LAPSUS$
š Analytical overview of Telegram channel LAPSUS$
Channel LAPSUS$ (@minsaudebr) in the English language segment is an active participant. Currently, the community unites 57 390 subscribers, ranking in the Other category.
š Audience metrics and dynamics
Since its creation on Š½ŠµŠ²ŃŠ“омо, the project has demonstrated rapid growth, gathering an audience of 57 390 subscribers.
According to the latest data from 08 September, 2024, the channel demonstrates stable activity. Although there has been a change in the number of participants by 0 over the last 30 days and by 0 over the last 24 hours, overall reach remains high.
- Verification status: Not verified
- Engagement rate (ER): The average audience engagement rate is 0%. Within the first 24 hours after publication, content typically collects N/A% reactions from the total number of subscribers.
- Post reach: On average, each post receives 0 views. Within the first day, a publication typically gains 0 views.
- Reactions and interaction: The audience actively supports content: the average number of reactions per post is 0.
š Description and content policy
Channel description not provided.
Thanks to the high frequency of updates (latest data received on 09 September, 2024), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Other category.
Data loading in progress...
| Date | Subscriber Growth | Mentions | Channels | |
| 30 March | 0 | |||
| 29 March | +1 | |||
| 28 March | +5 | |||
| 27 March | 0 | |||
| 26 March | +1 | |||
| 25 March | +4 | |||
| 24 March | +4 | |||
| 23 March | +5 | |||
| 22 March | +1 | |||
| 21 March | +1 | |||
| 20 March | +4 | |||
| 19 March | +2 | |||
| 18 March | 0 | |||
| 17 March | 0 | |||
| 16 March | 0 | |||
| 15 March | +4 | |||
| 14 March | +3 | |||
| 13 March | 0 | |||
| 12 March | +2 | |||
| 11 March | +1 | |||
| 10 March | +1 | |||
| 09 March | +1 | |||
| 08 March | +3 | |||
| 07 March | +2 | |||
| 06 March | +2 | |||
| 05 March | +4 | |||
| 04 March | 0 | |||
| 03 March | +2 | |||
| 02 March | +8 | |||
| 01 March | 0 |
| 2 | Leak of some customers source code from Globant.com corp GHE and GHE
Around 70gb.
Enjoy! | 126 419 |
| 3 | For anyone who is interested about the poor security practices in use at Globant.com. i will expose the admin credentials for ALL there devops platforms below.
https://confluence.globant.com/
https://confluence.corp.globant.com/ (massive, over 3000 spaces of customer documents)
admin
oighiegh
https://crucible.globant.com/
https://crucible.corp.globant.com/
admin
aiyiushe
https://jira.globant.com/
https://jira.corp.globant.com/
admin
ohgheibi
admin2
ohgheibi
https://github.globant.com/
https://github.corp.globant.com/
syed.aleem
New123456789!!! | 114 218 |
| 4 | We are officially back from a vacation (spoiler above) | 89 268 |
| 5 | No text... | 89 496 |
| 6 | @fuckmox call +44 7784 154619 +44 7932 860730 kkkkkkkkkkkkkk | 1 |
| 7 | It has come to our attention that many users are impersonating Lapsus$ staff. Reminder that anyone claiming to be lapsus$ is most likely false, the only public username is @Lapsusjobs where you can work as an insider and get paid. Lapsus$ will never have ādouble your bitcoinā scheme. The only official Lapsus$ media is t.me/minsaudebr and t.me/saudechat. | 119 685 |
| 8 | We would like to advise everyone not to respond to any message or deal with @fuckmox as their telegram handle was stolen, and they are scamming our users. The official fuckmox currently does not have a username. More information will be announced shortly. | 11 |
| 9 | Welcome a new member @fuckmox | 22 690 |
| 10 | A few of our members has a vacation until 30/3/2022.
We might be quiet for some times.
Thanks for understand us. - we will try to leak stuff ASAP. | 140 110 |
| 11 | https://www.okta.com/blog/2022/03/updated-okta-statement-on-lapsus/
I do enjoy the lies given by Okta.
1. We didn't compromise any laptop? It was a thin client.
2. "Okta detected an unsuccessful attempt to compromise the account of a customer support engineer working for a third-party provider." -
I'm STILL unsure how its a unsuccessful attempt? Logged in to superuser portal with the ability to reset the Password and MFA of ~95% of clients isn't successful?
4. For a company that supports Zero-Trust. *Support Engineers* seem to have excessive access to Slack? 8.6k channels? (You may want to search AKIA* on your Slack, rather a bad security practice to store AWS keys in Slack channels š)
5. Support engineers are also able to facilitate the resetting of passwords and MFA factors for users, but are unable to obtain those passwords. -
Uhm? I hope no-one can read passwords? not just support engineers, LOL. - are you implying passwords are stored in plaintext?
6. You claim a laptop was compromised? In that case what *suspicious IP addresses* do you have available to report?
7. The potential impact to Okta customers is NOT limited, I'm pretty certain resetting passwords and MFA would result in complete compromise of many clients systems.
8. If you are committed to transparency how about you hire a firm such as Mandiant and PUBLISH their report? I'm sure it would be very different to your report :)
_________________________________________________________________________________________________________________________________________________________________________________________________________
https://www.okta.com/sites/default/files/2021-12/okta-security-privacy-documentation.pdf
*21. Security Breach Management.
a) Notification: In the event of a Security Breach, Okta notifies impacted customers of such Security Breach. Okta
cooperates with an impacted customerās reasonable request for information regarding such Security Breach, and Okta
provides regular updates on any such Security Breach and the investigative action and corrective action(s) taken.* -
But customers only found out today? Why wait this long?
9. Access Controls. Okta has in place policies, procedures, and logical controls that are designed:
b. Controls to ensure that all Okta personnel who are granted access to any Customer Data are based on leastprivilege principles;
kkkkkkkkkkkkkkk
1. Security Standards. Oktaās ISMP includes adherence to and regular testing of the key controls, systems and procedures of
its ISMP to validate that they are properly implemented and effective in addressing the threats and risks identified. Such
testing includes:
a) Internal risk assessments;
b) ISO 27001, 27002, 27017 and 27018 certifications;
c) NIST guidance; and
d) SOC2 Type II (or successor standard) audits annually performed by accredited third-party auditors (āAudit
Reportā).
I don't think storing AWS keys within Slack would comply to any of these standards? | 128 059 |
| 12 | Just some photos from our access to Okta.com Superuser/Admin and various other systems.
For a service that powers authentication systems to many of the largest corporations, I think these security measures are pretty poor. | 122 958 |
| 13 | Leak of some Bing , Bing Maps and Cortana source code - Bing maps is 90% complete dump. Bing and Cortana around 45%.
Enjoy everyone! | 124 086 |
| 14 | Dump of all hashes for LGE.com employee's and service accounts - second time we hacked them in ~1 years.
Dump of LG's infrastructure confluence will be released soon.
Might be a good idea to consider a new CSIRT team! | 99 953 |
| 15 | Deleted for now will repost later | 87 286 |
| 16 | No text... | 194 |
| 17 | image_2022-03-20_04-54-28.png | 9 |
| 18 | URGENTE: https://g1.globo.com/politica/noticia/2022/03/18/moraes-determina-bloqueio-do-aplicativo-de-mensagens-telegram-em-todo-o-brasil.ghtml
ENTREM NESSE CANAL E SE CONECTEM A ALGUM PROXY: https://t.me/ProxyMTProto
(only for brazil users!!!!) | 100 388 |
| 19 | Vodafone winner.
We work to ready the data! | 24 734 |
| 20 | We have just hit 30000 members š„³
Stay tuned! More stuff coming soon | 105 913 |
