-01Consumer ServicesFR
2026-03-01EducationUS
2026-03-01
univ-lille.fr
Lille Universityuniv-lille.fr
EducationFR
2026-03-01
agriculture.gouv.fr
FR Ministry of Agricultureagriculture.gouv.fr
Public SectorFR
2026-03-01
eni.com
Eni Energyeni.com
EnergyIT
2022-03-07
S
Samsung Electronics
TechnologyJP
2022-02-25
N
Nvidia
TechnologyUS
2022-01-01
I
Impresa
Business ServicesPT
2021-12-10
B
Brazilian Ministry of Health
Public SectorBR