Open cardosec

Case BC9C7B · Famous breaches · L3 Applied

Lapsus$ and identity attacks

Practise as: Deep dive
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Teen-led group active 2021-2022 hitting Okta, Microsoft, Nvidia, Samsung and Uber, mostly without malware
  2. Tactics: SIM swapping, MFA push fatigue, buying creds and session tokens, paying insiders for access
  3. Went after helpdesks and support tooling to reset MFA, then pivoted into Slack, Jira, source code repos
  4. Loud, extortion-driven style: leaked data on Telegram rather than deploying ransomware
  5. Defenses: phishing-resistant MFA, number matching, strict helpdesk identity verification, insider monitoring

If the interviewer pushes back

  • How did Scattered Spider later refine the same helpdesk social-engineering playbook against MGM in 2023?

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.