Six things to know:
- Lapsus$ does not use ransomware, but instead relies on bribery and nonransomware extortion.
- The group uses tactics ranging “from simple to moderately complex,” according to the report. Some of its common approaches are credential theft; multifactor authentication bypass; social engineering; managed service provider compromise; SIM swapping; accessing employees’ email accounts; bribing employees, suppliers or business partners of target organizations for credentials and multifactor authentication approval; and self-injection into companies’ ongoing crisis communication calls.
- Lapsus$ may be composed of teenagers and young adults, according to the report. Its members speak English, Russian, Turkish, German and Portuguese.
- The group usually targets large companies.
- Lapsus$ was discovered in April 2020.
At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.