January 2022: security researchers watching the Lapsus$ collective’s early operations saw the shape of a new threat actor — one whose tradecraft inverted industry assumptions. No zero-days, no malware sophistication: Lapsus$ ran identity-driven intrusion, achieving with an initial-access playbook — recruiting/targeting credentials, MFA-fatigue via push bombs, SS7-adjacent telephony abuse and SIM-swaps, access to password managers, and social engineering of help desks — what APTs of prior eras achieved with custom implants. The group’s public emergence (its Telegram channel, its brazen extortion style with its signature: leaking incrementally to pressure victims, mixing Portuguese/English across Brazilian and UK-linked members) ran through December 2021—March 2022 as a rising sequence: December’s Brazilian ministry hits (health ministry), early 2022’s Portugal-media cluster, and by late January the Okta precursor activity. That early-2022 chapter — before the big-name victims that made Lapsus$ a household security term — established the template: a teenager-heavy collective out-performing e-crime norms by weaponizing identity-provider abuse, third-party supplier trust, and the gap between “we have MFA” and “our MFA resists a determined social engineer”.
Lapsus$’s early-2022 breach activity (January window; collective active from December 2021) marked the rise of identity-driven extortion: intrusions achieved via credential acquisition and MFA-bypass tradecraft — password-manager access, MFA-push fatigue bombing, SIM-swap/telephony abuse, help-desk social engineering — followed by data theft and incremental public leaking on Telegram as extortion leverage. The January 2022 Okta precursor activity involved Lapsus$ compromising a third-party subcontractor of a vendor supporting Okta’s customer-identity service — the intrusion that became public in March as the Sitel/Okta support breach, but whose access dated to January 20, 2022 (per Okta’s later incident timeline). Lapsus$’s early victims and targets (Brazilian and Portuguese institutions including the Brazilian health ministry, Portuguese media giant Impresa, telecoms) demonstrated the group’s escalating ambitions before its March big-game hunting (Microsoft, Samsung, Nvidia, Ubisoft — detailed in our Okta-Lapsus$ March post). Security meaning: (1) MFA is a control, not a cure — push-fatigue and SIM-swap resistance require number-matching, hardware keys, and help-desk verification protocols; (2) third-party support/supplier access into identity providers is crown-jewel attack surface (foreshadowing 2023’s major telco/identity cluster); (3) extortion-by-incremental-leak on social platforms demands antagonist-ready comms and law-enforcement coordination playbooks.
What happened
Lapsus$ surfaced as a named public actor in December 2021 (Brazilian health-ministry data leaks), but January–February 2022 was its international breakout: the Impresa/SIC cluster in Portugal (January), and the access into Okta’s support chain via subcontractor Sitel dated January 20, 2022. The Okta timeline matters for understanding the March disclosure blast radius: attackers compromised a Sitel engineer’s account and had visibility/access into Okta’s customer-support console — not Okta’s production identity plane — for a roughly five-day window, an event Okta’s March statement and later clarification documented. Meanwhile the group’s Telegram channel ran extortion theatre in the open: poll-based victim taunting, deadline drama, partial leaks escalating on refusal — a style optimised for attention economics rather than dark-web discretion.
The collective’s composition — eventually revealed as a nucleus of teenagers (UK arrests in March 2022 of members aged 16–21) with Brazilian and UK links — drove two analytical shake-ups. First, the capability bar for catastrophic breach had collapsed: no nation-state budget required, only fluency in identity workflow and social engineering. Second, attribution assumptions inverted: defenders accustomed to decrypting APT tradecraft now had to study Telegram personas and teenage social graphs. Both lessons priced into the year’s security spending — push-fatigue-resistant MFA, help-desk callback verification, and third-party access governance moved from nice-to-have to baseline — controls that remain today’s identity floor.
How it worked
The identity-driven intrusion chain:
Lapsus$ initial-access playbook (2021-12→2022-03):
1. credential acquisition:
- initial access brokers / credential
marketplaces
- target org's employees: phishing,
- personal-password reuse
- password-manager compromises
2. MFA bypass options:
- MFA-push fatigue (bomb targets with
prompts till approval)
- SIM swap / telephony redirects to
capture OTP factors
- legacy protocol misuse where enforced
MFA didn't cover
3. help-desk social engineering:
- push-bomb the target, then call
the help desk as a frustrated
executive to reset the factor
3b. extend: access via third parties
(Sitel subcontractor engineer account
-> Okta support console, Jan-20 window)
4. post-access:
- reconnaissance of SaaS estate
- data staging & exfil (Teams/Slack,
Confluence, DevOps tooling)
- source-code repositories targeted by
name (Bing/Cortana era trophies)
5. extortion: incremental leaks w/ public
Telegram drama (polls, countdowns)
Step 3’s help-desk vector deserves its modern rereading: the technique later termed “MFA-fatigue-then-reset” (push-bomb the target, then call the help desk as a frustrated executive) matured across 2022 into the dominant initial-access pattern of the identity era — Mitre’s ATT&CK social-engineering and account-manipulation techniques codified it, and our identity-attack coverage tracks its enterprise defences. Lapsus$ demonstrated that identity-provider auxiliary surfaces (support consoles, vendor links, reset workflows) are boundary-of-trust assets deserving production-grade hardening.
Impact and numbers
| Metric | Value | Source |
|---|---|---|
| Collective active from | December 2021 (Brazilian targets) | press/researcher timeline |
| January 2022 targets | Impresa/SIC (Portugal); Okta-chain via Sitel (access 2022-01-20) | press/Okta incident timeline |
| Okta-chain window | ~5 days console visibility (support plane) | Okta statements |
| Extortion style | Telegram incremental leaks, polls, countdowns | channel archive/press |
| Tradecraft | Credential buying, push-fatigue, SIM-swap, help-desk SE | researcher post-mortems |
| Arrests (later) | UK, March 2022: members aged 16–21 | press |
| Follow-on big-game victims | Microsoft, Samsung, Nvidia, Ubisoft (March 2022) | press/victim confirmations |
Timeline
| Date | Event |
|---|---|
| 2021-12 | Lapsus$ surfaces: Brazilian health-ministry leak; distinctive Telegram extortion style established |
| 2022-01 | Portugal cluster (Impresa/SIC); Okta-chain access begins via Sitel subcontractor (Jan 20) |
| 2022-02 | Escalating activity; credential/MFA tradecraft refined; group’s reputation builds in research circles |
| 2022-03 | Big-game disclosures (London arrests first, then Okta breach disclosure, then Microsoft/Samsung leaks); collective’s identity-driven playbook becomes the year’s reference threat |
Why it still matters in 2026
Because every threat model since has absorbed the Lapsus$-era correction: the cheapest route into any organisation is now understood to be its people, their phones, and its identity stack’s edges. The controls that became standard in the group’s wake — phishing-resistant MFA (FIDO2/passkeys), number-matching and push limits, help-desk identity-verification protocols with callback and video proof, third-party support access scoped and monitored as privileged access — remain 2026’s identity baseline, and the attack class the group pioneered (identity-provider auxiliary-surface abuse) has since been industrialised by both e-crime and state actors. The extortion-comms dimension also left doctrine: victims learned that public, social-native threat actors require comms strategies as rehearsed as their IR plans. And the human story retained its cautionary force: the capability floor for catastrophic intrusions fell to teenage fluency, which is why identity investment (rather than perimeter spend) dominates modern budgets.
Detection and hardening takeaways
- Deploy phishing-resistant MFA everywhere. Push-fatigue and SIM-swap-resistant factors (FIDO2/passkeys, number-matching) close the exact vectors Lapsus$ ran; password + OTP-only estates remain the group’s natural prey, per our identity-attack reference.
- Harden the help desk as a boundary of trust. Verified callbacks, manager confirmation, andvideo-proof-of-person protocols on reset requests defeat social-engineered takeovers — treat reset flows with the same risk class as privileged credentials.
- Govern third-party support access like production access. The Okta/Sitel chain shows vendor support consoles are identity crown jewels; require scoped, time-boxed, session-monitored access and audit vendor chains recursively (your vendor’s subcontractor is your attack surface).
- Alert on MFA-fatigue patterns and factor changes. Burst push attempts, unexpected re-enrollments, and out-of-character help-desk resets are pre-breach signals; SOCs now tune these as high-priority identity alerts, not noise.
- Rehearse antagonist-comms playbooks. Telegram-native extortion demands pre-planned public-response strategies (statement readiness, law-enforcement coordination, incremental-leak anticipation); ad-hoc comms under leak pressure amplifies damage.
FAQ
Was the January Okta activity the same event as the March Okta disclosure?
Same intrusion chain, different visibility: January 20, 2022 was the access window (via Sitel subcontractor account), the March disclosure followed Lapsus$’s screenshots forcing Okta’s public statement. The gap itself became a lesson in third-party incident discovery latency — the victim’s vendor’s vendor was compromised for months before ripple-awareness, driving the sector’s later vendor-incident-notification requirements.
Why were teenagers able to breach major tech firms?
Because their tradecraft targeted the weakest gap in modern stacks: identity workflow fluency over malware sophistication. MFA-fatigue, SIM-swaps, and help-desk social engineering exploit process and human factors that perimeters cannot fix — which is why the response era’s spending shifted to identity controls, not more appliances.
What happened to Lapsus$ afterwards?
The collective faded after the March 2022 arrests and the leaked-doxxing it suffered, with members absorbed into other e-crime circles; the group’s playbook lived on — repeated, industrialised, and refined by successors throughout 2022–2024. Lapsus$ as a brand mattered less than the tradecraft corpus it demonstrated, which is why security training still teaches January 2022 as the moment identity-driven extortion went mainstream.
