🏹 Lapsus$ — Ransomware
Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.
Classification
Ransomware
Leak-site victims
25
Ransomware.live
Associated IoCs
0
local intel
MITRE techniques
—
ATT&CK
Tracked
Yes
Ransomware.live
🔥 Leak-Site Victims (25)
| Victim | Country | Published | Domain |
|---|---|---|---|
| AYA BANK | MM | 2026-06-23T19:52:36.310851+00:00 | ayabank.com |
| INGKA GROUP | SE | 2026-06-13T10:02:51.787238+00:00 | ingka.com |
| VODAFONE | DE | 2026-05-29T22:52:45.767712+00:00 | vodafone.com |
| GITHUB INTERNAL | US | 2026-06-13T10:02:19.506378+00:00 | github.com |
| AXCERA TRADING | US | 2026-05-10T13:22:49.803177+00:00 | AXCERA.IO |
| MAPFRE ASSURANCE | ES | 2026-05-31T20:24:13.588968+00:00 | — |
| CHECKMARX | US | 2026-04-25T21:11:32.063949+00:00 | checkmarx.com |
| MERCOR | 2026-05-31T20:24:26.291695+00:00 | — | |
| VirtaHealth | US | 2026-04-05T06:14:34.809854+00:00 | virtahealth.com |
| ASTRAZENECA CORP | GB | 2026-04-05T06:14:38.685782+00:00 | astrazeneca.co.uk |
| AXCERA.IO | US | 2026-04-05T06:15:11.578046+00:00 | AXCERA.IO |
| Eiffage | FR | 2026-03-01T10:22:10.202152+00:00 | eiffage.com |
| OSAC Aero | FR | 2026-03-01T10:22:01.381949+00:00 | osac.aero |
| Salesfloor | CA | 2026-03-01T10:21:57.041090+00:00 | salesfloor.com |
| Adidas | DE | 2026-03-01T10:21:52.422688+00:00 | adidas.de |
| Loozap | CH | 2026-03-01T10:21:45.105034+00:00 | loozap.com |
| Lacoste | FR | 2026-03-01T10:21:40.200226+00:00 | lacoste.com |
| DreamUp | US | 2026-03-01T10:21:35.077307+00:00 | dreamup.org |
| Lille University | FR | 2026-03-01T10:21:29.049442+00:00 | univ-lille.fr |
| FR Ministry of Agriculture | FR | 2026-03-01T10:21:23.875406+00:00 | agriculture.gouv.fr |
| Eni Energy | IT | 2026-03-01T10:20:41.983780+00:00 | eni.com |
| Samsung Electronics | JP | 2022-03-07T00:00:00+00:00 | — |
| Nvidia | US | 2022-02-25T00:00:00+00:00 | — |
| Impresa | PT | 2022-01-01T00:00:00+00:00 | — |
| Brazilian Ministry of Health | BR | 2021-12-10T00:00:00+00:00 | — |
Source: Ransomware.live leak-site monitoring (cached, offline-safe).
🏹 Campaigns & malware
🧩 Advanced Capabilities
Live group profile & victims via Ransomware.live; ATT&CK technique hints are a static reference for well-known groups. All network calls cached & offline-safe.
Workstation · Copilot · AI Skills · Automation · Playbooks · Lookups · Docs · Reports
🤖 AI Copilot
⚡ AI Skills
🔍 Lookup & Enrich
📚 Docs & Reports
💡 Recommendations
- Explore related tools below
- Automate recurring work via cron