Entra ID & IdentityCIO BriefingsRetrospectives

CIO Brief: Insider Recruitment and Social Engineering — The Lapsus$ Playbook

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from March 2022, written in 2026 with the benefit of hindsight.

The short version: In 2022, a group of teenagers called Lapsus$ breached Microsoft, Nvidia, Samsung and Okta — not with advanced hacking tools, but by buying passwords, bribing employees, spamming people with login approval requests and tricking help desks.

The Lapsus$ playbook

  • Buy stolen passwords from criminal markets.
  • Recruit insiders: offer employees money for access.
  • Spam MFA prompts until someone taps "Approve."
  • Call the help desk pretending to be an employee.
  • Search internal chat and wikis for more passwords.

None of this requires sophisticated skills. That's what made it alarming.

The business impact

  • Source code and data theft at major companies.
  • Public extortion and embarrassment.
  • Supply-chain effects when support providers were breached.

Questions to ask your team

  • Would our MFA stop someone who spams login requests or relays codes from a fake page?
  • How does our help desk verify identity before resetting MFA?
  • Could we detect an employee selling access?
  • Are passwords stored in our chat tools or wikis?

What good looks like

Phishing-resistant MFA for privileged users, strong help desk verification, insider risk awareness, secrets kept out of collaboration tools, and monitoring for unusual access.

The decision

Ask your team to run a tabletop exercise based on the Lapsus$ playbook. It is one of the most realistic scenarios for mid-sized companies today.

lapsus$ hack impactLapsus$2022

More on this story