Catch up on stories from the past week (and beyond) at the Slashdot story archive

 



Forgot your password?
typodupeerror
×
United States Technology

DHS Board Starts Investigating Lapsus$ Teen Hacker Group (axios.com) 9

A group of federal cyber advisers is putting a suspected teen hacking group under the microscope in the second investigation ever conducted by the Cyber Safety Review Board. From a report: The Department of Homeland Security review board -- a group of 15 federal government and private-sector cyber experts -- announced Friday morning that it will study and provide recommendations to fend off the hacking techniques behind the Lapsus$ data extortion group. The Cyber Safety Review Board first investigated and released a report with security recommendations in July about the Log4j open-source software vulnerability that affected millions of devices last year.

Lapsus$, which has been outed as a teenage hacking group, is believed to be behind data breaches at Uber, Rockstar Games, Microsoft, Okta and other major companies earlier this year. Data extortion groups break into a company's systems, steal prized information like source codes, and then demand a payment from the company to stop them from leaking the stolen information. Specifically, Lapsus$ targets companies through MFA fatigue, where they use stolen login credentials to log in to a network and then spam account owners with two-factor authentication requests on their phones until they accept one. Suspected members of the gang are believed to be based in the U.K. and have been arrested several times throughout the year.

This discussion has been archived. No new comments can be posted.

DHS Board Starts Investigating Lapsus$ Teen Hacker Group

Comments Filter:
  • MFA fatigue, where they use stolen login credentials to log in to a network and then spam account owners with two-factor authentication requests on their phones until they accept one.

    ..."until they accept one"? I am honestly surprised and disturbed. If a homeless person keeps pestering me for money, and I finally throw a $20 bill at them, I shouldn't be surprised when my wallet has $20 less in it, later. That's not a great analogy, but....there's better ways! Like, change your password. :-(

I've noticed several design suggestions in your code.

Working...