What Happened to Lapsus$?
Lapsus$ is an international extortion-focused black-hat hacker group that gained notoriety in late 2021 for a series of high-profile cyberattacks against major tech companies like Microsoft, Nvidia, Samsung, and Okta. The group, largely composed of teenagers, primarily uses social engineering, SIM swapping, and insider recruitment for data exfiltration and extortion. While several key members have been arrested and convicted in the UK and Brazil, including leader Arion Kurtaj who received an indefinite hospital order in December 2023, a Lapsus$-branded actor announced a return to active operations in September 2026, claiming to challenge federal law enforcement.
Quick Answer
Lapsus$ is a notorious cybercrime group known for its data extortion tactics against major corporations and government entities. Although several key members, including leader Arion Kurtaj, were arrested and convicted in 2022 and 2023, the group's activities have seen a complex evolution. In September 2026, a Lapsus$-branded actor declared a return to operations, signaling a potential resurgence or continuation under a new guise, explicitly challenging federal law enforcement. Arion Kurtaj, a prominent member, was transferred to a standard prison in July 2026, awaiting trial.
📊Key Facts
📅Complete Timeline15 events
First Major Attack on Brazilian Ministry of Health
Lapsus$ launched its Telegram channel and claimed responsibility for breaching the Brazilian Ministry of Health, exfiltrating and deleting data, and demanding a ransom.
Okta Systems Compromised
Lapsus$ gained access to the servers of identity and access management company Okta through a compromised account of a third-party customer support engineer. Okta later confirmed the breach.
Nvidia Breach and Extortion Attempt
Nvidia became aware of a breach into its systems by Lapsus$. The group claimed to have a terabyte of data and threatened to release it if Nvidia didn't open-source its device drivers.
Samsung Data Breach Confirmed
Lapsus$ posted a 195 GB torrent of internal data belonging to Samsung, including the source code of its Samsung Galaxy line of phones. Samsung confirmed the breach three days later.
Microsoft Confirms Hack
Microsoft confirmed a hack by Lapsus$, stating that the group had leaked source code for Bing, Cortana, and other projects stolen from Microsoft's internal Azure DevOps server.
Initial Arrests in the UK
The City of London Police announced the arrest of seven individuals, aged between 16 and 21, in connection with a police investigation into Lapsus$ activities. Arion Kurtaj was among those arrested.
Re-emergence and Attacks on Uber, Rockstar Games
Lapsus$ was believed to have re-emerged with a series of data breaches against large companies like Uber and Rockstar Games, followed by subsequent arrests by City of London Police and Brazilian police.
Brazilian Member Arrested
A Brazilian citizen believed to be a Lapsus$ member was arrested by police in Feira de Santana, Bahia, accused of attacks on the Brazil Ministry of Health and other cybercrimes.
UK Teen Hackers Convicted
A London jury found two British teenagers, including Arion Kurtaj, guilty of involvement in high-profile cyberattacks attributed to the Lapsus$ data extortion gang.
Arion Kurtaj Sentenced to Indefinite Hospital Order
Arion Kurtaj, a prominent Lapsus$ member, was sentenced to an indefinite hospital order by a UK judge due to his severe autism and continued intent to commit cybercrime.
Formation of a New Cybercrime Collective
A collective of cybercrime groups, including Lapsus$, Scattered Spider, and ShinyHunters, was forged, creating at least 16 new Telegram channels.
Jaguar Land Rover Attack (Lapsus$ Playbook)
Automaking giant Jaguar Land Rover suffered a major cyberattack that forced production lines offline, with the underlying logic of the attack resembling the Lapsus$ playbook.
GitHub Breach Claimed by Lapsus$-GROUP and TeamPCP
A Lapsus$-GROUP, in collaboration with TeamPCP, claimed responsibility for breaching GitHub's internal infrastructure and exfiltrating approximately 4,000 private repositories.
Arion Kurtaj Transferred to Standard Prison
Arion Kurtaj, a key Lapsus$ member previously sentenced to an indefinite hospital order, was transferred to a standard prison awaiting trial.
Lapsus$-Branded Actor Announces Return, Challenges FBI
A Lapsus$-branded actor announced a return to active operations via a PGP-signed statement, explicitly challenging the FBI and federal law enforcement, and initiated a countdown for a 'Chapter II' victim leak.
Follow this story
Get an email when this timeline gets a major update.
🔍Deep Dive Analysis
Lapsus$ emerged in late 2021, quickly establishing itself as a significant threat in the cybercrime landscape through a series of high-profile data breaches and extortion attempts. The group targeted a diverse range of organizations, including government agencies and major players in the technology, telecommunications, and gaming sectors. Their modus operandi primarily involved social engineering, SIM swapping, and the recruitment of insiders to gain initial access to target networks, often eschewing complex malware in favor of human vulnerabilities. Once access was established, Lapsus$ would exfiltrate sensitive data and then threaten to leak it publicly if their demands were not met, frequently utilizing Telegram channels for communication, public shaming, and even recruitment.
The group's motivations were multifaceted, encompassing financial gain, a desire for notoriety, and what some described as acting "for the lulz" – seeking thrills and recognition. This was evident in their public boasting and unconventional demands, such as compelling Nvidia to open-source its device drivers. The success of Lapsus$ underscored critical vulnerabilities in organizational security, particularly concerning human-centric attacks, weak identity management, and the need for robust internal communication and access control policies.
Key turning points in the Lapsus$ saga began in December 2021 with their first major attack on the Brazilian Health Ministry. The group gained international notoriety through a spree of attacks in early 2022 against tech giants like Nvidia, Samsung, Microsoft, Okta, and Vodafone. This led to initial arrests by the City of London Police in March 2022, with seven individuals apprehended. Despite these arrests, Lapsus$ re-emerged in September 2022, targeting companies such as Uber and Rockstar Games, which resulted in further arrests in both the UK and Brazil. A significant legal development occurred in August 2023 when a London jury convicted two British teenagers, including prominent member Arion Kurtaj, for their involvement in the hacks. In December 2023, Kurtaj, who is autistic and was deemed unfit to stand trial, was sentenced to an indefinite hospital order due to his persistent intent to commit cybercrime.
The consequences of Lapsus$'s activities were substantial, including significant financial losses for victim companies, estimated at nearly $10 million from attacks on Uber, Nvidia, and Rockstar Games alone. Beyond financial damages, companies suffered reputational harm and the exposure of sensitive data, prompting a re-evaluation of cybersecurity strategies to better address social engineering and insider threats. Several members faced legal repercussions, with some receiving custodial sentences or hospital orders.
As of September 12, 2026, the status of Lapsus$ remains complex. While key members like Arion Kurtaj have been convicted and are in secure facilities or awaiting trial (Kurtaj was transferred to a standard prison in July 2026), the "Lapsus$" brand continues to be associated with cybercrime. In May 2026, a Lapsus$-GROUP, in collaboration with TeamPCP, claimed a breach of GitHub, exfiltrating approximately 4,000 private repositories. More recently, on September 9, 2026, a Lapsus$-branded actor announced a return to active operations, explicitly challenging the FBI and federal law enforcement, and initiated a countdown for a "Chapter II" victim leak. It is important to note that "Lapsus$" branding might be used by multiple distinct actor clusters, including "Scattered Lapsus$ Hunters" (SLH), making definitive attribution challenging. SOCRadar listed Lapsus$ as "active" as of September 6, 2026, indicating ongoing monitoring of entities operating under this name.
What If...?
Explore alternate histories. What if Lapsus$ made different choices?