Lapsus$ (Mar 2022): Teenagers, MFA Fatigue and Breaches at Okta and Microsoft
Retrospective: this article looks back at events from March 2022, written in 2026 with the benefit of hindsight.
Between late 2021 and March 2022, a loosely organized group calling itself Lapsus$ breached some of the world's largest technology companies, including Nvidia, Samsung, Microsoft and Okta (through a third-party support provider). Several members turned out to be teenagers.
How they operated
Lapsus$ didn't rely on sophisticated malware. Microsoft (which tracked them as DEV-0537) and others described their techniques:
- Buying credentials and session tokens from criminal markets and infostealer logs.
- Paying insiders — employees at target companies, telecoms or support providers — for access.
- MFA fatigue: repeatedly sending push notifications until a user accepted, sometimes combined with calling the user and posing as IT.
- SIM swapping to intercept SMS codes.
- Searching internal collaboration tools (Slack, Teams, Confluence, Jira) for credentials and documentation.
- Targeting help desks to reset passwords and MFA.
Once inside, they stole source code and data, and publicized breaches on Telegram for notoriety.
The Okta case
Okta disclosed that a support engineer at a subprocessor (Sitel) had been compromised, and that attackers had accessed a limited number of customer tenants' support information. Okta's initially slow and incomplete communication drew criticism.
Why it mattered
Lapsus$ showed that large, well-resourced companies could be breached through identity and social engineering alone. The US Cyber Safety Review Board later reviewed Lapsus$ and recommended phishing-resistant MFA and stronger help desk controls.
Lessons in hindsight
- Number matching and phishing-resistant MFA defeat MFA fatigue.
- Help desk identity verification must be robust.
- Insider threat includes paid recruitment.
- Secrets in collaboration tools are a goldmine for attackers.
- How to Enable MFA Number Matching and Stop Push Fatigue Attacks How-To & Hardening
- Detecting MFA Fatigue Attacks: Entra Sign-In Logs and Sentinel KQL Detection & Response
- CIO Brief: Insider Recruitment and Social Engineering — The Lapsus$ Playbook CIO Briefings