Lapsus$: How Teenagers Beat Microsoft, NVIDIA and Okta

Infographic 2026

Find Threat Talks on

A group of teenagers breached Microsoft, NVIDIA and Okta.

They used no zero-days, no custom malware, and no command and control infrastructure. They bought leaked credentials on the dark web, or called the service desk and asked for a password reset. Most of them are now in jail. The techniques they used are still available to anyone willing to pick up a phone.

Lieuwe Jan Koning, Co-founder & CTO at ON2IT, is joined by Yuri Wit, Threat Researcher at ON2IT, and Rob Maas, Field CTO at ON2IT, to walk the Lapsus$ playbook end to end. Yuri takes the attacker seat: how initial access was bought or talked into existence, why push-approval MFA folds under spam, and what the group did once they were inside. Rob takes the defender seat: what your help desk should demand before it resets anything, which second factor belongs on which Protect Surface, and why over-permissioned accounts are the reason a single stolen login becomes a breach. Rob’s verdict on whether this is still a risk: avoidable, but only to the extent you have actually done the work.

What you’ll learn

  • Initial access is bought, not built. Leaked credentials and a convincing help desk call replace every exploit in the toolkit.
  • Not all MFA is equal. Tap-to-approve prompts fail to spam and SMS fails to SIM swapping, while hardware keys and number-matching prompts make the user do real work.
  • Escalation is the real bottleneck. Attackers get in easily, so the control that matters is how hard it is to become an administrator, and AI agents are inheriting the same over-permissioning problem.

 

Your cybersecurity experts

Rob Maas

Rob Maas

Field CTO
ON2IT

Yuriwit

Yuri Wit

Researcher
ON2IT

Episode details

The Lapsus$ story is usually told as a curiosity: teenagers, brand-name victims, no sophistication. Yuri Wit reframes it as something less comfortable. The group skipped the entire attacker tech stack because they did not need it. Specialized malware, command and control, brand recognition: all optional, once the human layer is reachable by phone. That makes Lapsus$ a control test rather than a threat profile, which is why Lieuwe Jan closes the episode by telling companies to try to get in themselves.

Rob Maas pushes back on the idea that MFA settles the question. Multi-factor is a category, not a control. A push prompt satisfies the “something you have” definition and still collapses when an attacker spams login requests until the user taps approve out of irritation, which Lieuwe Jan compares to answering a call you never meant to pick up. SMS codes are undone by SIM swapping. A TOTP code stored in the same password manager as the password is not a second factor at all, because one stolen master password takes both. The decision Rob keeps returning to is a Zero Trust one: define the Protect Surface first, then pick the factor that matches the data inside it. Public content can live with a push prompt. Sensitive data should not.

The most actionable section is about privilege, and it is deliberately unglamorous. Rob’s position is that least privilege is an administrative problem, not a technical one. Know your systems, know your roles, know which role each user holds, and revalidate it when people move departments so old permissions do not accumulate. It takes time. It is not difficult. Where the data justifies it, a privileged access management system lets users raise permissions temporarily, gated by an extra factor or a second human in the loop. That is the hurdle Lapsus$ did not encounter, and the reason initial access turned into exfiltration and extortion.

The AI section is where the episode points forward. The same tooling that already sits on a Windows or Mac endpoint can read the whole directory tree, so a standard user can enumerate every account and group. That is reconnaissance handed to the attacker for free, and it is also, turned around, the fastest audit your team has ever run: ask which users are over-permissioned and get a list. The catch is what comes next. Agentic AI needs permissions to act, those permissions land in service accounts, and service accounts are being over-provisioned exactly the way human accounts were. Rob’s answer is just-in-time permissions. The lesson from Lapsus$ is that if you do not build that hurdle now, the next group will not need to be clever either.

Infographic 2026

Get your Hacker T-shirt

Join the treasure hunt!

Find the code within this episode and receive your own hacker t-shirt for free.

5 + 8 =

Christmas Hacker