Actor Profile

🏹 Lapsus$ — Ransomware

Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.

Classification

Ransomware

Leak-site victims

25
Ransomware.live

Associated IoCs

0
local intel

MITRE techniques

ATT&CK

Tracked

Yes
Ransomware.live

🔥 Leak-Site Victims (25)

VictimCountryPublishedDomain
AYA BANK MM 2026-06-23T19:52:36.310851+00:00 ayabank.com
INGKA GROUP SE 2026-06-13T10:02:51.787238+00:00 ingka.com
VODAFONE DE 2026-05-29T22:52:45.767712+00:00 vodafone.com
GITHUB INTERNAL US 2026-06-13T10:02:19.506378+00:00 github.com
AXCERA TRADING US 2026-05-10T13:22:49.803177+00:00 AXCERA.IO
MAPFRE ASSURANCE ES 2026-05-31T20:24:13.588968+00:00
CHECKMARX US 2026-04-25T21:11:32.063949+00:00 checkmarx.com
MERCOR 2026-05-31T20:24:26.291695+00:00
VirtaHealth US 2026-04-05T06:14:34.809854+00:00 virtahealth.com
ASTRAZENECA CORP GB 2026-04-05T06:14:38.685782+00:00 astrazeneca.co.uk
AXCERA.IO US 2026-04-05T06:15:11.578046+00:00 AXCERA.IO
Eiffage FR 2026-03-01T10:22:10.202152+00:00 eiffage.com
OSAC Aero FR 2026-03-01T10:22:01.381949+00:00 osac.aero
Salesfloor CA 2026-03-01T10:21:57.041090+00:00 salesfloor.com
Adidas DE 2026-03-01T10:21:52.422688+00:00 adidas.de
Loozap CH 2026-03-01T10:21:45.105034+00:00 loozap.com
Lacoste FR 2026-03-01T10:21:40.200226+00:00 lacoste.com
DreamUp US 2026-03-01T10:21:35.077307+00:00 dreamup.org
Lille University FR 2026-03-01T10:21:29.049442+00:00 univ-lille.fr
FR Ministry of Agriculture FR 2026-03-01T10:21:23.875406+00:00 agriculture.gouv.fr
Eni Energy IT 2026-03-01T10:20:41.983780+00:00 eni.com
Samsung Electronics JP 2022-03-07T00:00:00+00:00
Nvidia US 2022-02-25T00:00:00+00:00
Impresa PT 2022-01-01T00:00:00+00:00
Brazilian Ministry of Health BR 2021-12-10T00:00:00+00:00

Source: Ransomware.live leak-site monitoring (cached, offline-safe).

🧭 Intelligence disciplines

CYBINT →OSINT →HUMINT →GEOINT →
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports

🤖 AI Copilot

🔍 Lookup & Enrich

💡 Recommendations

⚙ Automation

Cron: 0 * * * * php /home/zaptf0zdggll/public_html/threats/cron.php