Skip to content
NetarxImpact Database
SIM SwapNo AI reportedConfirmed

LAPSUS$ repeatedly targeted T-Mobile staff to reach internal tools and source code

T-Mobile US · Telecom · United States · March 2022

What happened

Leaked internal chat logs published by Krebs on Security in April 2022 showed that the LAPSUS$ extortion group repeatedly compromised T-Mobile employee accounts in March 2022. On 19 March the group reached Atlas, an internal T-Mobile tool for managing customer accounts, and used Slack and Bitbucket access to download more than 30,000 source code repositories in about twelve hours. T-Mobile confirmed the intrusion and said no customer or government information was obtained.

How the deception worked

LAPSUS$ bought T-Mobile VPN credentials from criminal marketplaces and then had to get an attacker-controlled device enrolled in the company's mobile device management, which meant persuading a T-Mobile employee to approve the enrolment. The chats show the group working the human layer persistently: when one employee blocked them, they simply bought another set of credentials and tried the next person. Their sustained interest in T-Mobile staff was that internal tools such as Atlas enable hassle-free SIM swaps, the group's core money-maker. T-Mobile detected the activity and revoked the access tokens.

The control that would have caught it· our reading, not a claim from the sources

Device enrolment must require a verified, ticketed request rather than a single employee approval, and access to customer-account tooling should be tightly scoped and continuously monitored.

Sources (2)

  1. Leaked Chats Show LAPSUS$ Stole T-Mobile Source Code
    Krebs on Security·krebsonsecurity.comOpen ↗
  2. T-Mobile Admits Lapsus$ Hackers Gained Access to its Internal Tools and Source Code
    The Hacker News·thehackernews.comOpen ↗

This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.