Entra ID & IdentityIncident TeardownsRetrospectives

Lapsus$ (Mar 2022): Teenagers, MFA Fatigue and Breaches at Okta and Microsoft

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2022, written in 2026 with the benefit of hindsight.

Between late 2021 and March 2022, a loosely organized group calling itself Lapsus$ breached some of the world's largest technology companies, including Nvidia, Samsung, Microsoft and Okta (through a third-party support provider). Several members turned out to be teenagers.

How they operated

Lapsus$ didn't rely on sophisticated malware. Microsoft (which tracked them as DEV-0537) and others described their techniques:

  • Buying credentials and session tokens from criminal markets and infostealer logs.
  • Paying insiders — employees at target companies, telecoms or support providers — for access.
  • MFA fatigue: repeatedly sending push notifications until a user accepted, sometimes combined with calling the user and posing as IT.
  • SIM swapping to intercept SMS codes.
  • Searching internal collaboration tools (Slack, Teams, Confluence, Jira) for credentials and documentation.
  • Targeting help desks to reset passwords and MFA.

Once inside, they stole source code and data, and publicized breaches on Telegram for notoriety.

The Okta case

Okta disclosed that a support engineer at a subprocessor (Sitel) had been compromised, and that attackers had accessed a limited number of customer tenants' support information. Okta's initially slow and incomplete communication drew criticism.

Why it mattered

Lapsus$ showed that large, well-resourced companies could be breached through identity and social engineering alone. The US Cyber Safety Review Board later reviewed Lapsus$ and recommended phishing-resistant MFA and stronger help desk controls.

Lessons in hindsight

  • Number matching and phishing-resistant MFA defeat MFA fatigue.
  • Help desk identity verification must be robust.
  • Insider threat includes paid recruitment.
  • Secrets in collaboration tools are a goldmine for attackers.
lapsus$ hackLapsus$2022

More on this story