Microsoft

Lapsus$ group claims to have hijacked source code: Microsoft Investigating

After the attack on the South Korean electronics manufacturer Samsung, the extortion group Lapsus$ now claims to have gained access to Microsoft. The hackers reported that they had multiple DevOps accounts under their control and thus had access to important data sources. Nvidia, Ubisoft, and Vodafone have also fallen victim to the Lapsus$ group in the recent past. Microsoft would now be affected, but the extent of the hack is not yet known. Microsoft has already confirmed that they are taking the alleged data access reports very seriously and investigations have been launched.

short-term

Lapsus$ initially reported in forums on Sunday that Microsoft’s source code repositories had been hacked. Reports appeared on Telegram and Reddit, among others. However, these reports were removed again stating that a “re-post” would be presented once they were ready to provide details of the captured data. In a retracted screenshot, the group now claims to own the source code for Cortana and several Bing projects called “Bing_STC-SV”, “Bing_Test_Agile”, and “Bing_UX”. It concerns the internal Azure DevOps source code repositories of the software company. The group is said to have penetrated there and stolen data. So far, such attacks have always resulted in Lapsus sending millions of dollars in ransom to the company while simultaneously making parts of it public to confirm they have the data. The Bleeping Computer has already done some research into possible problems due to a source code leak.

On the security front, Microsoft said the group believes viewing the source code does not pose an increased risk. This is also due to the fact that the group pursues a so-called “inner source” approach. This includes the development of open-source software and open source-like culture – to make the source code visible within Microsoft. “This means that we don’t rely on source code secrecy to protect our products, and our threat models assume that attackers are aware of the source code,” Microsoft explains in a blog post about a legacy SolarWinds attacker accessing their source code. 


Recent Posts

Update chaos after patch day: WSUS server refuses synchronization

After Windows Patch Day in July 2026, reports of problems with the Windows Server Update…

1 day ago

PayPal Gets $53 Billion Takeover Offer from Stripe

The payment service provider PayPal is apparently facing a large-scale takeover. Two investors have submitted…

1 day ago

GTA 3 and Vice City run on in-game TV in San Andreas

A new mod for GTA San Andreas lets players play two older parts of the…

1 day ago

Emergency Alert: Robotaxis are helpless if passengers fall asleep

With the increasing spread of autonomous robotaxis, not only the technical capabilities of the vehicles…

1 day ago

UK to introduce mileage tax for electric cars in 2028

From 2028, electric car drivers in the UK will have to pay a distance-based levy.…

1 day ago

Galaxy Watch 9 & Ultra 2 Leak comes with smartwatches in official photos

Shortly before the next Unpacked event on July 22nd, official promo images of the new…

1 day ago