Microsoft confirms Lapsus$ hackers stole important Bing & Cortana source code
Thousands of companies and customers are now on high alert.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
You are now subscribed
Your newsletter sign-up was successful
Want to add more newsletters?
Every Friday
GamesRadar+
Your weekly update on everything you could ever want to know about the games you already love, games we know you're going to love in the near future, and tales from the communities that surround them.
Every Thursday
GTA 6 O'clock
Our special GTA 6 newsletter, with breaking news, insider info, and rumor analysis from the award-winning GTA 6 O'clock experts.
Every Friday
Knowledge
From the creators of Edge: A weekly videogame industry newsletter with analysis from expert writers, guidance from professionals, and insight into what's on the horizon.
Every Thursday
The Setup
Hardware nerds unite, sign up to our free tech newsletter for a weekly digest of the hottest new tech, the latest gadgets on the test bench, and much more.
Every Wednesday
Switch 2 Spotlight
Sign up to our new Switch 2 newsletter, where we bring you the latest talking points on Nintendo's new console each week, bring you up to date on the news, and recommend what games to play.
Every Saturday
The Watchlist
Subscribe for a weekly digest of the movie and TV news that matters, direct to your inbox. From first-look trailers, interviews, reviews and explainers, we've got you covered.
Once a month
SFX
Get sneak previews, exclusive competitions and details of special events each month!
Update: Microsoft confirmed the attack in a post last night, noting that it occurred after one of its employee's accounts was compromised by Lapsus$.
"No customer code or data was involved in the observed activities. Our investigation has found a single account had been compromised, granting limited access. Our cybersecurity response teams quickly engaged to remediate the compromised account and prevent further activity," the post reads.
Microsoft then goes on to lay out the groups tactics in detail, and ways to prevent against similar threat actors, so the post is worth a read if you're looking to tighten up security.
Original story: LAPSUS$, the same hacking group that targeted Nvidia and Samsung of recent, has confirmed it has targeted Microsoft, as well as LG and Okta. The latter would give the hackers access to 15,000 companies worldwide, including Peloton, Sonos and T-Mobile.
In the Microsoft attacks, the group claims to have stolen the source code for not only Bing browser, but also its mapping system and the Cortana assistant. Though El Chapuzas Informatico notes that the group admits it only managed to acquire 90% of the code for Bing Maps, whereas that number sits at around 45% for the code for Cortana and Bing itself. Torrents for both have been released, regardless.
As for LG, a "dump of all hashes for" the company's employee and service accounts has been leaked, and a "dump of LGs infrastructure confluence will be released soon." In the official chat announcement, the group taunts LG: "Might be a good idea to consider a new CSIRT team."
LAPSUS$'s attack on Okta has been proven with released screenshots, and security experts told Reuters they "definitely do believe it is credible." This is particularly troubling since it's one of the world's leading authentication companies for thousands of companies, universities, and government agencies across the globe. I'm sure I don't need to stress the kind of chaos that could cause, but as Reuters reports, Okta is looking into the security breach now.
Keep up to date with the most important stories and the best deals, as picked by the PC Gamer team.
"We believe the screenshots shared online are connected to this January event," Okta official Chris Hollis said in a statement. "Based on our investigation to date, there is no evidence of ongoing malicious activity beyond the activity detected in January."
Best AIO cooler for CPUs: All-in-one, and one for all... components.
Best CPU air coolers: CPU fans that don't go brrr.
Right now, thousands of companies, and countless customers, are on high alert. Since these are the same hackers that targeted Samsung, and released 190GB of sensitive data, it's safe to say their threats are not empty.
Their recent attack on Nvidia sent shockwaves, with the hackers threatening to release a bypass of Nvidia's hash rate limiter. Data stolen from those attacks was used to disguise malware as GPU drivers, so you can imagine what LAPSUS$ and the rest of the malicious few plan to do with Microsoft's source code.

Having been obsessed with game mechanics, computers and graphics for three decades, Katie took Game Art and Design up to Masters level at uni and has been writing about digital games, tabletop games and gaming technology for over five years since. She can be found facilitating board game design workshops and optimising everything in her path.

