You Can’t Publish Their Names
TL;DRLapsus, a loosely organized hacking group of British teenagers, breached NVIDIA, Microsoft, Samsung, Ubisoft, and Okta using data extortion before seven members were arrested by London police.
The story of a very strange doxxing and an even stranger hacking gang.
Transcript
Machine-generated transcript; may contain errors.
Speaker 1: There is a Telegram channel where you can vote on what major international companies' data is gonna get leaked next.
Speaker 2: Meantime, we are getting some headlines on the group Lapsus.
Speaker 1: It was a poll in the channel right at the end of last year, and they said three companies pick one, Vodafone, Impreza, or MercadoLibra, these three companies operating in South America. We're gonna leak their data. Who first? And this Telegram channel is public. I think there's about 45,000 people in the channel kind of right now. And last year, they all got this choice to vote on whose data gets dumped. The hacking group behind this Telegram would be interesting even if you just focused on the hacks themselves.
Speaker 2: The group that we believe hacked Okta earlier this year
Speaker 1: Microsoft, NVIDIA, Ubisoft, Samsung, really high profile companies, super highly publicized, like, data extortion schemes. Their name is Lapsus. And if you follow this kind of thing, you might have bumped into them very recently. But the reason I think we should talk about them, beyond just the hacks, which are interesting, is the drama.
Speaker 2: What's your take?
Speaker 3: Well, we're moving from the fog of war to the chaos of the Lapsus attack.
Speaker 1: Lapsus isn't like most of the other packing crews we talk about. You know? They're not state sponsored, but they also don't really operate like the well oiled business machine that comes up a lot in these conversations. There's sort of a looseness to lapses.
Speaker 3: It's a reminder that people can cause chaos and mayhem on the Internet.
Speaker 1: So at first, lapses is kind of confusing. But when you find out who lapses is made up of, it all kinda clicks together. The talent and the ambition balanced against the sort of amateurishness of it.
Speaker 2: A teenager is suspected by cyber researchers of being the mastermind behind this operation, a teenager who still lives with his mom in England.
Speaker 1: And while the City of London police won't say if he's one of them, they did announce that they had arrested a total of seven teenagers associated with lapses. So we're gonna talk about what happened to lapses on this episode of Hacked.
Speaker 4: Can we open this episode with a hint of appreciation for Telegram?
Speaker 1: You a big Telegram guy? I I Like to keep it secure, encrypted?
Speaker 4: I was a big Telegram guy years and years ago, but I will say that, like, it went from being an app that nerds use like me and an app that people use to talk to their drug dealers to now being, like, one of the central feeds for so many things. Like, the whole Russia Ukraine thing, like, there's so many Telegram feeds about what's going on, and, like, it's it's just a I don't know, like, good for them.
Speaker 1: Lapsus likes them some Telegram. That Telegram channel comes up a whole bunch in this story. I think it's it's not just a a platform choice. It's not just sort of how they like to do things. I think it's it's structural, but we'll we'll get to that. Mhmm. The big thing about Lapsus, and it it almost felt nostalgic, for me reading about this because I don't think cybercrime has felt like this for a little while. As I said in the intro, Lapsus is like shit posty. They they have that kind of Internet dicking around, this is all a big joke spirit about everything they're doing. And I think that used to be really, really common in the world of hacking and cybercrime. But over, say, maybe the last decade, it's sort of converged around, no. This is where we do crimes now. This is very serious stuff. There's a bit of humor, but it's not the same way it used to be. Lapses feels like a bit of a throwback in that way. You know? Mhmm.
Speaker 4: They're they're more doing it for the game, less doing it for the money.
Speaker 1: Yeah. There was a there was a Zoom call that one of the companies they had breached. So they breach a company, and they the employees of this company and the external consultants that they brought in to try and solve this data extortion scheme, they'd found themselves embroiled in. They all get in the middle of this call, and right on beat, Lapsus just Zoom bombs the whole call and comes in and starts yelling at them and messing with them on the call where they're trying to solve the hack that Lapsus did about them.
Speaker 4: So these are, like, hackers that grew up in Call of Duty multiplayer games? Like, they're just, like, troll trolls?
Speaker 1: Like, when you picture the, like, the teenagers swatting Call of Duty players.
Speaker 4: Yeah. Yeah.
Speaker 1: And the hacker that they would become, that's not a hypothetical that is an all too like, that's I spoiled something by saying that. So a little timeline. Where did these folks come from? Lapsus showed up super recently, just a couple months ago, originally targeting almost exclusively Portuguese language targets, and they start moving really, really fast. If you missed it, this story takes place on a way more compressed time scale than most of the big, you know, hacking gang cybercrime operations we talk about. All of those hacks I named earlier, every single one of them, and this started a couple of months ago. Instead of years of, like, lurking around in the dark web, Lapsus shows up and is immediately making an extraordinary amount of noise, an almost self destructive amount of noise. Their first big push was in December of last year. You got Brazil's health ministry, the Portuguese media giant Impreza, the South American telecoms giants Claro and Embretell, a Brazilian car rental, like, you know, big consortium Locoleezza. All these big companies in South America, all in about a month get caught up in these data extortion schemes. Mhmm. And like we've been saying, there is an economic element to this. By the end of the story, the guy walks away with 14,000,000 Bitcoin. Walk away, maybe not. But they're making money. But the discretion and the business like approach isn't really there. It's hard to know exactly why they started being so public, but every single one of these hacks has some kind of, Internet y punchline to it. When they hacked LocalEase, so the car rental company, they, just for fun, redirected the main page to a porn website. There's no reason to do that. It doesn't achieve anything in the hack, but they did it anyway. When they hacked, one of the large Portuguese newspapers' Twitter accounts, they just tweeted they just decided to tweet, Lapsus is officially the new president of Portugal. They thought that was funny. I kinda tend to agree. There's no reason to do that. It doesn't make you any more money. You do it because, you know, for the lols. You know what I mean?
Speaker 4: They were just a bunch of hackers truly raised on the modern Internet, not the leftist ideologues of the old hackers, you know, that I like to think of myself as a stalwartov.
Speaker 1: This brave new frontier. And for, you know, a little while, a month or two, they kinda start they're just running ram shot through South American technology companies. In December of last year, they wrote on that Telegram channel, which wasn't up to 45 k yet, but was growing, quote, remember, the only goal is money. Our reasons are not political. Then again, this past February when they were posting about their NVIDIA hack, which we'll talk about, they wrote, please note, again, we are not state sponsored, and we are not into politics at all. Lapsus in so much of their messaging wants you to know two things about themselves. They do not work for any government, and they think all of this is very, very funny.
Speaker 4: They're in it for the lols. I gotta respect it at some level. You know?
Speaker 1: You do. So technically speaking, what is Lapsus doing with all these hacks? Lapsus is sort of unique in this space. They're not quite a ransomware gang. They're an extortion gang. And right out the gate, they seem really committed to refining and figuring out this tactic. So, ransomware, we talk about a lot. It's a malware based hack where you use software to encrypt the victim's data, and if they want it unencrypted, they pay a ransom. It is distinct from extortion, which is lapses this whole thing, Where instead of using hacks to deploy ransomware, you fish your way into the enemy system using a bunch of off the shelf and social engineering tactics. And then once you're in, you just go digging around for the most sensitive information you can find. Once you find it, you steal a copy. The victim still has the data. It's unencrypted, but so do you. And if they don't pay you, the threat is you'll leak it. We've talked about double extortion before, which is combining ransomware and extortion lapses for some reason across all of this, is only concerned with the latter. They haven't locked you out, but they will share the information they have discovered running around in your system. What that means is that the hack only works if they can find something the victim really doesn't want getting out.
Speaker 4: Of course.
Speaker 1: Which, what does that mean for a large tech company? What do large tech companies really not want getting shared?
Speaker 4: I think they call it intellectual property. Sounds sis. Sounds so bad.
Speaker 1: I think they do too.
Speaker 4: I think they call it intellectual property.
Speaker 1: I think they call it IP theft on a massive international scale.
Speaker 5: I think
Speaker 4: they call it all of the thing they spend billions of dollars making.
Speaker 1: I think they call it what every single engineer and developer at a software company damn near has been tasked with creating.
Speaker 4: Yes. And and if it ever gets out, bad things.
Speaker 1: So a lot of their hacks start with the use of password stealing malware. The most common one is called Redline. It's a piece of off the shelf software, lets you get into a a system through a phishing scheme and then start doing that thing where you work your way up the org chart. So they they use password theft off the shelf to get in, and then they start just manually working their way around. The other tactic that they use quite a bit, and it ends up being kind of important to this whole story, is something called a session hijacking. My sense of it from trying to parse it out is it's essentially, what you're doing is you're buying a stolen cookie from a user who uses a website that stores the session ID as a cookie. Like, basically, certain sites will skip forcing you to log in by storing a bunch of your user data in a whole encrypted string in a cookie. Yeah. But that cookie can be stolen and resold and then loaded into another person's browser.
Speaker 4: Yeah.
Speaker 1: So you've got I didn't know this. These whole dark web marketplaces that's only purpose is to sell these token IDs.
Speaker 4: Sell authentication cookies? Exactly. Interesting.
Speaker 1: Where without having their login credentials, you can just load in this little cookie session ID thing and almost, like, wear their session as a mask and pick up the other user session right where you left off. It only works on really specific websites. Sure. But for the right vulnerability, it's apparently super effective.
Speaker 4: Most hacks are on a much more technical level that is relatively low low level. Like, popping a cookie at someone's computer and popping it into another one is pretty pretty tame. But, also, at the same time, probably very, very valid.
Speaker 1: One of the thing that's interesting is you can pop the cookie out of their system, or there's other ways to get it, which we'll talk about.
Speaker 4: Do do do.
Speaker 1: LafSys would buy these cookies, these session IDs, to help them get a foothold into their victim system. But all these tactics, session hijacking, password stealing software, it's all just about getting them in so they can start climbing. So that they can then do one of these data extortion schemes, every single time the same bit. So, Lapsus cooks up this tactic. They fish their way in, and they start beta testing this tactic in South America in December of last year. And right when they kind of get it figured out, they get their feet under them, they turn their view to the rest of the world, and their ambitions spanned. Once they leave South America, and expand globally, I'm just gonna rattle them off because these like, these hacking teens just go on a golf cart crime spree for the next two months.
Speaker 4: It's a terror.
Speaker 1: Just a Like that. Rip. You've got, NVIDIA, Microsoft, Samsung, Ubisoft, and that's not even including the biggest one. So in mid February, Lapsus breaches NVIDIA.
Speaker 6: Dan, let me bring you in here. A compelling new lineup from NVIDIA, but I understand you also talked with Jensen on the Lapsus hacking gang.
Speaker 7: That's right, Brian. We talked to him about Lapsus, which has broken into not just NVIDIA, but Samsung, Microsoft, and apparently Okta.
Speaker 1: Earlier, we chatted about, you know, the kind of information a large corporation would pay some money to keep private. Lapsus gets into NVIDIA system and lifts a terabyte of data, including the, incredibly sensitive information about the designs of their graphics cards, the source code for their AI, rendering system Yeah. The usernames and passwords of more than 70,000 employees, all of which they threatened to drop if NVIDIA doesn't meet their demands.
Speaker 4: What was their demand, Jordan?
Speaker 1: Their demand was to remove a, anti crypto mining feature called light hash rate from their GPUs. So they didn't want NVIDIA's money. Sure. They wanted them to remove a lock that said you can't mine crypto with their stuff.
Speaker 4: Sure. Well, that's a pretty pretty forceful negotiating tactic.
Speaker 1: It sure is. And it's just interesting to me because you you spend all this time cooking up, cooking up a way to get big companies to pay you, and then you have managed to hack someone that has a you got kind of a customer service gripe with it. You figure, hey. Why not? While we got them here, maybe you let me mine some crypto with your graphics cards, please.
Speaker 4: Yeah. No kidding. Or we're gonna tell the world how to make your graphics cards. You know? Your choice. Somebody somebody's gonna release a version of your graphic cards without the lock if we give this public information away. So
Speaker 1: Maybe someone just hacks a way to do it. Exactly. Release the the source code for these things.
Speaker 4: That's very true.
Speaker 7: This is something that, you know, is incredibly concerning, obviously. And Jensen Huang basically said to us, look. This is something, of a wake up call, and they wanna move their entire business structure to what's called a zero trust structure. Now just to give you an understanding of what that means, essentially, it means that nobody in the company can be trusted. No. You automatically assume that whoever is trying to access any files, within the company itself or any of the company's networks, is a potential threat. And so you make them go through, these different types of login processes to ensure that they aren't.
Speaker 1: They hack NVIDIA, but they're just getting started on their tour through PC gaming. Next up, you get Microsoft. Early on a Sunday morning in March, Lapsus posts the screenshot to their Telegram channel, their increasingly popular Telegram, saying, guess what? We just hacked Microsoft's Azure DevOps server, which contains the source code for Bing, Cortana, and Office. Monday night of that same week, they drop a torrent with a nine gigabyte zip file with over source code for over two fifty projects. But hey, the month is young. Maybe Microsoft and NVIDIA still isn't enough. Well, buckle up, because next up comes Samsung. Shortly after that, they drop a 200 gigabyte file, a bunch of IP relating to their mobile devices, which Samsung is a big company. Mobile devices is about the worst thing that could probably get leaked. I don't really care if my smart TV or my fridge, but, you know, my mobile phone, I would prefer the source code for that not be out there in the world.
Speaker 4: No kidding.
Speaker 1: Which it was. 200 gigabytes, the algorithms for all of their biometric unlocking operations, bootloader source code for all recent Samsung devices, Qualcomm gets wrapped up in it, their confidential source code, and a bunch of authorization tools for the actual Samsung account. And as of today, there are more than 400 people sharing that file. It is incredibly popular. Lots of seeders. No leechers. You can download it right now. Oh my god. Within a month, NVIDIA, Microsoft, Ubisoft, who I didn't even mention, Samsung. This all starts in late February and goes through to late March. All of that in about thirty days. And a crescendos with the big one, which is a company, I'm not sure if you've heard of it, Scott, called Okta?
Speaker 4: Of course. Okta Verify.
Speaker 1: Okta Verify. For anyone that doesn't know, broadly speaking, what is Okta?
Speaker 4: It's like a very fancy, Google Authenticate. Mhmm. It is a like a secondary authentication service that you run. Yeah. It's all time based. Requires a bunch of back and forth to verify that you're on your device, you're in a specific location that you're not trying to mitigate and reduce the the chances that something is going awry in your login.
Speaker 1: And it's super popular by really large corporations that will use it to manage all of the logins of all of their many employees, Peloton, Sonos, T Mobile, the FCC. We've got, like, 17,000 customers. And the thing that's cool about it from the little bit of reading I did is, you know, like a lot of sort of identity management platforms is it it really reduces the attack surface of a giant corporation. If you've got 10,000 people each using 20 different services in their job, each with its own password and username, the attack surface, the big area where a hacker can try and get in is giant. Okta shrinks it down to one login, makes it a lot easier. Mhmm. But that only works as long as Okta is very, very secure, which it typically is. Until at the end of March, Lapsus posts a screenshot to their Telegram channel showing them in control of a Okta administrative or superuser account, which is not great news.
Speaker 4: For the world and for all of the people, like, that care about intellectual property because they all use Okta.
Speaker 1: And for Okta's CEO, Todd McKinnon, who gave a quote in January 2022. We, we detected an attempt to compromise the account of a third purse a third party customer support engineer working for one of our subprocessors. We believe this screenshot, is connected to that January event, which is interesting because Okta would be the ultimate get for a supply chain attack, which we've talked about in the show. It's when you, you know, hack your way into a victim by hacking someone else and riding in on the bottom of their shoe. And it sounds like the way that Okta got attacked was itself a supply chain attack. They rode in on the bottom of someone else's shoe. The question then became, did they ride into anywhere else once they had the superuser access?
Speaker 4: RSA key fobs used to be like the the kind of original super control switch for big corporations. You know, those little digitized numbers that rotate on your key chain.
Speaker 1: Mhmm.
Speaker 4: And I feel like Okta has wholesale has given I shouldn't say replaced because those are so super secure, but have have given or or try to offer a similar solution, but to pretty much every user in a domain rather than the 10 most important. It used to be, you know, if you had access to the to the accounting records, you needed the RSA key fob to get access to it. But now, pretty much everybody in the corporation can have an Okta single sign on verification account. So it's it's trying to just elevate the base level of of access control for everybody. But then again, if that gets violated, you've kind of violated everybody rather than just a few accounts. So
Speaker 1: And it's really hard to know what exactly Lapsus got out of this this, you know, breach implied by the screenshot.
Speaker 4: For sure.
Speaker 1: They make so much noise and say such crazy crap. It's really hard to tell exactly what's true and what's false. Okta, by all accounts, was incredibly on this. Of course. The thing I find interesting about it, and you've you've told me about this and talked about it, is that there's a reason you don't post about a hack while it's happening. You draw attention to yourself, they know you're there. The lights are on, they shine a spotlight on you, you gotta scurry away, right? Mhmm. And this is just me speculating. They might have gotten nothing from this access they had within Okta. Of course. But it seems really relevant to me that the screenshots are from January, and they didn't share them until late March. And in between, they went on this extraordinary run of hacks in an incredibly compressed time frame. Yeah. And it's hard not to kinda wonder if that run Yeah.
Speaker 4: It correlates.
Speaker 1: And the access they had to Okta weren't in it's probably not one to one. I'm sure it isn't. But maybe they juice this access for everything it was worth. Once that fruit was dry, they got that one last little drip by publicizing it to their channel, and we get to watch everybody panic. You gotta wonder.
Speaker 4: The yeah. Like, I I don't know enough about the Okta systems to to know what what that would do. But if it like, the the speed and velocity at which they were
Speaker 1: Mhmm.
Speaker 4: Hacking and releasing things, like, either they are the world's best fishers or or if they had an extra layer of attacks and a layer of access, like, man. Like, I I can see how you draw those two correlations. But
Speaker 1: Mhmm.
Speaker 4: Because I'm sure a substantial amount of the people that were violated probably could have been running Okta. And I'm sure I'm sure I don't know if that would be disclosed as per you know? I'm sure Okta has it Doesn't want to disclose much more than that. So
Speaker 1: The last of these headlines, you know, the last punch of publicity from this crime spree is March 22. It ends with Okta. And then two days later, on March 24, there is a different headline. The last one we're gonna talk about. And this one isn't about a hack. It's about that arrest. That headline, right after the break. Starting some new isn't just hard. It can be downright terrifying. You put a lot of work into a thing. You're not entirely sure it's gonna work out. You're taking a huge leap of faith. I've started a few things. Now I know I was right for believing in, you know, the idea, the product, despite all of those fears and hesitations. But boy, does it sure help when you have a partner like Shopify on your side. Shopify is the commerce platform behind millions of businesses around the world and 10% of all e commerce in The US. From household names like, well, hacked podcasts merch, to brands just getting started, you can get started with your own design studio with hundreds of ready to use templates. Shopify helps you build a beautiful online store that matches your brand style. Did I mention that that iconic purple shop pay button is used by millions of businesses around the world? I don't know why I wouldn't. I should. It's why Shopify has the best converting checkout on the planet. It also helps boost conversions, meaning less carts, sort of getting abandoned in the parking lot, and more sales for you. It's time to turn those what ifs into sign up for your $1 per month trial at shopify.com/hacked. Go to shopify.com/hacked. One more time, that's shopify.com/hacked.
Speaker 8: Whatever your thing, it could be anything. Canva helps you make that thing a thing. Canva is a simple online tool thing. It's a way to design with our magic AI tool things. You can social media your thing, generate images or videos of your thing, Make decks for presentations to show your thing. Whatever needs to be done for your thing, Canva can make it an even better and bigger thing. Canva, the thing that makes anything a thing.
Speaker 5: No one goes to Hank's for his spreadsheets. They go for a darn good pizza. Lately though, the shop's been quiet, so Hank decides to bring back the $1 slice. He asks Copilot in Microsoft Excel to look at his sales and costs and help him see if he can afford it. Copilot shows Hank where the money's going and which little extras make the dollar slice work. Now Hanks has a line out the door. Hank makes the pizza. Copilot handles the spreadsheets. Learn more at m365copilot.com/work.
Speaker 1: So Microsoft
Speaker 9: You have one new message. Translating. Disney and Pixar's Hoppers is now available on Disney plus.
Speaker 1: You could say that again.
Speaker 9: Critics are calling it Pixar's funniest movie ever and a wildly entertaining ride. Blizzard potato is certified fresh and verified
Speaker 1: hot.
Speaker 3: Now we party.
Speaker 10: This is incredible. Wow.
Speaker 1: I am clearing the rest of the day.
Speaker 9: Disney and Pixar's Hoppers, now available on Disney plus rated PG.
Speaker 1: Soft had been tracking lapses for a while. They gave them the very, like, Microsoft y designation of dev o five three seven. It was a big long string. And their research prior to these arrests on March 24 charts the various pseudonyms used by this ringleader. It was by White and Breachbase. And the important one here is the name White Doxman, which he used on one site in particular, and it teases how all of this unravels. White Docksman? He uses the name White Docksman on the website docksbin,d o x
Speaker 4: b I n. Oh, Docksbin. I thought you meant Docksman as in, like, somebody who mans a dock. A Docksman. What a weird name. Docksman.
Speaker 1: He's a sailor themed tacker. Dockspin is a website. It's essentially a doxing forum.
Speaker 4: Yeah. Yeah.
Speaker 1: Yeah. Anyone can post the personal information of a target. You can go digging through these archives of hundreds of thousands of people that have been doxed. It's terrifying. And about a year earlier, someone bought Doxxbin. It had a new owner. And I guess shortly after this new owner takes over, the community starts to revolt as the new owner wasn't running things the way they had been. And the community at Doxxbin is getting angry at their new owner, white Doxxbin, the ringleader of Lapsus. So people are getting angry, and finally, White Dockspin says, I'm out. I got Lapsus to run. I don't need the headache of owning Dockspin two. So in January 2022, right during this crescendo of hacks, the new owner, White Docspin, agrees to relinquish control and sell the site at a pretty brutal loss. Where he messes up is right before he gives up control. White Docspin made the choice to leak the entire Docspin dataset, including, like, unpublished draft versions of doxes, to their public Telegram channel. He decides as he's walking out the door,
Speaker 4: To burn it.
Speaker 1: To give away all of Doc Spin's stuff to burn it behind him. And the community, the Doc Spin community is livid. And they respond in the way that you might expect a doxing site to respond. They dox him really, really badly. The first thing up, I think, wasn't even his name. It was a video shot outside of his home in The United Kingdom. Yeah. And then his name, and then his address, and then all of his personal data about this guy, Y. Doxben, the ringleader of Lapsus, who was 16. Wow. We find out in this moment that he'd been up to some stuff before all of this. He had founded another hacking gang called Recursion Team, and you teased what they did earlier. They they got in at the ground level. They they started with, like, not even hacks, SWAT attacks, fake bomb threats, teenager stuff. And then they graduate up to doing SIM swaps, and then they graduate up to doing the more social engineering stuff.
Speaker 4: Yeah.
Speaker 1: And they start making money. And he starts reinvesting the money, turning Lapsus into this, you know, bringing new people in and turning it into this very well publicized hacking crew. In the span of less than a year, just a couple months. Until his relationship with Doxman goes south end of March, and they dox him. On March 24, the city of London police arrest seven people between the ages of 16 and 21 in connection with lapses. And the wild part is they were all released because the doxing isn't evidence. It's incredibly incriminating, but it's not evidence. But the name, the the real IRL name of breach based White Oxford, now it's out there. So you've got journalists who who will not publish the name because the suspect is minor.
Speaker 4: Of course.
Speaker 1: But they will go visit his parents, his very confused parents, and ask very intense questions about the very intense future of their potentially hacker son's very intense life. 16. But there's this one other tactic they use that I think reframes some of this. So a month ago, that lapses Telegram channel, 45,000 members. One day, an ad goes up on the channel, and it's a recruitment ad, recruiting insiders at major mobile phone providers, large software and gaming companies, saying, we're gonna pay you $20,000 a week to be our inside person, to sell us your cookie session ID. And suddenly, that infamy, that channel with nearly 50,000 people in it, we see that it has a purpose. Mhmm. Because up until just two weeks ago, at this point, when you're reading it, this isn't teenagers trying to steal crypto. It is the very infamous and successful cybercrime operation, Lapsus. Give them a Google, and you'll see a ton of headlines. And that infamy that he fostered by making all this noise and having this big public channel, the infamy lends them authority.
Speaker 3: It's a reminder that people can cause chaos and mayhem on the Internet even if they're not connected to politically motivated objectives, even if some of their methods are laughable. So that's a critical reminder of our vulnerabilities and the need to clean up our digital environment.
Speaker 1: So where does that leave Lapsus? Lapsus didn't go away. A week after all of that went down, after their ringleader got arrested, they then posted a message on the telegram saying, back from vacation. Along with a 70 gigabyte torrent of more data allegedly stolen from another giant company. This time it was consulting giant Globant. So, whoever these teens that were arrested are, well, it's either one of two things. Either they're back at it really, really quickly from their family homes, or the rest of Lapsus, however old they are, is perfectly happy and capable to continue on without them. And who knows, was maybe around before those seventeen's in The UK joined. Which opens the door for the possibility that these 17 agers in The UK got involved with a pre existing hacking ring, swung crazy big, helped hack some of the world's biggest companies, and then got doxxed. And now it's on the news. But, as with all this stuff, it's tricky from the outside to tell what's going on in there. So last episode, we talked about virtual kidnappings, and we talked about how they work, and we speculated about how you could make them even more efficient crimes. But one commenter, noted we did actually talk about how to avoid them. We we kinda did, but I take your point. So just very briefly, there's no real way to stop these folks from calling you, but the what is it? The Internet crime complaint center has some best practices. And there it's a lot of the stuff we said in the episode. Step one, slow down, take a breath, get your feet under you. Step two, just contact the victim entirely. Like, just contact them. Call them, text them. That would have solved the episode's whole story. Step three, it's a kind of a kidnapping classic. It's the ask them something only the victim would know. The the formal version of it is if it's your child, you should have a secret password, which is something that we did when I was a kid. Did you really? As an adult. Yeah. No. That was a I think that was a thing in the nineties where there's a lot of, you know, your child's going to get kidnapped. Tell them a password so that they can check to make sure that I don't know. The nineties was a weird time.
Speaker 4: Verify it's the real person.
Speaker 1: Yeah. I remember my parents, they must have seen a spooky thing on the TV, and they they were like, your secret password is this. And I was like, cool. What are kidnappers? I'm six. What is this premise? I don't like any of this. And the step four is just report it to the Internet crime complaint center. So we left you hanging a little bit on that one. That's what you should do about virtual kidnappers.
Speaker 4: Yeah. Sorry. We're in the business of scaring, not solving.
Speaker 1: Maybe you got a new podcast description.
Speaker 4: In the business of scaring, not not solving. There's too many too many crimes out there for us to even consider solving.
Speaker 1: No. We just talk about them. Spicy takes.
Speaker 4: Spicy takes.
Speaker 1: Thanks for listening everybody. This was a fun one. This episode contained research and archival audio from News Nine Live, Bloomberg News, BBC Wired, silentpush.com, gizmodo.com, and vice.com. Shout out to our new patrons on Patreon. Patreon.com/hackedpodcast. Single best way to support the show. Brandon Vogt. Thanks, buddy. Crohn's. Thanks. It's it's a pleasure to have you. James Naysmith. It's good. Welcome to the club. Get on in here. Open the door. It's nice inside. Jimmy, you edited your pledge. You gave me more. I appreciate that. Thank you. Incredibly generous. Thank you so much to everyone who listens, so everyone's kept listening. This is, you got you got a mid month er. We're trying something new here. We're trying to make more of these bad boys. We hope you enjoyed it. Thanks again for listening. Tell some folks about the show, and we'll catch you in the next one. Cheers.
Speaker 10: Have no fear. Chosen Foods is here to defend your favorite foods from the forces of seedy oils and sketchy ingredients. With cooking oils, salad dressings, and mayo, all powered by the good fats from 100% pure avocado oil and simple delicious ingredients. Chosen foods.
Speaker 11: Athletic Brewing Company crafts award winning nonalcoholic beers for those who wanna be part of every round. With over 185 flavor awards, they're exceptional NA beers that fit your lifestyle and any social occasion. Summer's full of good times and athletic fits right in. Go to athleticbrewing.com to have brews delivered to your door or find them at a bar, restaurant, or store near you. Near beer, athletic brewing company fit for all times.
Speaker 12: Ryan Reynolds here for Mint Mobile. I don't know if you knew this, but anyone can get the same premium wireless for $15 a month plan that I've been enjoying. It's not just for celebrities. So do like I did and have one of your assistant's assistants switch you to Mint Mobile today. I'm told it's super easy to do at mintmobile.com/switch.
Speaker 13: Upfront payment of $45 for three month plan, equivalent to $15 per month required. Intro rate first three months only, then full price plan options available. Taxes and fees extra. Fee full terms at mintmobile.com.