Lapsus is an unconventional hacking group known for its talent, ambition, and audacious approach, which has brought attention to online security vulnerabilities.
To avoid falling victim to virtual kidnappings, it is important to contact the alleged victim directly, use a secret password, avoid paying the ransom, and report the incident to the Internet Crime Complaint Center (IC3).
Deep dives
Overview of Lapsus: A Unique and Amateurish Hacking Group
Lapsus is an unconventional hacking group that operates with a loose and amateurish approach. Unlike state-sponsored hackers or well-organized criminal organizations, Lapsus stands out for its talent and ambition balanced with a certain level of amateurism. The group gained notoriety for its high-profile hacks and data extortion schemes, targeting major international companies such as Vodafone, Impresa, Micato Libra, and more. Lapsus is known for its public Telegram channel, where it allows approximately 45,000 people to vote on and select which company's data will be leaked next. The group's unique approach, combined with its audacity and sense of humor, has brought attention to the vulnerabilities in online security.
Lapsus' Rapid Rise in the Hacking Universe and Strategies
Lapsus emerged relatively recently, primarily focusing on Portuguese-language targets before rapidly expanding globally. In a short span of time, the group successfully hacked high-profile companies like Nvidia, Microsoft, Samsung, and Ubisoft, among others. Lapsus employs various tactics, such as password stealing malware, session hijacking, and social engineering, to gain access to sensitive data. Once inside a victim's system, Lapsus engages in data extortion, threatening to leak the stolen information if ransom demands are not met. Their hacks are marked by a lack of discretion and a tendency to include internet punchlines, such as directing a company's main page to a porn website or posting humorous tweets from compromised accounts. The group's primary objective is financial gain, and they make it clear that their actions are not politically motivated.
The Unraveling of Lapsus and the Arrests
In a surprising turn of events, the ringleader of Lapsus, known as White Doxbin, was arrested, along with several others associated with the group, by the City of London Police. The arrests came after White Doxbin's real identity was exposed, resulting in a public outcry and retaliation from the Doxbin community. However, it is unclear whether these arrests have effectively dismantled the group, as Lapsus continues to operate, releasing new data and targeting additional companies. The implications of the arrests and the group's persistence hint at a potential pre-existing hacking ring that welcomed the involvement of the arrested teenagers but remains active with other members.
Recommended Practices and Response to Virtual Kidnapping
While discussing virtual kidnappings in a previous episode, the hosts addressed best practices to avoid falling victim to such scams. First and foremost, it is essential to contact the alleged victim directly and confirm their safety. The Interpol General Secretariat's guidelines suggest using a secret password only known to the victim and avoiding paying the ransom demanded by the perpetrators. Additionally, reporting the incident to the Internet Crime Complaint Center (IC3) is crucial for tracking and investigating virtual kidnapping cases. This serves as a reminder to be cautious and prepared in the face of evolving cybercrimes.
The story of a very strange doxxing and an even stranger hacking gang.
If you like the show and want to make sure we can keep making it, please subscribe, and if you can visit https://www.patreon.com/hackedpodcast and show us some love.