Key Takeaways
- A LAPSUS$-branded actor has announced a return to active operations, publishing a PGP-signed statement framing its stated goal as directly challenging the FBI and federal law enforcement while claiming operational immunity.
- A public countdown timer for a “Chapter II” first victim leak is running, putting a data release within days and signaling a leak-first extortion strategy.
- The statement explicitly credits TeamPCP, thanking the group for providing “the exact coverage” needed for the actor’s operations, consistent with a known cooperative relationship between the two in prior campaigns.
- Attribution should be treated with caution. “LAPSUS$” branding is used across more than one distinct actor cluster in the current cybercrime ecosystem, including groups separately tracked as Scattered Lapsus$ Hunters (SLH). This persona should not be assumed identical to SLH or to the original 2021 Lapsus$ group without further confirmation.
Incident Overview
On September 9, Dataminr detected an announcement from an actor operating under the “LAPSUS$ Group” persona, posted alongside a PGP-signed statement (SHA512). The message describes the group’s prior retirement as “a temporary diversion born of pure boredom” and states its present goal is “to openly challenge the FBI and the federal apparatus,” asserting the actor will continue extortion operations “without any risk” to itself.
The statement directly instructs targets to “prepare your incident response units and alert your federal managers.” Accompanying the post is a public countdown timer labeled “Chapter II First Victim Leak,” indicating a leak is expected within that window barring any change to the stated timeline. The statement opens by thanking TeamPCP by name for its “sacrifice” in providing cover for the actor’s operations, a detail consistent with previously observed cooperation between the two groups.
Dataminr Alert



Technical Details
This persona is tracked under aliases including DEV-0537 and GOLD RAINFOREST and operates within the broader cybercrime alliance framing known as “Trinity of Chaos,” alongside groups associated with Scattered Spider and ShinyHunters. Its known tradecraft favors rapid access-enablement over stealthy credential harvesting, most notably MFA bombing and SIM swapping to defeat multi-factor authentication and quickly escalate account compromise into broader access.
Its acknowledgment of TeamPCP reflects a documented operational relationship: TeamPCP’s cloud-native compromises of exposed control planes and developer ecosystems have previously fed victim access into LAPSUS$-branded extortion and leak operations, effectively turning TeamPCP’s supply chain intrusions into downstream infrastructure for this actor’s campaigns. No specific victim organizations, indicators of compromise, or intrusion vectors tied to the “Chapter II” campaign have been disclosed as of this writing.
Threat Actor & Motivation
The actor’s own statement frames its motivation as financial, citing “corporate extortion and the generation of countless millions of dollars,” layered with an explicit intent to provoke and publicly challenge federal law enforcement. This combination points to confrontational messaging being used as a credibility and pressure tool ahead of the stated leak deadline, rather than as an end goal in itself. The public countdown mechanic and direct address to incident response and federal personnel are consistent with a leak-first extortion posture, where visible urgency is intended to drive victim decision-making before organizations can independently confirm scope.
Imediate Action & Recommendations
- Enforce phishing-resistant MFA (FIDO2/WebAuthn hardware keys) on all remote access, VPN, and privileged accounts to close the MFA bombing and SIM-swap pathways this actor is known to use.
- Require out-of-band verification for any help desk-initiated MFA reset, password reset, or privilege escalation request, since this is the exact workflow this actor’s known tradecraft targets.
- Coordinate with mobile carriers to lock SIM changes and increase monitoring for SIM-swap indicators on accounts belonging to executives and privileged users.
- Audit developer and cloud environments for unauthorized service accounts, exposed control planes, and unreviewed API keys or tokens, given the stated TeamPCP relationship and its history of targeting these environments as an entry point.
- Validate incident response and legal notification playbooks now, ahead of the stated leak window, so data-exposure scoping and stakeholder communication can move quickly if your organization is named.
- Monitor known LAPSUS$-associated leak sites and channels for the “Chapter II” release and begin exposure scoping immediately if your organization or sector is referenced.

2026 Mid-Year Threat Landscape Report
The first half of 2026 was defined by a widening gap between attack speed and defense speed — and AI is accelerating both sides. Dataminr’s 2026 Cyber Threat Landscape Mid-Year Report pulls from 4,500 threat actors tracked, 73,000 vulnerabilities detected, and over 2 million alerts processed per month to surface what actually mattered in H1 and what teams need to prepare for in H2.
Download Report