Skip to content
TrackPodcasts
businessMar 28, 20262:10

Extortion Group Claims It Hacked AstraZeneca

RADIO 007

About this episode

www.osintinvestigate.com

The Lapsus$ hackers allegedly compromised internal code repositories, credentials, and employee data.

Interactive timestamps

Jump to segment

Get every episode summarized

Each time RADIO 007 publishes, we email you a written briefing from the transcript — the topics, who appeared, and any specific claims, with the ad reads skipped.

Email me new episodes

Free for 3 shows. No card needed.

Hosts & guests

Transcript ready

23 searchable segments. Every word is indexed and playable.

Extortion Group Claims It Hacked AstraZeneca

RADIO 007

0:00
2:10

Full transcript

RADIO 007Extortion Group Claims It Hacked AstraZeneca. Machine-transcribed; use the interactive transcript above to jump the player to any line.

0:00Welcome to Hacker News and Analysis Podcasts. Please visit our website ostentinvestigate.com. The notorious lapsus extortion group has boasted on an underground forum about hacking bio-pharmaceutical giant AstraZeneca and stealing roughly three gigabytes of data. The hackers say they ex-filterated multiple types of sensitive enterprise data from AstraZeneca, including credentials and tokens, internal code repositories, and employee data. Lapsus dollar claims to have ex-filterated Java-based application codes such as controllers, repositories, services, schedulers, configuration files, and spring boot resources. Cybersecurity firm SO Surradar Reports. The leak allegedly includes project paths associated with internal development assets, angular and Python packages, and AWS, Azure, and Terraform Cloud infrastructure information. Furthermore, the hackers claim to have stolen various credentials and other secrets. GitHub enterprise-related user information such as roles and account details and corporate

1:03email addresses. The file tree also points to large numbers of SQL scripts, table definitions, views, sequence files, batch processes, and inventory or order management components, SO Surradar Notes. In practical terms, that suggests the alleged breach may touch internal business operations, supply chain workflows, and system administration data, not just developer artifacts. The company points out. Lapsus dollar also added AstraZeneca to its tour-based leak site, offering the allegedly stolen information for sale. However, it has not set a price for it. Should the hacking groups claims be verified, the blast radius from the incident could be broad, as it may impact employees, partners, intellectual property, and the supply chain. The pharma giant has yet to publicly disclose the incident and confirm the extortion groups claims. Some voices suggest that the AstraZeneca hack could be linked to the recent supply chain attack that affected Aqua's trivia vulnerability scanner, but security researchers are skeptical

2:07saying that evidence is circumstantial.

More episodes

More from RADIO 007

View all episodes →