LAPSUS$ Convictions: Teenagers, Helpdesks, and the GTA VI Leak

📋 Key Takeaways
  • What happened
  • Why teenagers beat enterprise identity
  • Timeline
  • Defensive lessons
  • The unfit-to-stand-trial nuance
5 min read · 977 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.

Quick Answer — On August 31, 2023, a London jury convicted two teenagers for the LAPSUS$ spree — the 2021–22 hackathon that breached Nvidia, Microsoft, Okta, Uber, Revolut, and Rockstar Games using nothing more exotic than SIM swaps, helpdesk manipulation, and stolen credentials. The convictions put a legal period on the saga, but the real verdict was aimed at defenders: a handful of teenagers with commodity techniques dismantled the assumptions of billion-dollar identity stacks. If your helpdesk can be talked into resetting an executive, your firewall budget is theater.

The LAPSUS$ file is the definitive case study in social engineering as prime exploitation: no zero-days, no malware sophistication — just humans, phones, and the MFA button users love to press. The convictions closed the criminal chapter; the defensive chapter is still being written.

What happened

  • The group: LAPSUS$ — a loose, young, mostly UK- and Brazil-based collective that operated via Telegram, bragged loudly, and monetized through extortion and chaos rather than encryption.
  • The methods: SIM swaps to hijack phone numbers, helpdesk social engineering to reset credentials, MFA-fatigue push bombing, and credentials harvested from infostealer-log markets — all commodity techniques available to anyone with a phone and patience.
  • The verdicts: Per UK court reporting, Arion Kurtaj (18) was convicted of the hack acts — including breaching Rockstar with a hotel TV, an Amazon Fire Stick, and a hotel phone while under police protection — his devices sat in police custody. A 17-year-old co-defendant (anonymized) was convicted on minor counts and later received a rehabilitation order.
  • The sentencing coda: In September 2023, Kurtaj — deemed unfit to stand trial in the conventional sense — received an indefinite hospital order after a jury found he committed the acts.

Why teenagers beat enterprise identity

Weakness How LAPSUS$ used it
Helpdesk trust Phone + plausible story beats verification scripts; resets are the crown-jewel moment
SMS-based recovery SIM swap converts your phone number into their skeleton key
MFA fatigue Push-spam until a tired user approves “to make it stop”
Stealer-log economy Credentials already circulating from malware infections feed the first foothold
Insider recruitment Reported attempts to pay employees of target firms for access
data-hmmnm-seam="2">

Timeline

Date Event
2021 LAPSUS$ emerges, hitting Brazilian targets first before going global
2022-02 → 03 Nvidia and Microsoft breached; Okta contractor compromise follows, with screenshots posted for chaos
2022-09 Uber (MFA fatigue + VPN creds) and Rockstar (GTA VI leak — 90 clips from a Slack takeover) in the same week
2022-09 → 2023 City of London Police arrests; group effectively dismantled though copycats continue the pattern
2023-08-31 (event; our peg) Southwark Crown Court jury convicts Kurtaj and the 17-year-old co-defendant after a seven-week trial of the acts
2023-09 → 12 Kurtaj receives indefinite hospital order; co-defendant a youth rehabilitation order — the criminal chapter closes
data-hmmnm-seam="3">

Defensive lessons

  • Treat the helpdesk as your most attacked surface. Every reset is an authentication decision made under social pressure; verification must be number-based, out-of-band, and immune to a good story.
  • Kill SMS recovery for anyone who matters. SIM swapping works because carriers are soft targets; passkeys, hardware keys, and number-free recovery paths remove the entire lever.
  • Rate-limit and monitor MFA pushes. Fatigue attacks are visible in telemetry — twenty pushes in ten minutes should page a human, not just annoy one.
  • Screen your users against stealer logs. If your workforce’s credentials circulate in malware datasets, assume the first foothold already exists; forced resets in advance deny the cheap entry.
  • Assume Slack/takeover blast radius. LAPSUS$ weaponized internal messaging for reputational damage; internal comms tools need admin-session anomalies watched like production.
data-hmmnm-seam="4">

The unfit-to-stand-trial nuance

The case’s oddest legal wrinkle — worth understanding because coverage mangles it — is that Kurtaj was found unfit to participate in his own trial (per psychiatric assessment), so the jury was asked only whether he committed the acts, not whether he possessed criminal intent in the ordinary sense of a standard criminal conviction. That procedural shape is why the eventual disposition was a hospital order rather than a prison term. For the security record, nothing changes: the acts were proven — including the almost surreal detail that the Rockstar intrusion was conducted from a hotel room using a television, a Fire Stick, and a phone while police held his actual computers. If there is a more vivid argument that access control must assume attacker creativity, it hasn’t been filed.

data-hmmnm-seam="5">

Why it still matters in 2026

Every major identity incident since has reused some fragment of the LAPSUS$ playbook — MFA-fatigue at MGM weeks later, helpdesk resets against countless orgs, stealer-log-driven intrusions at scale. The industry response coalesced into what we now teach as baseline: phishing-resistant MFA, verified reset workflows, number matching, and credential-exposure monitoring. The teenagers were the stress test that proved identity — not the network — is the perimeter; the convictions just made the study permanent.

Who exactly were LAPSUS$?

Per law-enforcement and court reporting: a small core of teenagers (with a wider circle of hangers-on and copycats) coordinated over Telegram, motivated as much by notoriety as by money. Their opsec was poor — videos, brags, and traces everywhere — which is precisely how the City of London Police rolled them up within months.

Did the companies lose data or money?

Both, unevenly. Nvidia and Samsung saw source-code and credential leaks; Okta suffered a contractor foothold with reputational damage outsized to technical impact; Uber’s intruder wandered internal systems; Rockstar suffered the most famous content leak in gaming history. Direct ransom payments were rarely the outcome — extortion demands often weren’t paid.

Were they really teenagers?

Yes — the convicted core were 16–18 at the time of the crimes, and UK reporting anonymized several minors throughout. The disconnect between attacker profile and victim scale remains the case’s headline lesson.

What happened after the convictions?

The named principal was hospitalized indefinitely; the minor received a rehabilitation order. The group’s brand flickered among copycats, but the specific spree ended with the arrests. Their techniques, unfortunately, became permanent infrastructure — adopted by far less selective criminals.

Part of the hmmnm.com security-timeline series — one event per month, 2021–2024, indexed here.

data-hmmnm-seam="end">

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.