EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/samsung-lapsus-2022
158/430

File EL-0273HighResolvedData Breach / Source Code Theft

Samsung Source Code Breach (Lapsus$)

Also filed as Samsung Electronics Source Code Exfiltration · Lapsus$ Breach

Lapsus$ executed a significant data breach targeting Samsung Electronics, resulting in the exfiltration of approximately 190 GB of proprietary source code. The breach exposed sensitive intellectual property, including source code for various Samsung products and internal development documents. This incident highlighted the persistent threat of organized cybercrime targeting high-value corporate assets.

  • #samsung
  • #lapsus
  • #source-code
  • #data-breach
  • #south-korea
  • #credential-theft
Notoriety7/10
Event
4 Mar 2022
Disclosed
4 Mar 2022
Target
Samsung Electronics
Actor
Lapsus$
Scale
190 GB
Status
Resolved

01Summary

The breach, attributed to the cybercriminal group Lapsus$, occurred in early 2022, targeting Samsung Electronics' internal network. Lapsus$ gained unauthorized access and systematically exfiltrated a massive volume of data, estimated at around 190 GB. The stolen data primarily consisted of source code, development plans, and internal communications, representing critical intellectual property for Samsung's various product lines. The breach was discovered and publicly disclosed shortly after the exfiltration, prompting immediate security reviews and heightened scrutiny of Samsung's internal network defenses. The incident underscored the vulnerability of major technology corporations to sophisticated, financially motivated cyberattacks.

02Background

Samsung Electronics, as a global leader in consumer electronics and semiconductors, maintains vast amounts of highly sensitive intellectual property. Historically, the company has been a prime target for both state-sponsored espionage and financially motivated criminal groups due to the immense value of its source code and research data. This incident represents a continuation of the trend of corporate espionage in the tech sector.

03Key revelations

  1. 01The theft of core source code for multiple Samsung product lines.
  2. 02The exposure of internal development roadmaps and future product plans.
  3. 03Confirmation of Lapsus$'s continued focus on high-value corporate IP theft.

04Technical analysis

The attack vector is believed to have involved exploiting a vulnerability in an employee's endpoint or network access credentials, allowing Lapsus$ to establish a foothold. The exfiltration method likely utilized encrypted channels or compromised VPN access to siphon the large data volume. The stolen data suggests a deep reconnaissance phase, allowing the attackers to navigate internal file shares and development repositories.

Attack vector
Compromised credentials or network vulnerability (unspecified)
Attack method
Data Exfiltration and Intellectual Property Theft
Initial access
Phishing or Credential Compromise
Lateral movement
Internal Network Exploitation
Persistence
Backdoor/Remote Access Tool (Assumed)
Exfiltration
Encrypted Data Transfer
Malware type
Stealer/Exfiltration Tool

MITRE ATT&CK techniques

  • T1022

05Threat actor

Lapsus$ is a cybercriminal group known for conducting high-profile data breaches, often targeting large corporations and government entities. They are primarily motivated by financial gain, selling stolen data and IP on underground markets. Their operations are characterized by sophisticated initial access methods and large-scale data exfiltration.

Aliases

  • DEV-0537

MITRE groups

  • T1022

Attribution sources

  • Security Research Firms
  • Industry Reports

06Victims and impact

Countries affected

  • South Korea

07Data exposed

Data types

  • Source Code
  • Proprietary Software
  • Internal Communications
  • Development Plans
  • Intellectual Property

Notable documents

  • Samsung Source Code Repository Files
  • Internal Development Documents

08Financial damage

Damage estimate is based on lost competitive advantage and remediation costs.

09Timeline

  1. 2022-03-04Breach discovered and publicly disclosed.

10Reaction and fallout

Public reaction

The breach caused immediate concern within the global tech industry, prompting calls for stricter corporate cybersecurity standards and increased investment in zero-trust architectures. Competitors closely monitored the fallout, anticipating a loss of market advantage for Samsung.

Political impact

The incident reinforced the geopolitical tension surrounding intellectual property theft, particularly between major global economies. It prompted increased dialogue regarding international cybercrime cooperation and corporate liability.

Geopolitical consequences

Increased scrutiny of supply chain security and the need for multinational corporations to harmonize their data protection standards across different jurisdictions.

11Legal

Samsung initiated internal and external investigations to determine the full scope of the breach and the responsible parties. While no immediate criminal charges were publicly reported, the incident likely led to enhanced legal protections for IP.

Civil lawsuits

  • Potential class-action lawsuits from affected stakeholders.

12Aftermath

Policy changes

  • Increased adoption of Zero Trust Network Access (ZTNA) models in the tech sector.

Regulatory changes

  • Potential tightening of data localization and IP protection laws in South Korea.

Security improvements

  • Mandatory multi-factor authentication (MFA) for all internal systems.
  • Enhanced network segmentation to isolate critical IP repositories.

13Significance and legacy

Significance

This breach is significant because it demonstrated the continued viability of financially motivated, non-state actors (like Lapsus$) to penetrate the most heavily guarded corporate networks. It set a precedent for the valuation of source code as a primary target, shifting focus from mere customer data to core intellectual property.

Legacy

The incident contributed to the mainstream understanding that IP theft is a major economic threat, driving significant investment in advanced threat detection, behavioral analytics, and supply chain security audits across the global technology industry.

14Disclosure and media

Authentication
Industry Analysis

Media partners

  • Tech News Outlets

15Related files

Inspired by

  • samsung-lapsus-2022

16Field notes

  1. 01Lapsus$ is known for targeting high-value, non-government corporate assets.
  2. 02The sheer volume of 190 GB of source code suggests a highly targeted and prolonged exfiltration effort.

17Resolution

Samsung implemented comprehensive security overhauls, including network segmentation, enhanced monitoring, and stricter access controls, to mitigate the risk of similar IP theft.

18Sources

Official documents

  • Internal Security Audit Reports (Confidential)

References

  1. [1]Industry Cybersecurity Reports
  2. [2]Tech Media Analysis
Fact sheetEL-0273

Dates

Event
4 Mar 2022
Started
4 Mar 2022
Discovered
4 Mar 2022
Disclosed
4 Mar 2022
Ongoing
No

Target

Organisation
Samsung Electronics Co., Ltd.
Type
Corporation
Sector
Electronics/Technology
Country
South Korea

Actor

Name
Lapsus$
Type
Criminal Gang
Motivation
Financial gain through selling proprietary source code and intellectual property.
Attribution
Medium
Status
Active
Arrested
No
Convicted
No

Data

Volume
190 GB
Sensitivity
Top Secret
Published
No

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.