• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Android

Lapsus$’s latest confirmed cybercrime victims are Microsoft and authentication services provider Okta

March 23, 2022
Share on FacebookShare on Twitter

The hacking group is on a roll


Image with lock representing cybersecurity

Image by Darwin Laganzon from Pixabay 

Read update
  • Microsoft acknowledges hack…

Cybercrime is the bane of the internet. Time and time again we’ve seen companies fall prey to hackers. T-Mobile was attacked last year, while Nvidia and Samsung have been under threat in recent times. Some of these breaches result in little to no data exposure, while others end in potentially devastating data losses. The latter might be the case in the latest compromises of Microsoft and popular authentication services provider Okta Inc.

As reported by Bleeping Computer, the Lapsus$ hacking group appears to have obtained data from Microsoft’s servers, extracting parts of the source code for Bing, Cortana, and further internal projects on Sunday. It looks like only parts of the source code have been leaked, with the hacking group posting a torrent containing 9GB worth of data on Monday. Bleeping Computer supposedly has sources telling it that the group has a total of 37GB of Microsoft data in its possession, so there might be more to come. Microsoft is currently looking into these claims.

ANDROIDPOLICE VIDEO OF THE DAY

Meanwhile, Okta is investigating a potential breach after hacking group Lapsus$ posted screenshots on Telegram supposedly showing the company’s internal company environment, per Reuters. The pictures, as seen in a tweet by independent security researcher Bill Demirkapi, suggest that Lapsus$ may have gotten access to a host of interfaces, including Okta’s Slack channels, company VPNs, and the @Cloudflare tenant, possibly with the ability to reset employee passwords.

Lapsus$ says its focus is only on Okta customers, but the unnerving part of the report is that the group claims to have had access to Okta’s systems for two months, which correlates with the date in the screenshots (consistently appearing as January 21st, 2022). The situation is even more dire when you realize that Okta services tens of thousands of customers around the world, including well-known government agencies, universities, and companies like T-Mobile, Peloton, Sonos, and the FCC.

Despite the ruckus, Okta has downplayed the incident in a statement to The Verge. Official Chris Hollis said the company detected an attempt to compromise a third-party customer support engineer working for one of its subprocessors in late January. However, it was investigated and contained and there’s been no evidence of an ongoing attack since then. The report suggests that the screenshots could be connected to this January incident.

Lapsus$ is a household name in the world of cybercrime. It broke into Nvidia’s internal network last month and stole a lot of sensitive data — including hashed login credentials and critical trade secrets behind the company’s chips — which it has threatened to reveal. The cyber gang also targeted Samsung earlier this month, making away with vital information, such as algorithms for biometric unlocking operations and company source codes.

UPDATE: 2022/03/23 17:23 EST BY STEVE HUFF

Microsoft acknowledges hack…

In a note published Tuesday, Microsoft said that while Lapsus$ “made public claims that they had gained access to Microsoft and exfiltrated portions of source code,” the company’s security team “found a single account had been compromised, granting limited access.” The same note stated that no customer data was involved. So the intrusion definitely happened, but Microsoft security was able to get to the problem before the hackers were able to go any further.



A waving Android statue

Google’s Android statues are being repaired and will return soon

Read Next


About The Author

Haroun Adamu
(146 Articles Published)

Haroun became an Android enthusiast in 2014 and has been avidly following the industry since then. Currently a medical student, he doubles as an SEO copywriter for small businesses. When not scouring the net for the latest tech news, you’ll either find him nose-deep into his textbooks or working on Homeripped, his fitness website.

More
From Haroun Adamu

Next Post

Renault suspends Moscow plant, adjusts 2022 outlook

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Lego just dropped a new Mario Kart set — pre-order the Luigi & Mach 8 on Mario Day
  • NYT Strands hints and answers for Wednesday, March 11 (game #738)
  • Poker Night at the Inventory Review – Alternative Magazine Online
  • Meta has bought Moltbook, the AI agent ‘social network’
  • Ikea’s Matter-compatible smart bulbs are finally available in the US

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously