CIO Brief: Insider Recruitment and Social Engineering — The Lapsus$ Playbook
Retrospective: this article looks back at events from March 2022, written in 2026 with the benefit of hindsight.
The short version: In 2022, a group of teenagers called Lapsus$ breached Microsoft, Nvidia, Samsung and Okta — not with advanced hacking tools, but by buying passwords, bribing employees, spamming people with login approval requests and tricking help desks.
The Lapsus$ playbook
- Buy stolen passwords from criminal markets.
- Recruit insiders: offer employees money for access.
- Spam MFA prompts until someone taps "Approve."
- Call the help desk pretending to be an employee.
- Search internal chat and wikis for more passwords.
None of this requires sophisticated skills. That's what made it alarming.
The business impact
- Source code and data theft at major companies.
- Public extortion and embarrassment.
- Supply-chain effects when support providers were breached.
Questions to ask your team
- Would our MFA stop someone who spams login requests or relays codes from a fake page?
- How does our help desk verify identity before resetting MFA?
- Could we detect an employee selling access?
- Are passwords stored in our chat tools or wikis?
What good looks like
Phishing-resistant MFA for privileged users, strong help desk verification, insider risk awareness, secrets kept out of collaboration tools, and monitoring for unusual access.
The decision
Ask your team to run a tabletop exercise based on the Lapsus$ playbook. It is one of the most realistic scenarios for mid-sized companies today.
- Lapsus$ (Mar 2022): Teenagers, MFA Fatigue and Breaches at Okta and Microsoft Incident Teardowns
- How to Enable MFA Number Matching and Stop Push Fatigue Attacks How-To & Hardening
- Detecting MFA Fatigue Attacks: Entra Sign-In Logs and Sentinel KQL Detection & Response