THREAT ACTOR
LAPSUS_
ActiveLAPSUS is a ransomware operator tracked through its public data-leak infrastructure. The group operates under the double-extortion model that defines the modern ransomware ecosystem: file encryption combined with the threat of stolen-data publication on a public leak site. It continues to post fresh victim claims as part of an ongoing extortion campaign.
For Ransomnews editorial coverage of LAPSUS, including incident write-ups, attribution notes and additional context, see the Threat Groups archive or run a site search.
Victims by year
- 2026 14
Leak site mirrors
6 mirrors tracked, 3 currently reachable. These are criminal-infrastructure URLs; links are deliberately not provided.
-
t.meTelegram: Contact @minsaudebr snapshot · 2026-09-23 05:28 -
lapsus.byLAPSUS$ | DATA REPOSITORY snapshot · 2026-06-08 09:07 -
vunk5dvj634b75xpsj64zvhmglv6xzajcanj4g2gxo34q6ot7il3axqd.onionDirectory listing for / snapshot · 2026-03-05 15:09 -
tw3wa46dm7avezfqdc3ei5ckxm5cvvz6fae73h3pbxjvrokbxmhkk7yd.onionDirectory listing for / snapshot · 2026-03-05 12:00 -
lapsus.bzLAPSUS$ snapshot · 2026-09-23 05:13 -
lapsus.ar.ioLAPSUS$ snapshot · 2026-09-23 05:06
Recent victims
The 50 most recent victims claimed by LAPSUS. Total in the index: 14.
| Date listed | Victim | Description |
|---|---|---|
| 2026-04-08 | ASTRAZENECA CORP | 2026-03-25 | Source Code, Employee DB, API Keys, MongoDB/MySQL Creds |
| 2026-04-08 | VirtaHealth.com | 2026-03-29 | Healthcare research |
| 2026-04-08 | FR MINISTRY AGRICULTURE | 2025-12-28 | Government Infrastructure |
| 2026-04-08 | AXCERA.IO | 2026-03-22 | Source Code + Infrastructure Configs |
| 2026-03-04 | OSAC AERO | |
| 2026-03-04 | FR MINISTRY AGRI | |
| 2026-03-04 | LOOZAP | |
| 2026-03-04 | DREAMUP | |
| 2026-03-04 | SALESFLOOR | |
| 2026-03-04 | EIFFAGE | |
| 2026-03-04 | ADIDAS EXTRANET | |
| 2026-03-04 | LACOSTE | |
| 2026-03-04 | UNIV LILLE | |
| 2026-03-04 | ENI ENERGY |
CONFIRMED ATTACKS
Lapsus$ confirmed attacks: 12 verified incidents
Ransomnews has verified 12 Lapsus$ incidents against named organisations, each corroborated by a public source such as a breach notification, regulatory filing or press report. The confirmed record runs from December 2021 to March 2022. United States accounts for 3 of them (25%), with victims recorded in 7 countries in total. The most affected sector is technology, at 4 confirmed victims.
Confirmed victims by year
Most affected sectors
Most affected countries
Verified Lapsus$ incidents
| Date | Organisation | Sector | Location | Records | Ransom paid | Source |
|---|---|---|---|---|---|---|
| March 2022 | T-Mobile | Utilities | Washington, United States | — | Unknown | Source |
| March 2022 | Globant | Technology | Buenos Aires, Argentina | — | Unknown | Source |
| March 2022 | Ubisoft | Technology | Montreuil, France | — | Unknown | Source |
| March 2022 | Vodafone | Utilities | Newbury, United Kingdom | — | Unknown | Source |
| March 2022 | Okta | Technology | California, United States | — | Unknown | Source |
| March 2022 | Samsung Electronics Co. Ltd | Manufacturing | Suwon-Si, South Korea | — | Unknown | Source |
| March 2022 | Mercado Libre | Retail | Buenos Aires, Argentina | — | Unknown | Source |
| February 2022 | Nvidia | Technology | California, United States | — | Unknown | Source |
| January 2022 | Impresa Sociedade Gestora de Participações Sociais SA | Other | Lisbon, Portugal | — | Unknown | Source |
| December 2021 | Ministério da Saúde | Government | Rio de Janeiro, Brazil | — | Unknown | Source |
| December 2021 | Embratel | Utilities | Rio de Janeiro, Brazil | — | Unknown | Source |
| December 2021 | Claro Brasil | Utilities | São Paulo, Brazil | — | Unknown | Source |
Claimed vs confirmed. The figures above the fold on this page come from Lapsus$'s own leak-site postings and reflect what the operation claims. The table here is a separate evidence class: incidents Ransomnews verified against a public source. Confirmed counts are lower than claimed counts by design: most victims never disclose, and some leak-site listings are recycled, exaggerated or fabricated. Records and ransom figures are shown only where a named source disclosed them. See the full ransomware statistics or the Ransomtracker dataset.