UPDATED 16:40 EST / MARCH 24 2022

SECURITY

London police arrest 7 people in connection with investigation into Lapsus$

London police have arrested seven people as part of an investigation into the Lapsus$ hacking group, the BBC reported today.

“Seven people 16 and 21 have been arrested in connection with an investigation into a hacking group,” the City of London Police told the BBC in a statement. “They have all been released under investigation. Our inquiries remain ongoing.”

The statement didn’t specify if the 16-year-old from Oxford, England, who is believed to be the mastermind behind Lapsus$ was among those arrested. Earlier this week, Bloomberg reported that four researchers who have been investigating Lapsus$ believe the teenager is behind the group. The researchers were investigating the group on behalf of companies that were breached by the hackers.

Prominent cybersecurity journalist Brian Krebs on Wednesday published a detailed report about the hacking activities of Lapsus$. The hacking group is said to have emerged last December after launching a cyberattack against Brazil’s Ministry of Health that disrupted several of the ministry’s internal systems. The bulk of the group’s victims are reportedly based in Latin America and Portugal.

In recent weeks, Lapsus$ made headlines by launching cyberattacks against several major tech firms. Microsoft Corp. and Okta Inc., which provides software that enterprises use to manage access to internal applications, are two of the latest companies to have been breached by Lapsus$. The hacking group earlier carried out cyberattacks against Nvidia, Samsung Electronics Co. Ltd, Vodafone Group Plc and other tech firms.

According to Krebs, Lapsus$ used multiple tactics to carry out cyberattacks. In some cases, the group bribed or tricked employees at a company into assisting with a cyberattack. In other cases, the group targeted employees at the company’s partners and suppliers. The data breach at Okta, for example, was carried out using the computer of a support engineer at Okta supplier Sitel Group. 

As part of its hacking activities, Lapsus$ reportedly targeted workers’ personal email accounts with the goal of using those accounts to gain access to corporate systems. The hacking group also used a technique known as SIM swapping to target employees’ mobile devices. Additionally, Lapsus$ reportedly deployed password-stealing malware and searched public code repositories for login credentials.

Earlier this week, Microsoft published an analysis of the hacking group’s cyberattacks along with guidelines for how organizations can enhance their security. Microsoft recommends that firms increase employee awareness of social engineering tactics used by hackers, as well review internal policies for processing password reset requests. 

Photo: Unsplash

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.