INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
LAPSUS$ Group Allegedly Breached AstraZeneca's Data
| 2026-03-20 21:25 DATA BREACH
Executive Summary
AI-generated
A threat actor group identifying itself as “LAPSUS$” claimed responsibility for an alleged data breach involving AstraZeneca on March 20, 2026. The attackers allegedly obtained approximately 3GB of internal data, including source code and employee-related information from around 100 contractors. They are attempting to sell the data to the highest bidder and have shared sample files to support their claims. The attack works by exploiting contractor relationships and access systems, which could be used to support targeted social engineering campaigns. As of now, AstraZeneca has not publicly confirmed the breach or provided any details on the incident.
Technical Mitigations AI-generated
• User Training (ATT&CK mitigation for Social Engineering): Reduces success of phishing/vishing/impersonation and modern “human interface” lures.
• Audit (ATT&CK mitigation for Social Engineering): Enables correlation of email/identity/SaaS/endpoint activity that appears legitimate.
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ha•••••.com
ta•••••.gz
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Tactical Metrics
Intelligence Sources
HackRead
2026-03-20