Posts

Showing posts with the label Lapsus$

Data Breach on DEA Law Enforcement System Grants Cyber Criminals Access to 16 Databases

By Alicia Hope, CPO Magazine U.S. Drug Enforcement Agency (DEA) is investigating a potential law enforcement system data breach associated with an online harassment community that impersonates police officers. KrebsOnSecurity journalist Brian Krebs received a tip that hackers gained unauthorized access to the esp.usdoj.gov data portal, the Law Enforcement Inquiry and Alerts (LEIA) system. Krebs obtained the information from the administrator of the Doxbin cyberbullying community identified as “KT” with links to the LAPSUS$ hacking group. Doxbin members post personal information online and participate in “swatting,” while LAPSUS$ was responsible for high-profile data breaches on Microsoft, NVIDIA, Okta, Samsung, and others. LAPSUS$ also sells a service for making Emergency Data Requests to tech companies, social media platforms, and mobile service providers. The imposters trick organizations by claiming that the data requests could not wait for warrants because of their emergency nature...

Conti Ransomware Gang Strikes Major Component Supplier For Boeing And Lockheed Martin

Image
By Nathan Wasson, Hot Hardware The beginning of the year saw a flurry of stories about security breaches as the cybercriminal gang known as LAPSUS$ stole data from an alarming number of big name companies in a short period of time. However, while LAPSUS$ is no longer in operation, after the London police arrested all seven members of the group, other cybercriminal groups are still afoot and out to steal data. One of these groups is the Russian-based Conti ransomware group. When Russia’s war on Ukraine broke out in February, the Conti ransomware gang announced that it fully supported the Russian government and would carry out counterattacks against anyone who organized cyberattacks or other offensive measures against Russia. The group specifically called out “Western warmongers” and “American cyber aggression.” Earlier this month, the US Department of State announced its offering of up to $10 million for information that helps identify or locate key members of the Conti ransomware gang....

DEA Investigating Breach of Law Enforcement Data Portal

Image
By  KrebsOnSecurity The U.S. Drug Enforcement Administration (DEA) says it is investigating reports that hackers gained unauthorized access to an agency portal that taps into 16 different federal law enforcement databases. KrebsOnSecurity has learned the alleged compromise is tied to a cybercrime and online harassment community that routinely impersonates police and government officials to harvest personal information on their targets. Unidentified hackers shared this screenshot of alleged access to the Drug Enforcement Administration’s intelligence sharing portal On May 8, KrebsOnSecurity received a tip that hackers obtained a username and password for an authorized user of esp.usdoj.gov, which is the Law Enforcement Inquiry and Alerts (LEIA) system managed by the DEA. KrebsOnSecurity shared information about the allegedly hijacked account with the DEA, the Federal Bureau of Investigation (FBI), and the Department of Justice, which houses both agencies. The DEA declined to comment...

T-Mobile breached by cybercrime group LAPSUS$ through compromised employee accounts

Image
By Michael Potuck, 9 to 5 Mac T-Mobile has suffered another data breach, this time carried out by young hackers that were part of the LAPSUS$ group. While T-Mobile has said that no customer or government information was compromised, it appears LAPSUS$ gained access to T-Mobile’s source code repositories along with its customer account management system. Reported and seen by Krebs on Security , leaked messages between members in the LAPSUS$ cybercrime group show that they successfully hacked into T-Mobile multiple times last month. The hackers gained access to T-Mobile’s internal systems by taking over multiple employee accounts with purchases through sites like “Russian Market,” social engineering, and other methods of stealing the information. The messages reveal that each time LAPSUS$ was cut off from a T-Mobile employee’s account — either because the employee tried to log in or change their password — they would just find or buy another set of T-Mobile VPN credentials. T-Mobile curr...

Previous Lapsus$ Hacking Incident is 'Significantly Smaller' than Expected, Says Okta

Image
By Joseph Henry, Tech Times Lapsus$ operations started earlier this year when the control lasted for 25 consecutive minutes, according to Okta. Previously, the access management firm said that the data breach might have affected many systems. However, the recent finding reveals that the impact of the incident appears to be "significantly smaller" compared to the previous assumptions. Only two customers were hit by the hackers at that time. Lapsus$ Breach Only Impacts Two Customers Okta clarifies that the previous finding of the impact of the Lapsus$ hacking incident is only "significantly smaller" than its suspected maximum impact. According to Okta's blog post published on Tuesday, Apr. 19, the investigation concludes that the impact of the Lapsus$ hacking incident only hit two customer tenants. Initially, the event took place on Jan. 21, but it was only on March 22 when Okta understood what really happened during the system breach. The anonymous cybersecuri...