zerofox logo
Threat Intelligence

Flash Report: Lapsus$ Group Announces Resurgence 

by ZeroFox Intelligence
Flash Report: Lapsus$ Group Announces Resurgence 
6 minute read

Key Findings

  • On September 10, 2026, threat collective Lapsus$ Group posted a message on its leak site declaring a "Chapter II" return from retirement and stating an intent to directly target the Federal Bureau of Investigation (FBI).
  • The group's Chapter II announcement likely serves as an official declaration of its reactivated operations and likely indicates that fresh cyber offensive actions are already taking place. 
  • The leak site's "Upcoming Target" listing describes a global company generating more than USD 50 billion in annual revenue, with a countdown clock that showed roughly 10 days remaining as of the writing of this report.
  • The Chapter II announcement very likely marks a genuine, ongoing resumption of Lapsus$ Group’s offensive operations and will likely garner substantial near-term media coverage given the collective’s name reputation and recognition among security teams and the general public.

Details

On September 10, 2026, threat collective Lapsus$ Group posted a message on its leak site declaring a "Chapter II" return from retirement and stating an intent to directly target the FBI. This statement is paired with a leak site countdown clock referencing a new, as-yet-unnamed victim company the group describes as generating more than USB 50 billion in annual revenue.

  • The message was PGP-signed by the group, which is typically done by threat collectives to dispel authenticity concerns. It is the same authenticity marker Lapsus$ Group has used historically to validate its claims1. Despite this, there is a roughly even chance that the message is from a reorganized successor or an unrelated actor using a high-profile name.
  • Lapsus$ Group was part of the Scattered Lapsus$ Hunters (SLH) alliance responsible for several prominent ransomware and digital extortion (R&DE) attacks and doxxing campaigns targeting law enforcement last year. The group announced a temporary dissolution in October 2025 following law enforcement operations.

The group's Chapter II announcement likely serves as an official declaration of reactivated operations and likely indicates that fresh cyber offensive actions are already taking place. The statement frames the prior hiatus as a deliberate pause rather than a retreat forced by law enforcement pressure, while explicitly identifying U.S. federal law enforcement as a target of Lapsus$ Group’s renewed campaign.

The explicit focus on the FBI likely functions as a reputational and recruitment signal and increases the likelihood of retaliatory harassment or doxxing campaigns directed at law enforcement personnel and their families. The tactic is a continuation of an observed pattern in which the collective's members and affiliated groups have used public taunting of investigators—very likely to draw attention and elevate their standing among their cybercriminal peers. Prior enforcement actions against individuals connected to Lapsus$ Group have not ended the brand's activity, and its own framing treats those losses as the cost of doing business rather than a deterrent.

  • Lapsus$ Group’s statement closes by addressing incident response teams and federal managers directly, extending its intended audience beyond a single victim organization2.
  • Law enforcement in the United States, United Kingdom, and Brazil have previously arrested individuals tied to the collective, and the group's own post treats those losses as an acceptable operating cost3.
  • The collective's public taunting of federal agencies mirrors tactics used by its affiliate groups since at least 2022, when members openly mocked corporate security teams during earlier campaigns4.

The Chapter II declaration demonstrates the group’s persistence, as observed in the March 2026 claimed breach of French luxury retailer Lacoste SA by actors using the Lapsus$ name, which compromised employee records and internal business systems roughly three years after the group's original wave of high-profile intrusions. That incident, and the broader history of extortion brands surviving arrests through splintering or the reactivation of dormant members, likely indicates that prior law enforcement action degraded the group's visibility, not its capability.

  • The Lacoste breach, published March 1, 2026, compromised employee databases, CRM platforms, and SAP enterprise systems, though the full scope of affected records has not been publicly quantified to date.
  • The Lacoste incident very likely indicates that the 2022–2023 arrests of several Lapsus$ Group members were insufficient to permanently neutralize the operation, a conclusion the Chapter II announcement now reinforces directly5.

The collective paired its Chapter II statement with an active countdown clock toward a new disclosure, likely indicating the announcement reflects an operational restart already in progress. The pairing of a public statement with a live countdown clock mirrors a promotional pattern Lapsus$ Group has used in the past to build anticipation ahead of a release.

  • The site's "Upcoming Target" listing describes a global company generating more than USD 50 billion in annual revenue, with a countdown clock that showed roughly 10 days remaining as of the writing of this report.

The Chapter II announcement very likely marks a genuine, ongoing resumption of Lapsus$ Group’s offensive operations and will likely garner substantial near-term media coverage given the collective’s name reputation and recognition among security teams and the general public. This likelihood is heightened by the group's established record of high-impact intrusions spanning the technology, telecommunications, and financial sectors. Furthermore, Lapsus$ Group’s explicitly stated plan to target the FBI significantly increases the likelihood of secondary campaigns by its affiliated groups or other cybercriminals targeting law enforcement. 

Organizations in the sectors Lapsus$ Group has previously targeted, along with any entities whose personnel could be impacted in law-enforcement-directed campaigns, should treat the collective’s Chapter II announcement and countdown clock as an active rather than hypothetical threat. Heightened media traction is likely and consistent with Lapsus$ Group’s public profile, which is likely to amplify pressure on the collective’s named or teased victims independent of the technical severity of any single intrusion.

Appendix A: Traffic Light Protocol for Information Dissemination

Appendix B: ZeroFox Intelligence Probability Scale 

All ZeroFox intelligence products leverage probabilistic assessment language in analytic judgments. Qualitative statements used in these judgments refer to associated probability ranges, which state the likelihood of occurrence of an event or development. Ranges are used to avoid a false impression of accuracy. This scale is a standard that aligns with how readers should interpret such terms.

  1. hXXps://lapsus[.]ar[.]io/ ↩︎
  2. hXXps://lapsus[.]ar[.]io/ ↩︎
  3. hXXps://www.gblock[.]app/articles/lapsus-return-lacoste-luxury-brand-ransomware ↩︎
  4. Ibid. ↩︎
  5. hXXps://www.gblock[.]app/articles/lapsus-return-lacoste-luxury-brand-ransomware ↩︎

Tags: Threat Intelligence

See ZeroFox in action