INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Lapsus$ claims AstraZeneca hack

| 2026-03-25 10:00 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
On March 25, 2026, the cybercrime group Lapsus$ claimed to have hacked pharma giant AstraZeneca, stealing approximately 3GB of sensitive data including credentials, code, and employee information. The alleged breach was advertised on a Dark Web forum and also appeared on a data leak site associated with LAPSUS$. If confirmed, it could be one of the most serious healthcare cyber incidents this year. Healthcare organizations hold highly valuable assets, making even non-patient data exposure potentially serious. The incident fits a broader trend of targeting healthcare for leverage, and stolen information could help attackers map systems, launch phishing attacks, and target internal operations. AstraZeneca has not yet confirmed the breach or publicly addressed the extortion group's claims.
Technical Mitigations AI-generated
• Block or hunt for LAPSUS$'s Dark Web forum posts and data leak sites associated with the group. • Patch Java, Angular, Python code repositories to prevent exploitation of vulnerabilities. • Implement additional security measures to protect against phishing attacks targeting internal operations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
LAPSUS$LAPSUS$
Target & Sectors
Global Scope healthhealth
Incident Timeline
‎2026/03/25
Cybercrime group Lapsus$ claims it hacked pharma giant AstraZeneca, stealing approximately 3GB of sensitive data.
data_breach 3 GB
threat_actor LAPSUS$
Tactical Metrics
Metrics
data_breach
3
Gb
Intelligence Sources