Case BC9C7B · Famous breaches · L3 Applied
Lapsus$ and identity attacks
Practise as: Deep dive
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Teen-led group active 2021-2022 hitting Okta, Microsoft, Nvidia, Samsung and Uber, mostly without malware
- Tactics: SIM swapping, MFA push fatigue, buying creds and session tokens, paying insiders for access
- Went after helpdesks and support tooling to reset MFA, then pivoted into Slack, Jira, source code repos
- Loud, extortion-driven style: leaked data on Telegram rather than deploying ransomware
- Defenses: phishing-resistant MFA, number matching, strict helpdesk identity verification, insider monitoring
If the interviewer pushes back
- How did Scattered Spider later refine the same helpdesk social-engineering playbook against MGM in 2023?
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.