-
Given these investigations, the Bloomberg website reported that these attacks would be led by a 16-year-old teenager.
-
The researchers are looking at a Brazilian teenager and believe there are at least seven members of the Lapsus$ group in total.
-
Bill Gates’ company Microsoft said the group is running a “large-scale social engineering and extortion campaign against multiple organizations.
The Lapsus$ group claimed credit for breaking into Microsoft systems and stealing up to 37GB of sensitive information. These not only attacked the technology company but also large technology companies such as Okta, Ubisoft and Nvidia, which according to current reports these attacks were carried out by a 16-year-old teenager who “lives in his mother’s house” in England.
According to data from Statista, in 2021, Microsoft’s worldwide revenue was approximately 168 billion US dollars, a record value that represents an increase of approximately 18% compared to 2020. A similar behavior was also manifested by its profit figure, which amounted to 44,200 million dollars; 13% more than in 2019.
On March 23 through an entry on his official blog, the company confirmed to have been compromised by the ‘DEV-0537’ group, better known as Lapsus$.
Given these investigations, the Bloomberg website reported that these attacks would be led by a 16-year-old teenager, and the researchers are also analyzing a Brazilian teenager. and they believe there are at least seven members of the Lapsus$ group in total.
The English teenager was believed to be so good that the researchers initially thought the activity they were observing was automated.
For its part, Microsoft, the company of Bill Gates, said that the group is running a “large-scale social engineering and extortion campaign against multiple organizations, and that its success is due to the fact that they have been able to recruit privileged information in the victim companies. to aid in their attacks.
As it is also pointed out that the members of Lapsus$ “would have been using personal information of the workers involved to make Zoom calls where they have mocked the employees and consultants who are trying to clean up their hack.”
Till the date, official authorities have not charged any suspects, But the investigators claim to have identified the two aforementioned teenagers “because the group suffers from poor operational security despite its great offensive capabilities.”
“The Microsoft Threat Intelligence Center (MSTIC) assesses that the goal of DEV-0537 is to gain elevated access through stolen credentials that enable data theft and destructive attacks directed at an organization, often resulting in extortion. The tactics and objectives indicate that it is a cybercriminal actor motivated by theft and destruction, ”indicates the technology company in the text shared on its blog.
Now read:
–