Ransomware group

Lapsus$ ransomware: victims and leak site activity

The Lapsus$ ransomware group has listed 24 victims on its leak site since January 2022; its latest post is from 23 June 2026. Most affected countries: United States, France and Germany. Most targeted sector: Technology.

Total posts 24
First seen 2022-01-01
Latest post 2026-06-23
Countries hit 12

About Lapsus$

Lapsus$ is an internationally composed data extortion group most active from mid-2021 through 2022, executing high-profile breaches against Microsoft, Nvidia, Samsung, Okta, and Uber by stealing source code and threatening leaks rather than encrypting files; several members — predominantly teenagers — were arrested in the UK.

Leak site
http://lapsus.bz

Lapsus$ victims per year

3 2022
0 2023
0 2024
0 2025
21 2026

All 24 victims

Search every post in the full table.
Victim Country Sector Discovered
AYA BANK Myanmar Financial Services
INGKA GROUP Sweden Retail & E-Commerce
GITHUB INTERNAL United States Technology
MERCOR
MAPFRE ASSURANCE Spain Financial Services
VODAFONE Germany Technology
AXCERA TRADING United States Professional Services
CHECKMARX United States Technology
AXCERA.IO United States Technology
ASTRAZENECA CORP United Kingdom Healthcare
VirtaHealth United States Healthcare
Eiffage France Transportation
OSAC Aero France Manufacturing
Salesfloor Canada Technology
Adidas Germany Retail & E-Commerce
Loozap Switzerland Retail & E-Commerce
Lacoste France Retail & E-Commerce
DreamUp United States Education
Lille University France Education
FR Ministry of Agriculture France Government & Defense
Eni Energy Italy Energy & Utilities
Samsung Electronics Japan Technology
Nvidia United States Technology
Impresa Portugal Professional Services