AstraZeneca Data Breach: LAPSUS$ Group Claims Internal Data Access
Key Takeaways The LAPSUS$ hacking group has allegedly breached AstraZeneca, claiming access to 3GB of internal data. Stolen data reportedly includes source code, cloud infrastructure configurations,...
Key Takeaways
- The LAPSUS$ hacking group has allegedly breached AstraZeneca, claiming access to 3GB of internal data.
- Stolen data reportedly includes source code, cloud infrastructure configurations, and sensitive access credentials.
- LAPSUS$ is attempting to sell the data privately, indicating a financial motive rather than immediate public disclosure.
- AstraZeneca has not yet publicly acknowledged or commented on the alleged incident.
The notorious LAPSUS$ hacking collective has purportedly resurfaced, asserting responsibility for a significant data breach targeting the global pharmaceutical and biotechnology giant, AstraZeneca. This alleged compromise marks a potential shift in the group’s tactics towards direct data sales for financial gain.
Table Of Content
Currently, the threat actors are reportedly marketing a 3GB archive of internal AstraZeneca data. This move suggests LAPSUS$ is pivoting to a pay-to-access extortion model, differing from some of their previous high-profile public disclosures.
LAPSUS$, a group previously recognized for successful attacks against major technology corporations, appears to have reactivated with this claimed intrusion into AstraZeneca’s internal systems. The collective has shared previews of the exfiltrated data on clandestine forums, providing descriptions of the .tar.gz archive’s contents and including screenshots as ostensible proof of access.
The attackers are inviting prospective buyers to initiate contact via the secure messaging platform Session to negotiate the purchase of the data. As of the latest reports, no complete data leak has been released publicly for free. This strategy reinforces the notion that the group’s primary objective in this instance is monetary profit through a direct sale, rather than immediate public shaming or widespread extortion.
Further substantiating their claims to potential purchasers, the threat actors have also distributed password-protected links containing redacted sensitive information. AstraZeneca has yet to issue any official statement or comment regarding the alleged incident, as of March 20, 2026.
AstraZeneca Data Breach Claims
According to assertions made by the threat actors on the breach forum, the 3GB data dump encompasses a broad spectrum of highly sensitive intellectual property and critical infrastructure configuration details.
| Asset Category | Compromised Components |
|---|---|
| Source Code | Java Spring Boot applications, Angular frontend frameworks, and various Python scripts. |
| Cloud Infrastructure | Terraform configurations for AWS and Azure environments, alongside Ansible roles used for automation and orchestration. |
| Secrets and Access | Private cryptographic keys, Vault credentials, and authentication tokens related to GitHub and Jenkins CI/CD pipelines. |
To lend credibility to their claims, the attackers have released public samples that reveal specific internal repository structures and project information. The exposed directory tree reportedly shows a root folder labeled AZU_EXFIL, which contains a critical supply-chain portal repository identified as als-sc-portal-internal.
This internal portal seemingly manages several core logistical functions vital to pharmaceutical distribution. These include forecasting, inventory management, product master data management, integration with SAP systems, and metrics for On-Time In-Full (OTIF) delivery.
The details exposed, if verified, suggest that the breach could have significant ramifications for AstraZeneca’s internal supply chain operations and the overall security posture of its cloud infrastructure.
What You Should Do
- Regularly audit and rotate all sensitive credentials, including API keys, tokens, and private cryptographic keys.
- Implement robust Multi-Factor Authentication (MFA) across all internal and external-facing systems, especially for administrative accounts.
- Strengthen supply chain security protocols by thoroughly vetting third-party vendors and continuously monitoring their access to internal systems.
- Conduct regular security assessments and penetration testing on critical applications and cloud infrastructure to identify and remediate vulnerabilities proactively.
- Enhance monitoring for unusual network activity and data exfiltration attempts, particularly from systems managing sensitive intellectual property and supply chain logistics.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.