💻 techgroup6 views4 min read

What Happened to Lapsus$?

Lapsus$ is an international extortion-focused black-hat hacker group that gained notoriety in late 2021 for a series of high-profile cyberattacks against major tech companies like Microsoft, Nvidia, Samsung, and Okta. The group, largely composed of teenagers, primarily uses social engineering, SIM swapping, and insider recruitment for data exfiltration and extortion. While several key members have been arrested and convicted in the UK and Brazil, including leader Arion Kurtaj who received an indefinite hospital order in December 2023, a Lapsus$-branded actor announced a return to active operations in September 2026, claiming to challenge federal law enforcement.

Share:
⚡

Quick Answer

Lapsus$ is a notorious cybercrime group known for its data extortion tactics against major corporations and government entities. Although several key members, including leader Arion Kurtaj, were arrested and convicted in 2022 and 2023, the group's activities have seen a complex evolution. In September 2026, a Lapsus$-branded actor declared a return to operations, signaling a potential resurgence or continuation under a new guise, explicitly challenging federal law enforcement. Arion Kurtaj, a prominent member, was transferred to a standard prison in July 2026, awaiting trial.

📊Key Facts

Estimated members (March 2022)
7
Wikipedia
Estimated cost to Uber, Nvidia, Rockstar Games
Nearly $10 million
Security Affairs
Revolut customers affected by Arion Kurtaj's solo attacks
~5,000
Science of Security Virtual Organization
Okta customers potentially affected (January 2022 breach)
2.5% (366 businesses)
Okta, Keepnet Labs
GitHub repositories claimed in May 2026 breach
~4,000
FalconFeeds.io

📅Complete Timeline15 events

1
December 2021Major

First Major Attack on Brazilian Ministry of Health

Lapsus$ launched its Telegram channel and claimed responsibility for breaching the Brazilian Ministry of Health, exfiltrating and deleting data, and demanding a ransom.

2
January 2022Critical

Okta Systems Compromised

Lapsus$ gained access to the servers of identity and access management company Okta through a compromised account of a third-party customer support engineer. Okta later confirmed the breach.

3
February 2022Critical

Nvidia Breach and Extortion Attempt

Nvidia became aware of a breach into its systems by Lapsus$. The group claimed to have a terabyte of data and threatened to release it if Nvidia didn't open-source its device drivers.

4
March 2022Major

Samsung Data Breach Confirmed

Lapsus$ posted a 195 GB torrent of internal data belonging to Samsung, including the source code of its Samsung Galaxy line of phones. Samsung confirmed the breach three days later.

5
March 2022Critical

Microsoft Confirms Hack

Microsoft confirmed a hack by Lapsus$, stating that the group had leaked source code for Bing, Cortana, and other projects stolen from Microsoft's internal Azure DevOps server.

6
March 2022Critical

Initial Arrests in the UK

The City of London Police announced the arrest of seven individuals, aged between 16 and 21, in connection with a police investigation into Lapsus$ activities. Arion Kurtaj was among those arrested.

7
September 2022Critical

Re-emergence and Attacks on Uber, Rockstar Games

Lapsus$ was believed to have re-emerged with a series of data breaches against large companies like Uber and Rockstar Games, followed by subsequent arrests by City of London Police and Brazilian police.

8
October 2022Major

Brazilian Member Arrested

A Brazilian citizen believed to be a Lapsus$ member was arrested by police in Feira de Santana, Bahia, accused of attacks on the Brazil Ministry of Health and other cybercrimes.

9
August 2023Critical

UK Teen Hackers Convicted

A London jury found two British teenagers, including Arion Kurtaj, guilty of involvement in high-profile cyberattacks attributed to the Lapsus$ data extortion gang.

10
December 2023Critical

Arion Kurtaj Sentenced to Indefinite Hospital Order

Arion Kurtaj, a prominent Lapsus$ member, was sentenced to an indefinite hospital order by a UK judge due to his severe autism and continued intent to commit cybercrime.

11
August 2025Major

Formation of a New Cybercrime Collective

A collective of cybercrime groups, including Lapsus$, Scattered Spider, and ShinyHunters, was forged, creating at least 16 new Telegram channels.

12
September 2025Major

Jaguar Land Rover Attack (Lapsus$ Playbook)

Automaking giant Jaguar Land Rover suffered a major cyberattack that forced production lines offline, with the underlying logic of the attack resembling the Lapsus$ playbook.

13
May 2026Major

GitHub Breach Claimed by Lapsus$-GROUP and TeamPCP

A Lapsus$-GROUP, in collaboration with TeamPCP, claimed responsibility for breaching GitHub's internal infrastructure and exfiltrating approximately 4,000 private repositories.

14
July 2026Major

Arion Kurtaj Transferred to Standard Prison

Arion Kurtaj, a key Lapsus$ member previously sentenced to an indefinite hospital order, was transferred to a standard prison awaiting trial.

15
September 2026Critical

Lapsus$-Branded Actor Announces Return, Challenges FBI

A Lapsus$-branded actor announced a return to active operations via a PGP-signed statement, explicitly challenging the FBI and federal law enforcement, and initiated a countdown for a 'Chapter II' victim leak.

Follow this story

Get an email when this timeline gets a major update.

🔍Deep Dive Analysis

Lapsus$ emerged in late 2021, quickly establishing itself as a significant threat in the cybercrime landscape through a series of high-profile data breaches and extortion attempts. The group targeted a diverse range of organizations, including government agencies and major players in the technology, telecommunications, and gaming sectors. Their modus operandi primarily involved social engineering, SIM swapping, and the recruitment of insiders to gain initial access to target networks, often eschewing complex malware in favor of human vulnerabilities. Once access was established, Lapsus$ would exfiltrate sensitive data and then threaten to leak it publicly if their demands were not met, frequently utilizing Telegram channels for communication, public shaming, and even recruitment.

The group's motivations were multifaceted, encompassing financial gain, a desire for notoriety, and what some described as acting "for the lulz" – seeking thrills and recognition. This was evident in their public boasting and unconventional demands, such as compelling Nvidia to open-source its device drivers. The success of Lapsus$ underscored critical vulnerabilities in organizational security, particularly concerning human-centric attacks, weak identity management, and the need for robust internal communication and access control policies.

Key turning points in the Lapsus$ saga began in December 2021 with their first major attack on the Brazilian Health Ministry. The group gained international notoriety through a spree of attacks in early 2022 against tech giants like Nvidia, Samsung, Microsoft, Okta, and Vodafone. This led to initial arrests by the City of London Police in March 2022, with seven individuals apprehended. Despite these arrests, Lapsus$ re-emerged in September 2022, targeting companies such as Uber and Rockstar Games, which resulted in further arrests in both the UK and Brazil. A significant legal development occurred in August 2023 when a London jury convicted two British teenagers, including prominent member Arion Kurtaj, for their involvement in the hacks. In December 2023, Kurtaj, who is autistic and was deemed unfit to stand trial, was sentenced to an indefinite hospital order due to his persistent intent to commit cybercrime.

The consequences of Lapsus$'s activities were substantial, including significant financial losses for victim companies, estimated at nearly $10 million from attacks on Uber, Nvidia, and Rockstar Games alone. Beyond financial damages, companies suffered reputational harm and the exposure of sensitive data, prompting a re-evaluation of cybersecurity strategies to better address social engineering and insider threats. Several members faced legal repercussions, with some receiving custodial sentences or hospital orders.

As of September 12, 2026, the status of Lapsus$ remains complex. While key members like Arion Kurtaj have been convicted and are in secure facilities or awaiting trial (Kurtaj was transferred to a standard prison in July 2026), the "Lapsus$" brand continues to be associated with cybercrime. In May 2026, a Lapsus$-GROUP, in collaboration with TeamPCP, claimed a breach of GitHub, exfiltrating approximately 4,000 private repositories. More recently, on September 9, 2026, a Lapsus$-branded actor announced a return to active operations, explicitly challenging the FBI and federal law enforcement, and initiated a countdown for a "Chapter II" victim leak. It is important to note that "Lapsus$" branding might be used by multiple distinct actor clusters, including "Scattered Lapsus$ Hunters" (SLH), making definitive attribution challenging. SOCRadar listed Lapsus$ as "active" as of September 6, 2026, indicating ongoing monitoring of entities operating under this name.

What If...?

Explore alternate histories. What if Lapsus$ made different choices?

Explore Scenarios
Building relationship map...

❓People Also Ask

Who is Lapsus$?
Lapsus$ is an international cybercrime group known for data extortion, primarily targeting large technology companies and government agencies. They gained notoriety for their high-profile breaches and unconventional tactics.
What were Lapsus$'s main hacking methods?
Lapsus$ primarily used social engineering, SIM swapping, and bribing or recruiting insiders to gain initial access to target networks, rather than relying on complex malware. They often exploited human vulnerabilities and weak identity management.
Which major companies did Lapsus$ hack?
Lapsus$ successfully breached and exfiltrated data from high-profile companies including Microsoft, Nvidia, Samsung, Okta, Uber, Rockstar Games, Globant, and the Brazilian Ministry of Health.
What happened to the members of Lapsus$?
Several members of Lapsus$ have been arrested and convicted in the UK and Brazil. Notably, Arion Kurtaj, a key member, was sentenced to an indefinite hospital order in December 2023 and transferred to a standard prison in July 2026.
Is Lapsus$ still active in 2026?
While key members were apprehended, a Lapsus$-branded actor announced a return to active operations in September 2026, explicitly challenging federal law enforcement and initiating a countdown for a new data leak. SOCRadar also listed Lapsus$ as 'active' as of September 6, 2026.