On 1 March 2022, the Lapsus$ extortion group awoke the hardware world to its new favourite attack: pure source-code extortion without encryption. Samsung confirmed a security breach after Lapsus$ published roughly 190 GB of internal material — including source code related to its Galaxy devices’ bootloaders, trusted applets for Samsung Pass and SmartThings, activation and account-management servers, and assorted cryptography and biometrics-related code — allegedly scraped from Samsung’s own CI/CD environment after compromising a single contractor’s access. The leak’s significance was not immediate fraud but lasting exposure: authentication logic, signing infrastructure references, and device-trust internals were now public, forcing Samsung into a review-and-harden cycle it could never fully declare finished. For the industry, the event completed a February-to-March 2022 hat trick — Nvidia, then Samsung within a week — establishing data extortion (steal, threaten, dump) as a standalone business model distinct from ransomware, and establishing Lapsus$ itself as the scrappy, noisy, absurdly effective crew whose teenage social-engineering campaigns would keep CISOs awake through the spring.
On 2022-03-01, Samsung confirmed a breach after extortion group Lapsus$ published ~190 GB of internal data, dominated by source code for Galaxy device software: bootloader components, trusted applets (Samsung Pass, SmartThings), activation/account servers, biometrics-adjacent code, and cryptography-related source. Attack path per public reporting: Lapsus$ compromised an external contractor’s credentials/access into Samsung’s development (CI/CD) environment, exfiltrated repositories and artifacts, then dumped the archive publicly when Samsung declined to pay — extending the pure-extortion (no encryption) model the group had just demonstrated against Nvidia (2022-02). Impact: no direct customer data dump (unlike later Lapsus$ telecom hits), but durable security exposure — trust-architecture internals, signing references, and authentication code became permanent public review surface; Samsung acknowledged the incident, reviewed boot/process integrity implications, and the event became a flagship argument for CI/CD hardening, third-party access minimisation, and secret-rotation discipline. Security meaning: source code is a critical data class — its loss is strategic, unfalsifiable (“we fixed it” is unverifiable from outside), and its exfiltration path is increasingly a contractor or over-permissioned pipeline account rather than an unpatched perimeter server.
What happened
Lapsus$ had spent February 2022 escalating through big-name victims — Nvidia (source code + credential dumps, ~1TB claims), Mercado Libre, and after Samsung, Okta and Microsoft would follow within weeks. The group’s method was consistent: obtain initial access by any cheap means (credential markets, phishing, SIM-swapping contractors, paying insiders — they openly advertised for employees willing to leak for cash), pivot to identity-centric sprawl, harvest everything in reach, then extort with publication as the default outcome.
In Samsung’s case, reporting traced the foothold to an external contractor’s access into development infrastructure. The 190 GB archive appeared on Lapsus$ channels as torrents, described as including bootloader source for recent Galaxy devices, trusted applet code for Samsung Pay/Pass and SmartThings, activation and account-server source, and backend database schema excerpts. Samsung’s confirmation was terse: data included source code unrelated to customers’ personal information was taken; the company was assessing implications and had activated responders.
The long tail stayed quiet — deliberately. No dramatic follow-on exploitation of the leaked code was ever publicly attributed, but security teams understood the asymmetry: attackers worldwide had gained permanent reference material on Samsung’s trust architecture, and any latent bug in that corpus was now crowd-sourced. Samsung’s subsequent disclosures emphasised hardened CI/CD and tightened third-party access, never claiming (because no one could) that publication had been harmless.
The Lapsus$ method
Lapsus$ operational signature (2021-2022):
INITIAL ACCESS - identity-first
- credential dumps from prior
breaches (password reuse)
- phishing + MFA-fatigue style
prompts; session/token theft
- SIM swap contractors/employees
- RECRUIT INSIDERS: public posts
offering $ cash for employees
to perform actions or leak
credentials (multiple confirmed)
- access brokers / markets
PIVOT & SPRAWL
- target identity providers, VPN,
CI/CD, help desks (MFA resets)
- create or co-opt service
accounts; consent-phishing on
OAuth apps for mail/storage
EXFIL & EXTORT - no encryption
- mass-download source/repos/
internal docs
- demand payment with deadline;
if unpaid -> PUBLIC DUMP
- loudly narrate everything on
Telegram (recruitment, taunts,
victim updates) - growth-
hacking their own brand
TARGETS Feb-Apr 2022
Nvidia ~1TB claims, Samsung
190GB, Vodafone, Mercado Libre,
Okta (via Sitel), Microsoft
(Bing/Cortana partial), Ubisoft,
Globant...
Impact and numbers
| Metric | Value | Source |
|---|---|---|
| Publication/confirm | 2022-03-01 | Samsung statement / Lapsus$ channels |
| Data volume | ~190 GB archive | torrent listings |
| Content | Bootloader, Samsung Pass/SmartThings applet code, activation/account servers, crypto-adjacent source | archive contents / reporting |
| Foothold (reported) | Contractor access into dev/CI environment | contemporaneous reporting |
| Customer PII | Samsung: no direct customer data in dump | Samsung statement |
| Extortion model | Steal-and-dump (no encryption) | group behavioural history |
| Family context | Lapsus$ Feb–Apr 2022 spree (Nvidia, Okta, Microsoft, others) | public record |
Timeline
| Date | Event |
|---|---|
| 2021-12 | Lapsus$ emerges (Brazilian Ministry of Health hit amid early ops) |
| 2022-02-22→28 | Nvidia breach: source + credential dumps published; pure-extortion brand established |
| 2022-03-01 | ~190 GB Samsung archive published; Samsung confirms breach same day |
| 2022-03-04→22 | Group continues: Vodafone, Okta/Sitel, Microsoft, Ubisoft, Globant |
| 2022-03→09 | City of London Police arrests (incl. teenagers) — spring 2022; group’s momentum degrades |
Why it still matters in 2026
Because every headline menace of the modern identity era was already in this playbook. Lapsus$ ran contractor-compromise, credential-reuse, SIM-swap, MFA-fatigue, help-desk social engineering, and paid-insider recruitment in a single spring — the same primitives that Scattered Spider (the 2023–2025 hotel-and-retail terror) industrialised, and that the MGM/Caesars-style attacks of 2023 re-ran at nine-figure cost. Defenders learned to think in terms of identity supply chains: your contractors, your help desk, your MFA help flows, even your employees’ willingness to take a stranger’s Telegram cash — all live on the attack paths. Source-code extortion specifically became a genre: the 2023–2025 stretch delivered a steady cadence of steal-and-dump incidents (from Snowflake-customer intrusions’ downstream source theft to game-studio and carmaker leaks), each re-proving that code’s value is cumulative, its loss permanent, and its CI/CD provenance the new crown-jewel perimeter. Samsung’s 190 GB remains the reference exhibit for hardware-trust exposure — biometrics applets, bootloaders, activation logic — the exact material a state or competitor would prize, obtained not through exotic zero-days but through one contractor’s credentials.
Detection and hardening takeaways
- Minimise third-party dev access. The reported path was contractor access to CI/CD; tie every external identity to least-privilege, time-boxed scopes, and monitored artifact-repository permissions — and inventory which contractors can reach source at all.
- Assume source is exfiltratable; plan for its publication. Manage the exposure as a lifecycle: secret-scanning pre-merge, rapid key/credential rotation post-incident, and architecture that survives disclosure (defence-in-depth in trust design, not security-by-obscurity in algorithms).
- Harden the identity edges Lapsus$ used. Phishing-resistant MFA with number-matching discipline, help-desk verification protocols resistant to voice-social-engineering, SIM-swap coordination with carriers or port-free lines for critical staff, and alerts for new OAuth consent grants.
- Watch for insider-recruitment tells. Lapsus$ publicly solicited insiders for cash; monitor for anomalous internal repo access, privilege escalation requests outside change windows, and grooming contacts on professional networks — the insider market is now public, and staff-awareness programmes should say so.
- Instrument exfiltration paths on egress. Mass clone/fetch patterns from dev tools, unusual repo-download volumes, and fresh token grants to unrecognised CI jobs are the telemetry that catches pure-extortion crews before their deadline, not after their dump.
FAQ
Was customer data leaked?
Samsung stated the dumped material was source code and related internal data, not a direct trove of customer personal information. The harm was of a different class: permanent disclosure of trust-critical code (bootloaders, biometrics applets, account infrastructure) whose security implications could not be fully re-verified from outside — and whose future bug discovery was now crowd-sourced to the entire world.
How did Lapsus$ get in?
Public reporting centred on compromised contractor credentials reaching Samsung’s development environment; the group’s broader toolkit (credential reuse, SIM swaps, phishing, MFA-fatigue, paying insiders) was documented across its spree. Samsung never published a full technical post-mortem, consistent with a general pattern: pure-extortion victims rarely detail the entry path, since the negotiation ended in publication rather than a joint disclosure.
Whatever happened to Lapsus$?
Arrests in the UK (the City of London Police’s spring 2022 operations including teenagers, one repeatedly identified in reporting as central) degraded the crew’s momentum by late March, and the brand wound down — but the tradecraft outlived it: the identity-first, extort-without-encrypting playbook resurfaced in successor collectives (most prominently Scattered Spider), and its techniques are now permanent fixtures of threat models for help desks, carriers, and CI/CD pipelines alike. The Samsung dump itself remains the hardware-security reference case for what contractor-grounded source theft looks like at scale.
