Executive Summary:
On 9 September 2026, Securonix ThreatWatch team began tracking lapsus.ar[.]io after the site appeared online carrying "LAPSUS$ GROUP - CHAPTER II" branding. At the time of review, the site used "LAPSUS$ GROUP - CHAPTER II" branding and displayed a countdown to 12 September at 22:00 UTC. It published a clear-signed statement, linked the associated OpenPGP public key, and pointed visitors to a profile on a disputed BreachForums successor. The statement thanked TeamPCP for its "sacrifice," challenged the FBI, and claimed the group would resume extortion activity with a "first victim leak."
We independently verified the OpenPGP signature. It validates against fingerprint 7D0FA2E212E398576C797102131C4FF38C4D936B, confirming that the statement was signed using the private key associated with the published public key. We also traced the site's publication sequence through ArNS and Arweave. The ArNS name was leased on 30 August. A four-byte test object appeared shortly afterward, and the final 10,977-byte page was anchored on 2 September. This places the completed page online about a week before Alvieri drew public attention to it.
The page we analyzed was static. Its active content was limited to the announcement and countdown. We found no credential collection, loader, redirect mechanism, exploit, downloader, or command-and-control functionality in that version of the site. The Arweave history is also consistent with deliberate staging rather than a page assembled in response to the 9 September attention.
We have high confidence in the technical findings: the statement was signed by whoever controls the corresponding private key, and the supporting infrastructure was prepared before the site became publicly visible to the wider security community. Neither finding, on its own, identifies the operator behind the key.
Attribution is less certain. The branding, language, references to TeamPCP, and surrounding 2026 activity support a moderate-confidence relationship with the broader LAPSUS$ persona operating during 2026. We cannot currently determine whether the same operator has controlled that persona across the different 2026 incidents.
We assess direct continuity with the original 2021-2022 LAPSUS$ cluster with low confidence. The current evidence supports continuity of persona and narrative more strongly than continuity of personnel. Additional evidence linking infrastructure, accounts, cryptographic material, or operator behavior across the two periods would be required to raise that assessment.
Website Screenshots:


Key Judgments:
| Question | Assessment | Confidence |
| Is the Chapter II statement validly signed by the linked key? | Yes. The signature binds the exact text to the linked key. | High |
| Does the signature authenticate historic LAPSUS$ membership? | No. No trusted pre-2026 identity anchor was found. | Low for historic continuity |
| Was the page deliberately staged before public attention? | Yes. ArNS/Arweave records show test content, final upload, and pointer changes before September 9. | High |
| Did the analyzed page deliver malware? | No malware-delivery mechanism was observed in the analyzed version. | High for observed version |
| Is there a TeamPCP relationship? | Some access/data/monetization relationship with the broader 2026 persona is plausible; structure is unresolved. | Moderate |
Technical Findings:
-
Static announcement with countdown behavior
At the time of analysis, hxxps[://]lapsus.ar[.]io/ returned a 10,977-byte HTML page titled LAPSUS$. The page is self-contained apart from one remote background image. Styling is embedded in the HTML, and a single JavaScript block controls the countdown.
The countdown targets 2026-09-13T00:00:00+02:00, equivalent to 12 September at 22:00 UTC. When the timer reaches zero, the script sets each counter to zero and changes the displayed status to "Execution Live." We found no other functional use of JavaScript on the page.
We reviewed both the HTML and JavaScript for signs that the site was being used to deliver content or execute additional activity in the visitor's browser. In the version examined, it was not. The script makes no fetch, XHR, or WebSocket requests. It does not use browser storage, fingerprint the visitor, create additional script elements, or retrieve executable content.
The HTML also contains no credential collection form, iframe, embedded object, service worker, redirect logic, or encoded payload. We found no references to executable files, archives, documents, PowerShell or shell scripts, or external JavaScript payloads. Based on the page source available during analysis, the site functioned as a static announcement page with a countdown rather than a delivery mechanism.
Two outbound links are presented to the visitor: a Pastebin page containing the public key and the forum profile referenced by the actor. The only asset loaded automatically from a third party was the page background hosted on Wired's media infrastructure. The path ends in .jpg, but the server returned a 730,390-byte RIFF/WebP object. Its SHA-256 is 4acc860ee85baa533cb8e49ebd5cc51bd43f0f275a118f32e864a8a682418466.
We examined that object separately and found no indication that it should be treated as malicious. The browser also requested /favicon.ico, but lapsus.ar[.]io returned the site's HTML fallback instead of a dedicated favicon. Neither request changed our assessment of the page's behavior.
-
OpenPGP verification and attribution limits
The Pastebin page linked from the announcement publishes a version 4 OpenPGP key with UID LapsusGroup and fingerprint 7D0FA2E212E398576C797102131C4FF38C4D936B. The key uses EdDSA algorithm identifier 22 with an Ed25519 curve OID. The Chapter II statement is accompanied by a canonical-text signature using SHA-512.
We normalized the message according to OpenPGP canonical text rules and verified the signature independently against the published key. The signature validates. Its issuer fingerprint and key ID match the linked key, and the CRC-24 checks for both ASCII-armored objects also passed.
The signature packet records a creation time of 2 September 2026 at 14:33:00 UTC. We do not treat that value as independent evidence of when the message was signed because the timestamp is supplied by the signer. The same limitation applies to the signature's hashed manu notation. The recorded values map, according to GnuPG documentation, to GnuPG 2.5+1.12 on amd64 Windows. This may describe the environment used to generate the signature, but it is signer-controlled metadata rather than endpoint telemetry collected independently.
The cryptographic result is straightforward. Whoever controls the private key corresponding to fingerprint 7D0FA2E212E398576C797102131C4FF38C4D936B signed the Chapter II statement. We assess that conclusion with high confidence.
What the signature does not establish is the identity of that key holder or whether the operator has any direct connection to the original LAPSUS$ group.
The public key packet records a creation date of 17 December 2025. Pastebin shows the key as published on 16 February 2026, and the same fingerprint is indexed by keys.openpgp.org without the UID. We found no earlier LAPSUS$ key carrying this fingerprint and no cryptographic bridge to accounts or infrastructure associated with the 2021-2022 activity. We also found no validation through a previously trusted account, Telegram channel, or identified historic member.
We therefore separate key ownership from actor attribution. The available evidence is sufficient to confirm possession of the private key used to sign the Chapter II message. It is not sufficient to identify the operator or establish continuity with the historic 2021-2022 LAPSUS$ cluster. The signature is valid; the identity behind it remains unverified.
Infrastructure Staging and Publication Timeline:
AR.IO's ArNS layer provides the human-readable lapsus.ar[.]io name, while the underlying ArNS Name Token controls which Arweave object the name resolves to. The ArNS pointer can be updated, but an Arweave object cannot be modified under the same data ID once published. From a monitoring perspective, this gives defenders two separate points to track: the hostname itself and the Arweave object currently returned by the resolver.
At the time of collection, lapsus.ar[.]io resolved to Arweave object Gc-rpi5LRuUl-7W_886E7lGgqwCjLHxyQ-jhkUUMXhQ. Arweave metadata links the HTML object to wallet H-sJj0oFLFqpwIKteAdCFQFS4VDFmUKhrWbuGrZjZA0 and includes ArDrive/Web uploader metadata. One uploader tag records 2 September at 14:51:54 UTC. The bundle containing the object was later included in Arweave block 1,992,730 at 15:01:42 UTC. For timeline analysis, we treat the block timestamp as the more reliable reference because the uploader tag is creator supplied.
Solana records show that the lapsus ArNS name was purchased on 30 August at 21:50:49 UTC for a one-year term. The registry lists HeHTLNLcuV5G3wzw5Ef8YarEtxaieRs5Lt4g9kAwjfxn as the holder and 9HVcBG572WENSB6uTMB2geYQxMVWS1Z6C6fNsbW6oagx as the ANT asset. We did not observe a configured *_lapsus undername during collection. The Solana holder and the Arweave uploader are different wallets. Their activity correlates through the ArNS pointer changes, which is consistent with coordinated use of the infrastructure, but we found no cryptographic link between the two wallets and no wallet-level evidence identifying an individual operator.
The earlier ArDrive state shows that the infrastructure was tested before the final page was published. Within minutes of the ArNS name being acquired, the uploader placed a four-byte object containing "test" on Arweave. The ArNS root initially resolved through a manifest that mapped index.html to that object.
On 2 September, the root was updated to a manifest for the completed page. The TTL was then reduced from 900 seconds to 60 seconds, followed by another update that pointed the root directly to the final data ID. This sequence is consistent with the operator validating name resolution first, publishing the finished page afterward, and lowering cache duration to make subsequent pointer changes propagate more quickly.
We assess that the publication infrastructure was deliberately staged before the site drew broader attention. The sequence of acquisition, test publication, manifest changes, TTL reduction, and final pointer update is consistent with planned deployment rather than an ad hoc publication. The records do not identify the operator, and we found no evidence in this activity that a third-party system was compromised.

Infrastructure Integrity and Hosting Context:
-
Content-integrity verification
We retrieved the page independently through lapsus.ar[.]io, arweave[.]net, and turbo-gateway[.]com. Each source returned the same 10,977-byte object. The SHA-256 we calculated is 81d70576a454ccfbbdb9c8b6bab351fe1ba0bff17c9f586c8cfcbc8db894e799, which matches the value represented in the AR.IO content-digest header. We use this hash to identify the exact page version analyzed. It should not be treated as a malware indicator.
The AR.IO response also included gateway-local status fields such as trusted, stable, and verified. These values describe the gateway's own trust and verification state and are not maliciousness verdicts. Separately, Arweave GraphQL linked the data item to a layer-one bundle in block 1,992,730, and the Arweave status endpoint showed the object as deeply confirmed when we checked it. The combination of the data ID and matching digest is sufficient to identify the anchored content version even if gateway availability or gateway-specific status flags change later.
-
DNS, TLS, and shared infrastructure
During collection, lapsus.ar[.]io resolved with 60-second TTLs to 162[.]55[.]156[.]39, 49[.]13[.]45[.]141, 2a01:4f8:1c1d:fc2::1, and 2a01:4f8:1c1f:7ff0::1. RIPE registration data places the associated address space in Hetzner Online infrastructure announced by AS24940. We also queried a synthetic, nonexistent hostname beneath ar[.]io and received the same IPv4 pair. That result is consistent with wildcard gateway routing rather than infrastructure provisioned specifically for the lapsus hostname.
Lapsus.ar[.]io is an ArNS name under the ICANN-registered ar[.]io domain. It is not a separately registered domain. The TLS certificate observed during analysis was a Let's Encrypt wildcard certificate covering *.ar[.]io and ar[.]io, valid from 21 August through 19 November 2026. Certificate Transparency records exposed the shared wildcard names but did not contain a dedicated lapsus.ar[.]io SAN.
For that reason, the resolved IP addresses, AS24940, the wildcard certificate, and the ar[.]io apex should be treated as hosting context rather than standalone indicators for blocking. These resources are shared and are not specific to the LAPSUS$-branded page.
-
Public threat-intelligence observations
VirusTotal first received the URL on 2 September at 17:34:44 UTC, approximately two and a half hours after the final page object entered its Arweave block. At the time we reviewed the record, none of the 90 URL engines returned a malicious verdict. The capture showed an HTTP 200 response with no redirect and the page title LAPSUS$. Three requests were recorded: the landing page, the Wired-hosted background image, and the favicon request.
VirusTotal category labels such as "hacking" describe content or taxonomy and should not be interpreted as a malware-family classification or proof of malicious browser behavior. The absence of a malicious verdict is also consistent with what we observed during source review: the analyzed page was a static extortion announcement rather than a loader or payload-delivery page.
Campaign and Actor Assessment:
-
A separate 2026 LAPSUS$ persona predated Chapter II
The September Chapter II page was not the first LAPSUS$-branded activity reported in 2026. SpyCloud documented a separate persona using a data-leak site, auctions, private sales, and a disputed BreachForums successor. KELA later placed the same persona within the broader 2026 underground forum ecosystem. Neither source identified a verified link between that activity and the original 2021-2022 LAPSUS$ group.
The forum evidence is less stable. KELA reported that the relevant BreachForums faction moved its primary domain from breached[.]st to breached[.]su on 20 May, while the Chapter II page still links to a .st member URL. When we checked that route on 9 September, it returned a login gate. The breadcrumb identified member ID 4392 as Fuhrerbunker, while the URL path still contained the lapsus slug. XenForo uses the numeric member ID as the authoritative account reference, so the slug may be stale or may have changed without affecting which account is resolved. We could not establish the current ownership or mirror status of breached[.]st.
There is evidence that at least one 2026 LAPSUS$-branded release contained authentic victim data. Checkmarx reported that compromised credentials were used to access its GitHub environment and that data was exfiltrated on 30 March. A party using the LAPSUS$ name later published material on 25 April. Following an investigation conducted with support from Mandiant, Checkmarx confirmed that the released data originated from its GitHub repositories. This confirms that the persona possessed and published genuine victim data. It does not establish who carried out the initial compromise or how the data reached the party using the LAPSUS$ name.
That earlier publication also complicates the Chapter II statement's reference to a "first victim leak." If the Chapter II operator is the same 2026 persona, "first" is unlikely to mean the first victim data ever released under the LAPSUS$ name in 2026. It may instead refer to the first disclosure associated with the Chapter II site or this phase of activity. We therefore do not treat that wording as evidence of operator continuity.
-
TeamPCP relationship
Several sources point to some relationship between TeamPCP and the 2026 LAPSUS$ persona, although the exact structure remains unclear. TeamPCP statements preserved by Socket referred to LAPSUS$ as a partner in activity involving Checkmarx. Those statements originated from the actors themselves and were not independently authenticated. KELA observed both personas operating in the same underground ecosystem, and Flare later assessed with moderate confidence that TeamPCP supplied initial access or victim data to LAPSUS$ for brokerage.
The overall case is stronger when those reports are considered alongside Checkmarx's confirmation that the published material was genuine and the Chapter II author's reciprocal reference to "the acts of our cooperation." We assess with moderate confidence that TeamPCP and the broader 2026 LAPSUS$ persona had some form of operational or commercial relationship. Plausible models include transfer of access, handoff of stolen data, distribution support, or monetization. The current evidence does not allow us to distinguish among those possibilities. It also does not establish common membership, common ownership, or shared control of infrastructure.
The FBI's July FLASH on TeamPCP describes supply-chain compromise, theft of credentials and tokens, persistence, extortion, and collaboration with other cyber actors. The bulletin does not name LAPSUS$. Those behaviors are relevant when assessing organizations exposed to TeamPCP, but they should not be attributed to the Chapter II page based on the FBI reporting alone.
-
Arrest timing and remaining operator models
Australian authorities arrested two alleged TeamPCP participants on 26 August. The U.S. Department of Justice separately named Ruben Ian Thomson and stated that an indictment dated 25 August was unsealed following his arrest. These are criminal allegations, not convictions. Neither the AFP nor DOJ reporting connects the defendants to the Chapter II page, its OpenPGP signing key, the associated wallets, or the historic LAPSUS$ group.
The timing is nevertheless relevant to the campaign timeline. The arrests occurred on 26 August. The lapsus ArNS name was leased and tested on 30 August. The Chapter II statement was signed and uploaded on 2 September, and the site drew public researchers' attention on 9 September.
The statement thanks TeamPCP for its "sacrifice" and "falling" and then challenges the FBI. Given the wording and the short interval between the arrests and the site's staging, we assess with moderate confidence that the language refers to the recent disruption of TeamPCP. That remains an analytic judgment rather than a fact stated explicitly by the operator.
Taken together, the evidence supports a relationship between Chapter II, the broader 2026 LAPSUS$ persona, and the TeamPCP narrative, but it does not resolve who is operating the persona. Several models remain possible, including continued operation by an established 2026 actor, transfer of the persona to another operator, or coordinated use of the LAPSUS$ brand by multiple parties. None of the evidence reviewed so far establishes personnel continuity with the original 2021-2022 LAPSUS$ cluster.
| Operator model | Assessment | Why it remains plausible |
| Surviving partner | Moderate confidence | An existing 2026 LAPSUS$ partner responds to or exploits the TeamPCP disruption. |
| Affiliate / rebrand | Possible | A TeamPCP associate or adjacent actor adopts or revives the LAPSUS$ name. |
| Opportunistic impersonation | Possible | An unrelated actor uses public arrests and earlier partnership reporting to borrow credibility. |
Historic LAPSUS$ context:
Microsoft tracked the 2021-2022 LAPSUS$ cluster as DEV-0537 and described an identity-focused extortion actor that relied heavily on stolen credentials and access abuse rather than ransomware. Reported techniques included session-token replay, SIM swapping, MFA fatigue, help-desk social engineering, insider recruitment, and searches for credentials and secrets in code repositories.
The U.S. Cyber Safety Review Board later characterized LAPSUS$ as a loosely organized and fluid group with overlapping membership and mixed motivations. UK court proceedings resulted in a restricted hospital order for Arion Kurtaj and a youth rehabilitation order for another teenager associated with the activity.
We use these historical behaviors only as context for identity-focused hunting and defensive recommendations later in this report. They are not evidence that the Chapter II activity is being operated by the same individuals.
We found no direct technical bridge between the current Chapter II infrastructure and the historic 2021-2022 cluster. Without such a link, historic LAPSUS$ tradecraft should not be mapped to the current page as observed behavior or treated as proof of operator continuity.
MITRE ATT&CK Mapping:
Only resource development behavior is supportable from the Chapter II artifact reviewed. We therefore exclude TeamPCP capabilities and historic LAPSUS$ techniques that were not directly observed in the current activity.
| Tactic | Technique | ID | Observed behavior | Confidence |
| Resource Development | T1583.006 | The observed operator used an ArDrive/Arweave publication stack to host the content-addressed HTML object. This is a closest-fit mapping: service use is proven; account acquisition is not. | Moderate |
We considered T1583.001 (Acquire Infrastructure: Domains) but did not map it. The lapsus[.]ar.io name was acquired through the AR.IO and Solana ArNS system rather than through conventional ICANN domain registration, so the ATT&CK technique is only a partial fit.
We also do not map techniques for initial access, execution, persistence, privilege escalation, credential access, discovery, lateral movement, collection, exfiltration, or impact. The analyzed page provides no evidence that any of those stages occurred in connection with Chapter II.
Detection and hunting opportunities:
The guidance below is intended as implementation logic rather than production-ready query syntax. Organizations should adapt it to their Securonix data model, available telemetry, existing allowlists, and risk-scoring thresholds.
-
Exact-indicator and content-provenance hunting
Start with direct searches for the infrastructure and provenance values observed during analysis. DNS, secure web gateway, proxy, firewall, browser-isolation, and EDR network telemetry can be used to identify access to the exact hostname and the linked URLs.
Threat-intelligence repositories and case-management data should also be searched for the OpenPGP fingerprint, Arweave uploader wallet, ANT asset, manifest IDs, and associated Arweave data IDs. Base64url identifiers are case-sensitive and should be preserved exactly. These values are best used as investigative pivots rather than automatic block indicators.
Where HTTP response headers are retained, collect and compare values such as x-arns-resolved-id, x-arns-ant-id, x-ar-io-data-id, content-digest, and etag. A change from the values documented in this report should trigger a new collection and content review.
-
Follow-on browser and process behavior
The Chapter II page analyzed in this report did not launch a process or deliver a payload. For that reason, a visit to the URL should not be treated as evidence of compromise by itself. Higher-value detection comes from identifying activity that follows the visit.
Useful correlations include browser access to the exact host followed by the creation or download of an archive, executable, script, disk image, or macro-capable document. Analysts should also review cases where the browser subsequently launches powershell.exe, pwsh.exe, cmd.exe, wscript.exe, cscript.exe, mshta.exe, rundll32.exe, regsvr32.exe, an installer, or an archive utility.
File telemetry can provide another useful pivot. Look for newly created files whose origin URL or referrer points to lapsus.ar[.]io, the linked forum, or a newly resolved Arweave object. A downloaded artifact becomes more significant when process and file lineage show that it later establishes persistence, launches additional tooling, or makes rare outbound connections.
-
Controlled content-drift monitoring
Because the ArNS name can be repointed to a different Arweave object, defenders should monitor the content rather than assume the currently observed page will remain unchanged.
Use an isolated threat-intelligence collector, not an end-user browser, to resolve the ArNS name at regular intervals. Record the resolved data ID, HTTP status, byte length, MIME type, content digest, and outbound-link set for each observation.
Changes to the resolved ID, digest, file size, content type, script behavior, form elements, redirects, iframe usage, outbound domains, or downloadable artifacts should trigger review. Prior Arweave objects should be retained so analysts can compare versions and reconstruct when meaningful changes occurred.
Conclusion:
Securonix ThreatWatch assesses that the LAPSUS$ "Chapter II" page was deliberately staged as an extortion-focused publication rather than a malware delivery mechanism. The statement published on the site carries a valid OpenPGP signature that verifies against the linked public key. This confirms control of the corresponding private key, but it does not establish continuity with the original 2021-2022 LAPSUS$ operators. We found no trusted historical key, previously controlled account, or other cryptographic link that bridges the current activity to the historic group.
The infrastructure timeline shows preparation before the page received public attention. The lapsus ArNS name was acquired on 30 August, followed by a short test object. The final page was published on 2 September, after which the operator changed the ArNS pointer and reduced the TTL. Taken together, those records are consistent with planned staging and controlled publication through ArNS and Arweave. The Solana ArNS holder and Arweave uploader appear operationally related through the pointer history, but we found no cryptographic evidence linking the wallets to each other or to a known individual.
The page version analyzed contained no malware, exploit, credential collection, redirect chain, downloader, or command-and-control behavior. Chapter II should therefore be treated as a developing threat-intelligence and extortion-monitoring lead, not as evidence of an active malware campaign or confirmed intrusion. Any future change to the ArNS-resolved object, appearance of downloadable content, publication of victim data, or change in browser-side behavior should be collected and assessed as a new artifact.
Attribution remains unresolved. Available reporting supports a moderate-confidence relationship between the broader 2026 LAPSUS$ persona and TeamPCP, but the evidence does not establish shared membership, common control, or a direct link between Chapter II infrastructure and individuals arrested during the TeamPCP disruption. We continue to assess continuity with the historic LAPSUS$ cluster with low confidence.
For defenders, precision matters more than broad blocking. Monitoring should focus on the exact hostname, the current Arweave object, related content identifiers, and any subsequent pointer changes. Shared AR.IO, Arweave, Hetzner, and certificate infrastructure should not be treated as malicious solely because it appears in this activity. The most meaningful change would be a new resolved object, verified victim material, a downloadable payload, or a trusted identity link to historical LAPSUS$ infrastructure or accounts.
On the evidence available now, the most supportable assessment is that Chapter II is a validly signed LAPSUS$-branded announcement backed by deliberately staged infrastructure, with an assessed relationship to the TeamPCP-linked 2026 ecosystem and an operator identity that remains unverified.
References:
-
LAPSUS$ GROUP, "CHAPTER II," landing page, observed September 9, 2026.
hxxps[://]lapsus.ar[.]io/
-
LapsusGroup, "PUBLIC KEY," Pastebin, displayed February 16, 2026.
https://pastebin.com/2L4dyaZy
-
keys.openpgp.org, public key associated with fingerprint 7D0FA2E212E398576C797102131C4FF38C4D936B, observed September 9, 2026.
https://keys.openpgp.org/vks/v1/by-fingerprint/7D0FA2E212E398576C797102131C4FF38C4D936B
-
Internet Engineering Task Force (IETF), RFC 9580, "OpenPGP," July 2024.
https://www.rfc-editor.org/rfc/rfc9580.html
-
GnuPG Project, "DETAILS - Notation Data," accessed September 9, 2026.
https://github.com/gpg/gnupg/blob/master/doc/DETAILS#L1705-L1734
-
AR.IO Documentation, "ArNS," accessed September 9, 2026.
https://docs.ar.io/learn/arns/
-
Arweave, Chapter II final data object, transaction/data ID Gc-rpi5LRuUl-7W_886E7lGgqwCjLHxyQ-jhkUUMXhQ, block timestamp September 2, 2026.
https://arweave.net/Gc-rpi5LRuUl-7W_886E7lGgqwCjLHxyQ-jhkUUMXhQ
-
Arweave, precursor test object, transaction/data ID Q8ufDg2z1NjqSbCoUxcDPmAEUtxkDvGJBycwhL3l9MI, block timestamp August 30, 2026.
https://arweave.net/Q8ufDg2z1NjqSbCoUxcDPmAEUtxkDvGJBycwhL3l9MI
-
VirusTotal, URL analysis for https://lapsus.ar.io/, observed September 9, 2026.
https://www.virustotal.com/gui/url/aHR0cHM6Ly9sYXBzdXMuYXIuaW8v/details
-
Checkmarx Team, "Update: Ongoing Checkmarx Supply Chain Security Incident," updated July 6, 2026.
https://checkmarx.com/blog/ongoing-security-updates/?p=108697
-
KELA Cyber Intelligence Center, "The BreachForums Succession Wars," published June 13, 2026, updated June 22, 2026.
https://www.kelacyber.com/blog/breachforums-succession-wars-2026/
-
Flare, "Supply Chain Ransomware: TeamPCP Weaponizes Worms to Fuel Partnerships and $95K Data Sales," June 14, 2026.
https://flare.io/learn/resources/blog/supply-chain-ransomware-teampcp-weaponizes-worms-to-fuel-partnerships-and-95k-data-sales/
-
Federal Bureau of Investigation, "Cyber Criminal Group TeamPCP," FLASH-20260702-01, July 2, 2026.
https://www.fbi.gov/investigate/cyber/alerts/2026/cyber-criminal-group-teampcp
-
U.S. Attorney's Office, Northern District of California, "Australian Man Indicted For 'TeamPCP' Cyberattacks On Software Supply Chain," August 27, 2026.
https://www.justice.gov/usao-ndca/pr/australian-man-indicted-teampcp-cyberattacks-software-supply-chain
-
Australian Federal Police, "Two WA Men Charged Following AFP-FBI-WAPF Disruption of Alleged Global Cybercrime Syndicate," August 27, 2026.
https://www.afp.gov.au/news-centre/media-release/two-wa-men-charged-following-afp-fbi-wapf-disruption-alleged-global
-
Microsoft Threat Intelligence Center, "DEV-0537 Criminal Actor Targeting Organizations for Data Exfiltration and Destruction," March 22, 2022.
https://www.microsoft.com/en-us/security/blog/2022/03/22/dev-0537-criminal-actor-targeting-organizations-for-data-exfiltration-and-destruction/
-
Cyber Safety Review Board, "Review of the Attacks Associated with Lapsus$ and Related Threat Groups," U.S. Department of Homeland Security, August 2023.
https://www.cisa.gov/sites/default/files/2023-08/CSRB_Lapsus%24_508c.pdf -
Solana Foundation, mainnet-beta JSON-RPC evidence for the lapsus ArNS BuyName and SetRecord transactions, queried September 9, 2026.
Primary RPC endpoint: https://api.mainnet-beta.solana.com
ArNS purchase transaction: 3yf6tswKZ2GgDmfAJ9fesgixNKGr9cULCqkDBFssT7brquxRFRsRnPnsnj8Ab8jEUKL38TUQ8hvjAvVwr5j2ksGG

