Episode Details

Back to Episodes
Lapsus$:Teenagers Hacked Microsoft.

Lapsus$:Teenagers Hacked Microsoft.

Published 14 hours ago
Description

A group of teenagers walked into Microsoft, NVIDIA and Okta. No zero-days. No custom malware. No command and control infrastructure. They bought leaked credentials, or they called the service desk and asked for a password reset.

Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with threat researcher Yuri Wit and Field CTO Rob Maas to take Lapsus$ apart step by step: bought credentials, MFA fatigue, over-permissioned accounts, and the extortion payday at the end.

The uncomfortable part is not how clever the attack was. It is how basic it was. If your help desk resets passwords without proof of identity, if your MFA is a tap-to-approve prompt, if your users carry permissions from two jobs ago, Lapsus$ did not need to be good. They only needed to try.

Yuri and Rob also cover what actually stops this: password resets that require physical identification, hardware tokens for sensitive Protect Surfaces, privileged access management with a human in the loop, and why AI is both the fastest way to audit your permissions and the fastest way to recreate the same over-permissioning problem all over again.

Timestamps

00:00:00 Hacking the largest companies on earth is super easy 
00:01:19 Who Lapsus$ were, and why they are in jail 
00:02:25 Step one: bought credentials and a phone call to the service desk 
00:03:36 Password resets should be a hurdle, not a link 
00:06:16 Not all MFA is equal: push fatigue, SMS and SIM swapping 
00:09:03 Why your second factor does not belong in your password manager 
00:11:09 Inside the network: privilege escalation, exfiltration, extortion 
00:13:29 The fix: least privilege, PAM and a human in the loop 
00:16:05 AI as auditor, and the agentic over-permissioning problem

Key Topics Covered

  • How Lapsus$ obtained initial access without a single novel technique: dark web credentials and social engineering of the help desk
  • Why MFA type matters more than MFA presence, and where push approval, SMS and TOTP each break
  • Privilege escalation as the real bottleneck for attackers, and what least privilege plus PAM changes
  • Zero Trust Protect Surface thinking as the way to decide which control is appropriate for which data
  • The AI double edge: faster permission audits on one side, over-permissioned agent service accounts on the other
Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us