← All ransomware groups
Lapsus$ logo

Ransomware group profile · #148 by claimed victims

Lapsus$ ransomware

Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.

Active First seen Sep 2026
25Victims claimed on leak sites
0Victims in the last 30 days
1Victims in the last 90 days
13Countries hit
6Leak-site URLs tracked, 3 online
23 Jun 2026Latest claim recorded

Victimology

Who Lapsus$ claims to have breached, from 25 leak-site posts recorded by VULONE.

Claims per month last 12 months

Oct 2025: 0OctNov 2025: 0Dec 2025: 0Jan 2026: 0JanFeb 2026: 0Mar 2026: 10Apr 2026: 4AprMay 2026: 4Jun 2026: 3Jul 2026: 0JulAug 2026: 0Sep 2026: 0

Top sectors

Technology7
Retail & E-Commerce4
Healthcare2
Professional Services2
Financial Services2
Government & Defense2
Education2
Transportation1

Top countries

United States7
France5
Germany2
Canada1
Italy1
United Kingdom1
Japan1
Portugal1

Latest claimed victims 12 most recent

VictimSectorCountryClaimed
AYA BANK ayabank.com Financial Services MM 23 Jun 2026
INGKA GROUP ingka.com Retail & E-Commerce SE 13 Jun 2026
GITHUB INTERNAL github.com Technology US 13 Jun 2026
MERCOR Not Found 31 May 2026
MAPFRE ASSURANCE Financial Services ES 31 May 2026
VODAFONE vodafone.com Technology DE 29 May 2026
AXCERA TRADING axcera.io Professional Services US 10 May 2026
CHECKMARX checkmarx.com Technology US 25 Apr 2026
AXCERA.IO axcera.io Technology US 5 Apr 2026
ASTRAZENECA CORP astrazeneca.co.uk Healthcare GB 5 Apr 2026
VirtaHealth virtahealth.com Healthcare US 5 Apr 2026
Eiffage eiffage.com Transportation FR 1 Mar 2026

All 25 Lapsus$ victims, searchable

Full victim list with claim posts, domains, timing and exports, plus the negotiation chats and leak-site screenshots VULONE archives for this crew.

Start free Sign in

Tactics, techniques and procedures

ATT&CK technique mapping for Lapsus$ is in progress. Victimology, infrastructure status and leak-site tracking are live above.

Indicators, detections and the full playbook

Hashes, C2 addresses, onion services, Sigma and YARA detections per technique, and the negotiation transcripts are available to signed-in analysts.

See full IOCs

Frequently asked

Is Lapsus$ ransomware still active?
Lapsus$ is tracked as active. The most recent leak-site claim VULONE recorded is dated 23 June 2026.
How many victims has Lapsus$ claimed?
VULONE has recorded 25 leak-site victim claims attributed to Lapsus$ since December 2021, across 13 countries and 11 sectors.
Which industries does Lapsus$ target?
The sectors most often named on the Lapsus$ leak site are Technology, Retail & E-Commerce, Healthcare.
Which countries are most affected by Lapsus$?
Most Lapsus$ victims recorded by VULONE are located in United States, France, Germany.
Where does VULONE get Lapsus$ victim data?
Claims are collected continuously from the group's own leak sites and cross-checked with ransomware.live and RansomLook. A claim is the group's assertion, not a confirmed breach.

VULONE research mentioning Lapsus$

Other ransomware groups

Victim claims are collected from leak sites and enrichment partners (ransomware.live, RansomLook) and represent the group's own assertions, not confirmed breaches. Profile last updated 16 September 2026. Questions or corrections: [email protected].