Microsoft confirms Lapsus$ hackers stole important Bing & Cortana source code

Some code in purple and white whooshing away from the screen.
(Image credit: Negative Space)

Update: Microsoft confirmed the attack in a post last night, noting that it occurred after one of its employee's accounts was compromised by Lapsus$.

"No customer code or data was involved in the observed activities. Our investigation has found a single account had been compromised, granting limited access. Our cybersecurity response teams quickly engaged to remediate the compromised account and prevent further activity," the post reads.

Microsoft then goes on to lay out the groups tactics in detail, and ways to prevent against similar threat actors, so the post is worth a read if you're looking to tighten up security.


Original story: LAPSUS$, the same hacking group that targeted Nvidia and Samsung of recent, has confirmed it has targeted Microsoft, as well as LG and Okta. The latter would give the hackers access to 15,000 companies worldwide, including Peloton, Sonos and T-Mobile. 

In the Microsoft attacks, the group claims to have stolen the source code for not only Bing browser, but also its mapping system and the Cortana assistant. Though El Chapuzas Informatico notes that the group admits it only managed to acquire 90% of the code for Bing Maps, whereas that number sits at around 45% for the code for Cortana and Bing itself. Torrents for both have been released, regardless.

As for LG, a "dump of all hashes for" the company's employee and service accounts has been leaked, and a "dump of LGs infrastructure confluence will be released soon." In the official chat announcement, the group taunts LG: "Might be a good idea to consider a new CSIRT team."

LAPSUS$'s attack on Okta has been proven with released screenshots, and security experts told Reuters they "definitely do believe it is credible." This is particularly troubling since it's one of the world's leading authentication companies for thousands of companies, universities, and government agencies across the globe. I'm sure I don't need to stress the kind of chaos that could cause, but as Reuters reports, Okta is looking into the security breach now. 

"We believe the screenshots shared online are connected to this January event," Okta official Chris Hollis said in a statement. "Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January."

Cooling off

Cooler Master MasterLiquid ML360R and EK-AIO Basic 240 CPU coolers on a two-tone grey background

(Image credit: Cooler Master, EKWB)

Best AIO cooler for CPUs: All-in-one, and one for all... components.
Best CPU air coolers: CPU fans that don't go brrr.

Right now, thousands of companies, and countless customers, are on high alert. Since these are the same hackers that targeted Samsung, and released 190GB of sensitive data, it's safe to say their threats are not empty.

Their recent attack on Nvidia sent shockwaves, with the hackers threatening to release a bypass of Nvidia's hash rate limiter. Data stolen from those attacks was used to disguise malware as GPU drivers, so you can imagine what LAPSUS$ and the rest of the malicious few plan to do with Microsoft's source code.

Katie Wickens
Hardware Writer

Screw sports, Katie would rather watch Intel, AMD and Nvidia go at it. Having been obsessed with computers and graphics for three long decades, she took Game Art and Design up to Masters level at uni, and has been rambling about games, tech and science—rather sarcastically—for four years since. She can be found admiring technological advancements, scrambling for scintillating Raspberry Pi projects, preaching cybersecurity awareness, sighing over semiconductors, and gawping at the latest GPU upgrades. Right now she's waiting patiently for her chance to upload her consciousness into the cloud.

Read more
Mister Fantastic giving a thumbs up
A Marvel Rivals player has uncovered 'one of the most dangerous vulnerabilities a game can have' that'll let cheaters take over your PC and find your passwords
An image of a fake Bitcoin with a laptop in the background displaying financial data
North Korean hackers are said to have stolen $1,300,000,000 in crypto in 2024, an estimated 61% of the total funds swiped this year
Image manipulated symbolic alegory pointing into the mystery of being.
Deep trouble: Infosec firm finds a DeepSeek database 'completely open and unauthenticated' exposing chat history, API keys, and operational details
Path of Exile 2 early access class key art
Around 66 accounts in Path of Exile 2 were compromised, due to a one-two punch of an old unused Steam account and a backend bug
Pipboy holds up an open padlock.
A BIOS update could be all that's stopping you or someone else from jailbreaking your old AMD CPU
Hacker
$1.5 billion crypto heist could be the biggest yet, more than doubling the previous record, but don't worry: The affected firm says it can take the hit
Latest in Hardware
A pink GameSir Nova Lite, and a purple 8BitDo Ultimate 2C float in a teal void.
Hall effect controllers are so cheap now I’ve got a deal for you AND your player two
Peely from Fortnite with banana-fied Wolverine claws.
Fortnite comes to Snapdragon: Epic Games announces upcoming Arm support for its Easy Anti-Cheat software
Texas Instruments MSPM0C1104 tiny chip
World's smallest microcontroller looks like I could easily accidentally inhale it but packs a genuine 32-bit Arm CPU
Varjo Aero
Varjo Aero VR headsets seem to be not working on RTX 5090s, and its community is opting for strange solutions while waiting for an Nvidia driver release to fix it
A pasta "display" on a table showing the word "keep" surrounded by fruit. Obviously.
Penne for your thoughts: This pasta display can show three individual frames and it's trying its best, okay
Intel engineers inspect a lithography machine
Finally some good vibes from Intel as stock jumps 15% on new CEO hire and Arizona fab celebrates 'Eagle has landed' moment for its 18A node
Latest in News
Man facing camera
The Day Before studio reportedly sues Russian website for calling infamous disaster-game a 'scam'
Will Poulter holding a CD ROM
'What are most games about? Killing': Black Mirror Season 7 includes a follow-up to 2018 interactive film Bandersnatch
Casper Van Dien in Starship Troopers
Sony, which is making a Helldivers 2 movie, is also making a new Starship Troopers movie, but it's not based on the Starship Troopers movie we already have
Assassin's Creed meets PUBG
Ubisoft is reportedly talking to Tencent about creating a new business entity to manage Assassin's Creed and other big games
Resident Evil Village - Lady Dimitrescu
'It really truly changed my life in every possible way': Lady Dimitrescu actor says her Resident Evil Village role was just as transformative for her as it was for roughly half the internet in 2021
Storm trooper hero
Another live service shooter is getting shut down, this time before it even launched on Steam