Episode Details
Back to Episodes
Lapsus$:Teenagers Hacked Microsoft.
Description
A group of teenagers walked into Microsoft, NVIDIA and Okta. No zero-days. No custom malware. No command and control infrastructure. They bought leaked credentials, or they called the service desk and asked for a password reset.
Lieuwe Jan Koning, Co-founder & CTO at ON2IT, sits down with threat researcher Yuri Wit and Field CTO Rob Maas to take Lapsus$ apart step by step: bought credentials, MFA fatigue, over-permissioned accounts, and the extortion payday at the end.
The uncomfortable part is not how clever the attack was. It is how basic it was. If your help desk resets passwords without proof of identity, if your MFA is a tap-to-approve prompt, if your users carry permissions from two jobs ago, Lapsus$ did not need to be good. They only needed to try.
Yuri and Rob also cover what actually stops this: password resets that require physical identification, hardware tokens for sensitive Protect Surfaces, privileged access management with a human in the loop, and why AI is both the fastest way to audit your permissions and the fastest way to recreate the same over-permissioning problem all over again.
Timestamps
00:00:00 Hacking the largest companies on earth is super easy
00:01:19 Who Lapsus$ were, and why they are in jail
00:02:25 Step one: bought credentials and a phone call to the service desk
00:03:36 Password resets should be a hurdle, not a link
00:06:16 Not all MFA is equal: push fatigue, SMS and SIM swapping
00:09:03 Why your second factor does not belong in your password manager
00:11:09 Inside the network: privilege escalation, exfiltration, extortion
00:13:29 The fix: least privilege, PAM and a human in the loop
00:16:05 AI as auditor, and the agentic over-permissioning problem
Key Topics Covered
- How Lapsus$ obtained initial access without a single novel technique: dark web credentials and social engineering of the help desk
- Why MFA type matters more than MFA presence, and where push approval, SMS and TOTP each break
- Privilege escalation as the real bottleneck for attackers, and what least privilege plus PAM changes
- Zero Trust Protect Surface thinking as the way to decide which control is appropriate for which data
- The AI double edge: faster permission audits on one side, over-permissioned agent service accounts on the other