LAPSUS$

A handful of teenagers with a Telegram channel and almost no interest in money walked straight through Nvidia, Samsung, Microsoft, Okta, Uber and Rockstar Games — the last one leaking ninety clips of the most anticipated video game on earth. They didn't use zero-days. They SIM-swapped phone numbers, bought their way in through bored insiders, and spammed employees with login prompts until someone tapped "approve." Then they posted the loot to a channel with forty thousand followers and asked the audience what to hit next. It was LulzSec's "for the lulz" spirit stripped of the manifesto: chaos and clout over cash or cause. The best-defended companies in the world lost to kids doing the dumbest possible thing well.

We decided to help mining and gaming community, we want nvidia to push an update for all 30 series firmware that remove every LHR limitations otherwise we will leak hw folder.

Lapsus$, public extortion demand posted to its Telegram channel after the Nvidia breach, February 2022 — as reproduced verbatim in contemporaneous reporting

WHO
Lapsus$ (tracked by Microsoft as DEV-0537) — a loosely-organised extortion crew, members mostly teenagers in the UK and Brazil, active ~2021–2022 FACT
SCENE
The clout-teen descendant of LulzSec's "for the lulz" ethos — spectacle over money, no cause bolted on. Same skill-versus-noise argument the scene has had since TeaMp0isoN called LulzSec script kiddies (see Crew Rivalries)
THE DRAMA
Breached Nvidia, Samsung, Microsoft, Okta, Uber and Rockstar Games in a single explosive run — leaking GTA VI footage — using SIM-swaps, bribed insiders and MFA-fatigue, then taunting each victim on Telegram
RECORD
Seven arrested in the UK (March 2022). At a 2023 London trial a jury found Arion Kurtaj had carried out the hacks; he was assessed unfit to stand trial and given an indefinite hospital order. The US Cyber Safety Review Board published a full review of the group FACT
STATUS
DISBANDED — the channel went quiet after the arrests. The template for the low-tech, high-audacity teen extortion crew that followed

This file is not an accusation; the accusations were the state's, and a court found most of them made out. It is a record of how little it took — not a foreign intelligence service, not a novel exploit, but stolen phone numbers, a few bribed employees, and a login prompt spammed until someone caved — to humiliate Nvidia, Samsung, Microsoft and Okta in the same season. The through-line is the gap between the theatre — the Telegram channel, the audience polls, the ransom notes written like a group chat — and the paperwork, which shows real intrusions, real victims, a government review concluding the industry's lynchpin defences simply failed, and a defendant the court handled as a matter of psychiatric care rather than a criminal to punish.

the drama timeline

ACT I — THE CLOUT KIDS ASSEMBLE (2021–early 2022)

A crew forms out of the online underground, sets up shop on Telegram, and settles on a method so unglamorous the industry never took it seriously — until it worked on everyone.

  1. 2021–22

    A method, not a manifesto

    Lapsus$ builds a repertoire out of the cheapest tricks available: SIM-swapping a target's phone number to intercept its texts, paying insiders to hand over VPN or Okta access, and MFA-fatigue — hammering an employee with login-approval prompts until they tap "yes" to make it stop. No zero-days, no ransomware. Microsoft tracks the crew as DEV-0537 and notes it runs on "pure extortion and destruction" without deploying malware payloads.

  2. 2021–22

    The channel is the point

    Everything happens in public. The group runs a Telegram channel that swells past forty thousand followers, announces breaches, dumps data, and — at the peak — recruits insiders and polls the audience on what to hit next. The CSRB would later single this out: a crew that used its public channel "to discuss its operations, targets, and successes." It is LulzSec's spectacle without the politics.

ACT II — THE BIG-TECH SPREE (Feb–Mar 2022)

In a matter of weeks the crew hits four of the most valuable technology companies on the planet, one after another, and posts the receipts each time.

  1. FEB 2022

    Nvidia — and a demand about mining cards

    Lapsus$ breaches Nvidia, claims roughly a terabyte of data including employee credentials and hardware schematics, and posts a Telegram ransom note demanding Nvidia strip the anti-cryptomining "LHR" limiter from its GPUs — later escalating to a demand that Nvidia open-source its drivers "or else." Nvidia confirms the intrusion and calls it a wake-up call. The ransom, tellingly, is not for money.

  2. MAR 4, 2022

    Samsung — 190GB out the door

    Days later the crew dumps roughly 190GB of Samsung data, including source code for the trusted applets that run in the Galaxy phones' secure TrustZone and for biometric-unlock routines. Samsung confirms a breach of internal company data. The pattern is set: breach, brag, leak.

  3. MAR 20–21, 2022

    Microsoft — Bing, Maps, Cortana

    Lapsus$ posts screenshots, then a 37GB torrent it says contains source code for Bing, Bing Maps and Cortana. Microsoft confirms a single employee account was compromised, granting "limited access," and says no customer data was taken. A single account was all it took to reach the source tree.

  4. MAR 22, 2022

    Okta — through the back door of a contractor

    The crew posts screenshots of internal Okta systems, taken via a compromised support contractor months earlier. Okta — whose entire business is verifying who is logging in — is forced to concede the incident, and its slow, minimising response becomes a case study in how not to disclose a breach. That failure is its own file: this page is the crew; the company's conduct lives at troll.fan — Okta.

ACT III — ARRESTS, THEN A RELAPSE FROM A HOTEL ROOM (Mar–Sep 2022)

British police move in and make arrests within days. It does not stop. The biggest hit of all comes after — carried out, the court would hear, on an Amazon Fire Stick from a hotel room.

  1. MAR 24, 2022

    The knock comes fast

    City of London Police announce the arrest of seven people aged 16 to 21 in connection with the Lapsus$ investigation. Among those later charged is Arion Kurtaj, then a teenager from Oxford. The crew's operational security — loud, public, on Telegram — had made it findable.

  2. SEP 15, 2022

    Uber

    A Lapsus$-linked intruder breaches Uber via an MFA-fatigue attack on a contractor, then announces the breach inside Uber's own internal Slack. It is the same trick that worked on Microsoft — the human, not the firewall, is the way in.

  3. SEP 18, 2022

    Rockstar — the GTA VI leak

    The crew breaches Rockstar Games and dumps roughly 90 clips of unreleased Grand Theft Auto VI footage — one of the largest leaks in game history. The court would later hear it was done while a defendant was on bail for the earlier hacks, staying in a hotel under police protection, using an Amazon Fire Stick, a hotel TV and a phone. Rockstar's parent later put the cost of the incident at around $5 million.

ACT IV — THE TRIAL, AND WHAT CAME AFTER (2023–2026)

The case that reaches a London courtroom is unusual: the central defendant is found unfit to stand trial, so the jury is asked only whether he did the acts, not whether he is guilty of them.

  1. AUG 2023

    A jury finds the acts were done

    After a weeks-long trial at Southwark Crown Court, a jury finds that Arion Kurtaj carried out the offences attributed to him — computer intrusion, blackmail and fraud among them. Because psychiatrists assessed him unfit to stand trial — the court heard he is autistic — the jury was asked to decide only whether he committed the acts, not whether he was criminally culpable. A second defendant, a minor who was not publicly named, was convicted on associated counts.

  2. DEC 21, 2023

    An indefinite hospital order

    A judge at Southwark Crown Court orders that Kurtaj be detained indefinitely in a secure hospital, to remain until clinicians judge he is no longer a danger. The court's stated reason is the risk of reoffending — he had, after all, continued hacking while on bail. It is a public-safety disposition, handled as a matter of psychiatric care rather than punishment.

  3. JUL 2026

    Out of the hospital, into a retrial

    By reporting in July 2026, Kurtaj has been moved from the secure hospital to an ordinary prison and is awaiting a retrial listed for November 2026. The case that began with a Telegram channel and a Fire Stick is, four years on, still open.

both sides, on the record

The "real crime, real victims" case: these were not victimless pranks. Source code for Samsung's secure enclave and Microsoft's search stack was stolen and dumped; Okta's customers were exposed through a contractor; Rockstar's unfinished game leaked to the world at a cost its parent put near $5 million. The crew extorted its targets and taunted them while doing it. A UK jury found the acts were carried out, and people were arrested and prosecuted on two continents' worth of harm.

Loud is not the same as clever—but it still worked: rivals dismissed the scene's spectacle crews as script kiddies, and Lapsus$ used no exotic technique. That did not make the damage less real. Bragging on Telegram is what got them caught; it is not what makes the intrusions lawful.

The defences failed, not just the kids succeeded: the US Cyber Safety Review Board — a government body, not the crew's fan club — concluded Lapsus$ beat "industry-standard security tools that are a lynchpin of many corporate cybersecurity programs" using simple techniques, and found deficiencies in how firms vet vendors, how carriers stop SIM-swapping, and how companies authenticate users. Teenagers with stolen phone numbers should not be able to walk through Nvidia, Microsoft and Okta. That they could is an indictment of the defenders.

The central defendant was handled as a patient, not a mastermind: the court found Arion Kurtaj unfit to stand trial and detained him for treatment and public safety rather than convicting and punishing him. He was a juvenile at the time of the earliest offences. Those are the court's findings, stated as such — the archive draws no conclusion about his character from them.

YOU DECIDE

The intrusions and the extortion were real, and a court found Kurtaj carried them out. But the story a crew of teenagers wrote — SIM-swaps, bribed insiders, a login prompt spammed until someone caved — is less a tale of criminal genius than of how little stood in their way. The same season that humiliated Nvidia, Samsung, Microsoft and Okta produced a government report saying the industry's lynchpin controls simply did not hold. Were they dangerous prodigies or the loudest symptom of everyone else's bad security? The archive keeps the victim list and the CSRB's finding, and lets you weigh them.

The archive does not deify. It keeps the ransom note — and the Cyber Safety Review Board's homework.

evidence locker

PRIMARY / REFERENCE

  1. Wikipedia — Lapsus$ ATTRIBUTED — dated timeline and roster: the DEV-0537 designation, the Telegram channel, the SIM-swap / insider / MFA-fatigue methods, the Nvidia, Samsung, Microsoft, Okta, Uber and Rockstar breaches, the March 2022 arrests, the 2023 trial and unfit-to-plead finding, and the July 2026 transfer to prison. en.wikipedia.org/wiki/Lapsus$
  2. DHS Cyber Safety Review Board — "Review of the Attacks Associated with Lapsus$ and Related Threat Groups" FACT — the US government's full review: simple techniques defeating lynchpin controls, vendor / SIM-swap / authentication deficiencies, the public Telegram channel, and ten recommendations. cisa.gov/…/CSRB_Lapsus$_508c.pdf
  3. iTechPost — the verbatim Nvidia LHR demand ATTRIBUTED — reproduces, verbatim, the Lapsus$ public Telegram extortion post about Nvidia's mining limiter (source of the "In their own words" quote). itechpost.com/articles/109406/…

CONTEMPORANEOUS REPORTING — THE BREACHES

  1. The Verge — "Nvidia confirms it was hacked" ATTRIBUTED — the Nvidia intrusion, the ~1TB claim, and the open-source-drivers escalation. theverge.com/2022/3/1/22957212/…
  2. BleepingComputer — "Samsung confirms hackers stole Galaxy devices source code" ATTRIBUTED — the ~190GB Samsung dump and TrustZone / biometric source code. bleepingcomputer.com/…/samsung-confirms-hackers-stole-galaxy-devices-source-code/
  3. The Register — "Microsoft investigates Lapsus$ claim of Bing, Cortana theft" ATTRIBUTED — the Bing / Maps / Cortana source-code claim and Microsoft's single-account confirmation. theregister.com/2022/03/21/microsoft_lapsus_breach_probe/
  4. BleepingComputer — "Lapsus$ hackers leak 37GB of Microsoft's alleged source code" ATTRIBUTED — the torrent contents and 250-project claim. bleepingcomputer.com/…/lapsus-hackers-leak-37gb-of-microsofts-alleged-source-code/
  5. BleepingComputer — "Okta: Lapsus$ breach lasted only 25 minutes" ATTRIBUTED — the contractor route into Okta and the company's own account of the incident. bleepingcomputer.com/…/okta-lapsus-breach-lasted-only-25-minutes-hit-2-customers/
  6. Krebs on Security — "Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code" ATTRIBUTED — reproduced private-channel chats showing the crew's methods and dynamics; identifies the leader "White" only as a UK teenager. krebsonsecurity.com/2022/04/leaked-chats-show-lapsus-stole-t-mobile-source-code/

CONTEMPORANEOUS REPORTING — THE TRIAL

  1. BBC News — "Lapsus$: Court finds teenagers carried out hacking spree" FACT — the August 2023 jury findings, the unfit-to-plead mechanism, and the Fire Stick / hotel-room GTA VI hack detail. bbc.com/news/technology-66549159
  2. The Register — "Two teens found to be part of Lapsus$ gang" ATTRIBUTED — the jury's findings across the twelve offences. theregister.com/2023/08/24/two_teens_lapsus_jury/
  3. The Hacker News — "Two Lapsus$ Hackers Convicted in London Court" ATTRIBUTED — the trial outcome for both defendants. thehackernews.com/2023/08/two-lapsus-hackers-convicted-in-london.html
  4. The Register — "Lapsus$ teen sentenced to indefinite detention in hospital" FACT — the December 21, 2023 disposition. theregister.com/2023/12/21/lapsus_teens_sentenced/
  5. The Record — "Autistic teen behind spate of Lapsus$ hacks sentenced to indefinite hospital stay" FACT — the indefinite hospital order and the court's stated reasoning. therecord.media/lapsus$-hacker-sentencing-uk
  6. Bloomberg — "Grand Theft Auto VI Lapsus$ Teen Hacker Gets Hospital Sentence" (Wayback) ATTRIBUTED — the sentencing, archived snapshot (paywalled live). web.archive.org/…/bloomberg.com/…
  7. gHacks — "GTA 6 Hacker Arion Kurtaj Moved From Secure Hospital to Prison Ahead of November 2026 Retrial" ATTRIBUTED — the July 2026 transfer and the pending retrial. ghacks.net/2026/07/17/…

CONTEXT & CROSS-LINKS

  1. troll.fan — LulzSec CROSS-LINK — the "for the lulz" spectacle crew Lapsus$ descends from. troll.fan/dossiers/lulzsec.html
  2. troll.fan — TeaMp0isoN CROSS-LINK — the skill-versus-spectacle argument that predates and outlives Lapsus$. troll.fan/dossiers/teamp0ison.html
  3. troll.fan — Okta CROSS-LINK — the company's much-criticised breach response, the charlatan angle to the Lapsus$ intrusion. troll.fan/dossiers/okta.html
  4. troll.fan — Crew Rivalries CROSS-LINK — where the teen-crew lineage sits among the scene's feuds. troll.fan/crew-rivalries.html
  5. troll.fan — Timeline CROSS-LINK — the Lapsus$ spree in the wider chronology of the scene. troll.fan/timeline.html
The standard. Lapsus$ is a substantially-adjudicated and government-reviewed public matter: the intrusions, the extortion, the arrests, the 2023 trial outcome, and the DHS Cyber Safety Review Board's findings are documented in court reporting, contemporaneous press, and primary government filings, and are stated here as fact. The first-party quote is the group's own verbatim public Telegram post, attributed to the group, not to any individual. Arion Kurtaj is named only because he was named in open court and in widespread reporting; his autism and his age are stated exactly as the court established and the press reported, as bare fact, with no inference drawn about his character. His co-defendant, a minor who was not publicly named, is not named here. Nothing beyond the public record is asserted. If a line here couldn't survive scrutiny, it wouldn't be on the page.