IT and software developer Globant says its code repo was partially breached, after Lapsus$ shared 70GB of allegedly stolen data; Globant's stock closed down 10%
The Lapsus$ data extortionists are back from a week-long … Pierluigi Paganini / Security Affairs : Lapsus$ extortion gang claims to have hacked IT Giant Globant Dora Tudor / Heimdal Security Blog : IT and Software Consultancy Company Globant Got Hacked Jonathan Greig / The Record : Globant confirms reports of breach after Lapsus$ shares 70GB of stolen files Karandeep Oberoi / MobileSyrup : New Lapsus$ data breach compromises 70GB of Globant's client data Joseph F. Kovar / CRN : Globant Source Code Breached As Lapsus$ Strikes Again iTnews : ‘Back from vacation’ - Lapsus$ hackers claim breach of Globant Kyle Alspach / VentureBeat : Lapsus$ is clearly not done leaking Claudia Glover / Tech Monitor : Is Lapsus$ back for good after Globant breach? Tweets: Dominic Alvieri / @alvierid : Facebook, DHL, BNPParibas, Abbott... Lapsus$ making a statement post which needs to be verified. @campuscodi @vxunderground #cybersecurity #infosec #Lapsus https://twitter.com/... https://twitter.com/... Cher Scarlett / @cherthedev : oh boy https://twitter.com/...
Context & Ripple Effects
Lapsus$ had already been tied to an employee-focused intrusion model in a profile of the group’s social-engineering tactics, alongside confirmed access to an Okta engineer’s laptop and a single-account compromise at Microsoft that exposed portions of source code. Globant extends the run of incidents from identity and software vendors into an IT-services provider with client data at stake.
The market reaction makes the exposure more than an internal security event: a code-repository breach can affect both Globant’s own development assets and confidence among the clients whose data was exposed.
First-order effects
- Globant must contain and assess the partial repository breach and the reported client-data exposure while responding to data already shared by Lapsus$.
- Globant’s 10% stock decline immediately puts the incident into view for investors as well as affected clients.
Second-order effects
- Clients will need to assess whether exposed data or development materials create risks in their own projects, increasing pressure on Globant to clarify the scope of exposure.
- The sequence of Lapsus$ incidents raises the priority of controls around employee access to source code and identity systems, following the Okta engineer-laptop compromise.
Third-order effects
- If source-code theft continues across software makers, service providers and telecom projects, development repositories become a more central target in data-extortion campaigns rather than a secondary asset.
- The pattern favors security programs that treat identity access and the software-delivery environment as connected controls, not separate operational domains.
The trend: Data extortion is expanding from stealing customer records to targeting the employee access and code repositories that underpin software delivery.