LAPSUS$ Strikes Again As Hackers Seem To Have Targeted Microsoft’s DevOps Platform
LAPSUS$ then followed up the NVIDIA attack by stealing Samsung source code, which the company has since confirmed. LAPSUS$ has leaked 204GB of Samsung data and 20GB of NVIDIA data, but claims to possess 1TB of NVIDIA data. The 20GB of NVIDIA data that have been leaked included employee information, as well as two of NVIDIA’s code signing certificates, which bad actors are currently using to sign malware and bypass Windows protections.
It remains to be seen whether LAPSUS$ really does possess additional NVIDIA data. The group originally set March 4 as the date on which it would release its full 1TB trove if NVIDIA didn’t comply with the ransomware group’s demands to make all future graphics drivers open source. However, over two weeks have passed since then and LAPSUS$ has still not made additional data available for download. The group has ended multiple Telegram posts by asking people to give them time and even said that repeatedly asking about additional NVIDIA data will result in a ban.

However, LAPSUS$ later deleted the image from its Telegram channel and posted an update, saying that the image has been deleted for now, but will be reposted later. LAPSUS$ has been silent since then, so we’ll have to wait and see if additional information comes out about the suspected Microsoft breach.