A website presenting itself as official infrastructure for the LAPSUS$ extortion group has published a PGP-signed statement claiming the operation has permanently ceased all activities.
The message declares that the group has achieved its financial objectives, will publish no further leaks, sell no additional access, and issue no future communications.

PGP-signed statement claims operations have ended
The announcement states that the group is retiring voluntarily rather than as a result of law enforcement pressure or operational setbacks.
According to the statement, LAPSUS$ claims it “achieved precisely what we set out to accomplish,” adding that its financial goals had been met and describing the shutdown as a deliberate decision rather than a retreat.
The message also claims there will be “no further communications, no additional leaks, and no more access points” associated with the operation.
Message criticizes investigators and references Mercor
Beyond announcing the purported shutdown, the statement mocks investigators and other cybercrime actors while claiming responsibility for multiple successful intrusions.
It also alleges that data stolen from Mercor has already been sold to Chinese enterprises. The statement claims the information includes personally identifiable information, biometric data, voice recordings, and facial videos. BreachNews has not independently verified those claims, and no evidence was provided to support them.
The message concludes with what appears to be a PGP signature intended to authenticate the announcement.
Authenticity remains unverified
While the announcement is presented as an official statement from LAPSUS$, there is currently no independent confirmation that the website remains controlled by the original operators or that the published PGP signature belongs to the group.
Cybercrime groups have historically announced retirements only to later rebrand, fragment into new operations, or resume activity under different infrastructure. In some cases, infrastructure has also been taken over by unrelated actors seeking to leverage an established reputation.
Until the site’s operators and cryptographic signature can be independently authenticated, the announcement should be treated as a claimed shutdown rather than definitive confirmation that LAPSUS$ has permanently ceased operations.
One of the most disruptive extortion groups
LAPSUS$ emerged as one of the most prominent financially motivated threat groups after compromising major technology companies through social engineering, insider recruitment, credential theft, and MFA fatigue attacks rather than traditional ransomware deployment.
LAPSUS$ emerged as one of the most prominent financially motivated threat groups after compromising major technology companies through social engineering, insider recruitment, credential theft, and MFA fatigue attacks rather than traditional ransomware deployment.
The group targeted organizations including Microsoft, NVIDIA, Samsung, Uber, Okta, Rockstar Games, Cisco, and others, often publicly leaking stolen data while attempting to extort victims.
Cybercrime groups have previously announced retirements before later rebranding, fragmenting into new operations, or resurfacing under different infrastructure. While the statement includes a PGP signature, its authenticity and the identity of the current operators behind the LAPSUS$ website have not been independently confirmed. Whether this announcement marks the genuine end of the group’s operations or another evolution in its public identity remains to be seen.











