
What happened
Between January and March 2022, a loosely organized group publicly known as Lapsus$ intruded into a series of large technology and telecommunications companies. Rather than relying on custom malware, the group is described in Microsoft's contemporaneous account of the actor it tracked as DEV-0537 as buying stolen credentials, paying employees or contractors for access, and using SIM-swapping to intercept one-time codes. In August 2023, the Department of Homeland Security's Cyber Safety Review Board published its review of the group's intrusions, confirmed as posted by CISA's resource page on 10 August 2023. The review found that organizations' reliance on SMS- and voice-call-based multi-factor authentication, and on telecommunications carriers' own account-security practices, left a gap the group repeatedly exploited through SIM swaps and through calls to corporate help desks impersonating employees. The board also described push-notification fatigue, in which repeated authentication prompts eventually produce an accidental or exhausted approval, as a related technique the group and similar actors used.
Confidence and limits
The review is an official federal assessment based on interviews and material the board says organizations voluntarily shared; it does not name most affected companies, citing its confidentiality commitments, so specific intrusion details beyond what companies separately disclosed are not independently checked here. The board's central finding, that SMS and voice MFA implementations broadly in use were not sufficient, is a considered judgment rather than a measured failure rate, and it does not quantify how many organizations remain exposed.
Why it mattered
Lapsus$ was notable less for technical sophistication than for showing how far identity and help-desk weaknesses could carry an attacker against companies with substantial security budgets. The review's recommendations pushed beyond individual organizations to carriers and regulators, calling for the Federal Communications Commission and Federal Trade Commission to address SIM-swap protections and for a federal move toward phishing-resistant authentication standards, treating the problem as partly a telecommunications and identity-infrastructure issue rather than one any single company's security team could fully solve alone.
Defensive takeaway
Review whether any account recovery or step-up authentication path in your organization still depends on SMS, voice calls, or a help-desk agent's judgment during a live phone call, since each is a path the board found attackers had already used at scale.
- Can a help-desk agent reset a privileged account's credentials or MFA enrollment based on a phone call alone?
- Does your MFA implementation resist a flood of repeated push prompts, or does it eventually get approved by habit?
- Would a SIM swap on an executive's or administrator's phone number grant access to anything beyond that phone number?
The board's report does not claim these gaps are closed. It documents a pattern across many organizations at one point in time and argues that closing it requires coordinated action beyond any single security team, which is a different kind of finding than a conventional incident postmortem.
Check whether any help-desk process or SMS-based recovery path in your organization could grant access on a phone call or intercepted text alone, and prioritize moving privileged accounts to phishing-resistant authentication.
The Cyber Safety Review Board's report is an official federal assessment based on voluntary industry cooperation; it withholds most victim names by design, and its finding that SMS and voice MFA are broadly insufficient is a considered judgment rather than a measured failure rate.
Sources & reading trail
The Cyber Safety Review Board's account of Lapsus$'s methods, its finding that SMS and voice MFA implementations collectively failed, and its recommendations including a shift to phishing-resistant authentication.
government-primary · Source published: 10 August 2023 · Retrieved: 16 September 2026
Confirms CISA's 10 August 2023 release date for the CSRB report.
government-primary · Source published: 10 August 2023 · Retrieved: 16 September 2026
Microsoft's contemporaneous description of the same actor's social-engineering and SIM-swap-enabled tactics and its own recommended mitigations.
vendor-primary · Source published: 22 March 2022 · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.