Ransomware Intelligence

lapsus$

Ransomware group profile

22Victims
United KingdomSource country
105Impact score
Also Known As
Strawberry Tempest
Slippy Spider
DEV-0537
G1004

Description

Lapsus$ is a financially motivated cybercrime group that emerged in late 2021, known for employing unconventional data extortion tactics. The group leverages social engineering, SIM swapping, and insider recruitment to gain access to sensitive information from high-profile organizations across various sectors.

Key insights

  • Employs social engineering techniques, including phishing and bribery, to gain initial access.
  • Targets major technology, telecommunications, and gaming companies globally.
  • Utilizes legitimate tools for credential theft instead of deploying custom malware.
  • Publicly threatens victims with data leaks via Telegram to extort ransom.
  • Operates a recruitment program for insiders to facilitate access to internal networks.
  • Often causes disruptions by deleting systems and resources in compromised environments.

Threat Level & Status Breakdown

For lapsus$ · Based on incidents in selected period

3.4threat level
Aggressiveness8/ 10
Lethality0.1/ 10
Criticality1.9/ 10

Status Breakdown

Data Leaked9.1%2
Claimed27.3%6
First seenMar 2026
Last seenMay 2026
Avg ransom
Payment rate
Statusactive
Sophistication0
Last updatedJun 2, 2026

Recent activity

Monthly attack count for lapsus$ in the selected period

22Total attacks
13peak in Mar
7.3avg / month
↓ 10 vs first month
MarAprMay0481216

Intelligence

IOCs, YARA/Sigma rules, and related families for lapsus$

TTPs & Attack Vectors

Tools, initial access, and MITRE ATT&CK techniques for lapsus$

Other

T1078

T1078

T1056

T1056

T1486

T1486

T1490

T1490

T1562

T1562

T1021

T1021

T1021.001

T1021.001

T1003

T1003

T1203

T1203

T1080

T1080

T1557

T1557

Victims(70)

CompanyDomainCountryIndustryStatusDiscovered
VODAFONEDE GermanyTechnology
Unknown
5 days ago
AXCERA TRADINGUS United StatesProfessional Services
Unknown
24 days ago
CHECKMARX.COMcheckmarx.comUS United StatesTechnology
Claimed
26 days ago
MAPFRE ASSURANCEES SpainFinancial Services
Data Leaked
3 days ago
CHECKMARXUS United StatesTechnology
Claimed
about 1 month ago
AXCERA.IOaxcera.ioAE United Arab EmiratesTechnology
Claimed
about 2 months ago
UNIV LILLEFR FranceEducation
Claimed
about 2 months ago
ASTRAZENECA CORPGB United KingdomHealthcare
Claimed
about 2 months ago
VirtaHealthUS United StatesHealthcare
Claimed
about 2 months ago
MERCORUS United StatesProfessional Services
Data Leaked
3 days ago
FR MINISTRY AGRIFR FranceGovernment & Defense
Unknown
3 months ago
ADIDAS EXTRANETRetail & E-Commerce
Unknown
3 months ago
Eiffageeiffage.comFR FranceOther
Unknown
3 months ago
OSAC Aeroosac.aeroFR FranceManufacturing
Unknown
3 months ago
Salesfloorsalesfloor.comCA CanadaTechnology
Unknown
3 months ago
Adidasadidas.deDE GermanyRetail & E-Commerce
Unknown
3 months ago
Loozaploozap.comCH SwitzerlandRetail & E-Commerce
Unknown
3 months ago
Lacostelacoste.comFR FranceRetail & E-Commerce
Unknown
3 months ago
DreamUpdreamup.orgUS United StatesEducation
Unknown
3 months ago
Lille Universityuniv-lille.frFR FranceEducation
Unknown
3 months ago

Page 1 of 4