Hacker who hit Microsoft, Samsung and Nvidia could be this 16-year-old

Hacker in hoodie
(Image credit: Shutterstock)

One of the Lapsus$ hackers who have stolen data the internal systems of Microsoft, Samsung, Nvidia and other companies in the past few months may be a 16-year-old living with his mother near Oxford, England.

So says Bloomberg News in an unconfirmed (and paywalled) report that cites unnamed sources. Another member of Lapsus$ is believed to be a teenager in Brazil, Bloomberg said, and there may be as many as five other individuals involved. No individuals were named and no arrests have been made.

Bloomberg's William Turton and Jordan Robertson said personal information about the Oxford teen and his parents, including street addresses, had been posted online by rival hackers. 

The group cajoles tech-support workers into resetting passwords, pays insiders to provide access, and even joins in internal chatroom discussions when companies strategize about how to react to Lapsus$'s intrusions.

On Twitter, Turton said Robertson had rung the doorbell at the teen's mother's house and spoken to the mother through the intercom. The mother said she was unaware of the allegations against her son.

The Bloomberg report said the Brazilian teenager was so fast at breaking into systems that investigators initially thought they were witnessing an automated attack. 

If Lapsus$ are indeed a group of bored teenagers, that would make sense. The group seems more interested in notoriety than in money, and while it does make extortion demands tied to stolen data, it does not use ransomware or indeed much malware of any kind. 

Rather, the group breaks into corporate networks using bribery and trickery, a Microsoft report Tuesday (March 22) noted. It cajoles tech-support workers into resetting passwords, pays insiders to provide access, and even joins in internal chatroom discussions when companies strategize about how to react to Lapsus$'s intrusions.

The group has asked for payoffs in exchange for not publicly posting stolen data, but has also demanded, for example, that Nvidia release open-source drivers for its high-end graphics cards. 

Over this past weekend, Lapsus$ posted source code for several Microsoft online projects, including Bing, Bing Maps and the Cortana digital assistant. Microsoft insisted that the posting of the source code did not pose a security risk.

Paul Wagenseil

Paul Wagenseil is a senior editor at Tom's Guide focused on security and privacy. He has also been a dishwasher, fry cook, long-haul driver, code monkey and video editor. He's been rooting around in the information-security space for more than 15 years at FoxNews.com, SecurityNewsDaily, TechNewsDaily and Tom's Guide, has presented talks at the ShmooCon, DerbyCon and BSides Las Vegas hacker conferences, shown up in random TV news spots and even moderated a panel discussion at the CEDIA home-technology conference. You can follow his rants on Twitter at @snd_wagenseil.

Read more
An open lock depicting a data breach
Thousands including children exposed in major data breach — names, addresses, Social Security numbers and more accessed by hackers
A hacker typing on a computer
FBI issues serious warning to iPhone and Android users — stop doing this ASAP
A picture showing different credit cards stacked on top of each other on a table
5 million Americans just had their credit card details leaked online — what to do now
An open lock with a digital background and a cross and bones indicating a cyberattack
More than 70 million students and teachers had their personal data stolen in PowerSchool breach
children in school on their laptops with teacher in front of class
I'm a security editor and after the massive 70 million PowerSchool data breach — I started asking questions about how it affects my kids
Screen graphic showing data breach warning
5 worst data breaches of 2024 — including the mother of all breaches
Latest in Online Security
An image of a CAPTCHA
Hackers are using reCAPTCHA to trick users into infecting their own PCs with malware — how to stay safe
A smartphone screen displaying the Android name and logo next to a sign reading 'MALWARE'.
Fake Google Play Store pages are spreading Trojan malware that can steal your financial data
Best antivirus software
How does antivirus software work
and image of the Google Chrome logo on a laptop
Google Chrome at risk from shape-shifting browser extensions — how to stay safe
Green skull on smartphone screen.
Over 1 million Android devices infected with password-stealing, pre-installed botnet malware — how to stay safe
Android 12
Google March Android Security Update fixes two high severity vulnerabilities — update now
Latest in News
NYTimes Connections
NYT Connections today hints and answers — Tuesday, March 11 (#639)
An image of a CAPTCHA
Hackers are using reCAPTCHA to trick users into infecting their own PCs with malware — how to stay safe
Gmail logo on iPhone
Gmail just got a huge AI upgrade that will save you a ton of time
Xbox handheld
Xbox handheld reportedly arriving this year, new PC-like console in 2027
Concept image of foldable iPad
Apple reportedly has an 18.8-inch foldable iPad prototype with under-display Face ID
Adam Scott in "Severance," now streaming on Apple TV Plus.
'Severance' season 2 finale runtime just revealed — expect a violent finale