Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
CISA Adds Microsoft Internet Key Exchange RCE Vulnerability Exploited in Attacks
August 19, 2026
Critical Microsoft 365 Flaw Lets Attackers Bypass MFA, Hijack Sessions
August 19, 2026
Leaked Stripe Merchant API Keys Expose Payment and Payout Capabilities
August 19, 2026
Home/CyberSecurity News/AstraZeneca Data Breach: LAPSUS$ Group Claims Internal Data Access
CyberSecurity News

AstraZeneca Data Breach: LAPSUS$ Group Claims Internal Data Access

Key Takeaways The LAPSUS$ hacking group has allegedly breached AstraZeneca, claiming access to 3GB of internal data. Stolen data reportedly includes source code, cloud infrastructure configurations,...

Jennifer sherman
Jennifer sherman
March 22, 2026 3 Min Read
74 0

Key Takeaways

  • The LAPSUS$ hacking group has allegedly breached AstraZeneca, claiming access to 3GB of internal data.
  • Stolen data reportedly includes source code, cloud infrastructure configurations, and sensitive access credentials.
  • LAPSUS$ is attempting to sell the data privately, indicating a financial motive rather than immediate public disclosure.
  • AstraZeneca has not yet publicly acknowledged or commented on the alleged incident.

The notorious LAPSUS$ hacking collective has purportedly resurfaced, asserting responsibility for a significant data breach targeting the global pharmaceutical and biotechnology giant, AstraZeneca. This alleged compromise marks a potential shift in the group’s tactics towards direct data sales for financial gain.

Table Of Content

  • Key Takeaways
  • AstraZeneca Data Breach Claims
  • What You Should Do

Currently, the threat actors are reportedly marketing a 3GB archive of internal AstraZeneca data. This move suggests LAPSUS$ is pivoting to a pay-to-access extortion model, differing from some of their previous high-profile public disclosures.

LAPSUS$, a group previously recognized for successful attacks against major technology corporations, appears to have reactivated with this claimed intrusion into AstraZeneca’s internal systems. The collective has shared previews of the exfiltrated data on clandestine forums, providing descriptions of the .tar.gz archive’s contents and including screenshots as ostensible proof of access.

The attackers are inviting prospective buyers to initiate contact via the secure messaging platform Session to negotiate the purchase of the data. As of the latest reports, no complete data leak has been released publicly for free. This strategy reinforces the notion that the group’s primary objective in this instance is monetary profit through a direct sale, rather than immediate public shaming or widespread extortion.

Further substantiating their claims to potential purchasers, the threat actors have also distributed password-protected links containing redacted sensitive information. AstraZeneca has yet to issue any official statement or comment regarding the alleged incident, as of March 20, 2026.

AstraZeneca Data Breach Claims

According to assertions made by the threat actors on the breach forum, the 3GB data dump encompasses a broad spectrum of highly sensitive intellectual property and critical infrastructure configuration details.

Asset Category Compromised Components
Source Code Java Spring Boot applications, Angular frontend frameworks, and various Python scripts.
Cloud Infrastructure Terraform configurations for AWS and Azure environments, alongside Ansible roles used for automation and orchestration​.
Secrets and Access Private cryptographic keys, Vault credentials, and authentication tokens related to GitHub and Jenkins CI/CD pipelines.

To lend credibility to their claims, the attackers have released public samples that reveal specific internal repository structures and project information. The exposed directory tree reportedly shows a root folder labeled AZU_EXFIL, which contains a critical supply-chain portal repository identified as als-sc-portal-internal.

This internal portal seemingly manages several core logistical functions vital to pharmaceutical distribution. These include forecasting, inventory management, product master data management, integration with SAP systems, and metrics for On-Time In-Full (OTIF) delivery.

The details exposed, if verified, suggest that the breach could have significant ramifications for AstraZeneca’s internal supply chain operations and the overall security posture of its cloud infrastructure.

What You Should Do

  • Regularly audit and rotate all sensitive credentials, including API keys, tokens, and private cryptographic keys.
  • Implement robust Multi-Factor Authentication (MFA) across all internal and external-facing systems, especially for administrative accounts.
  • Strengthen supply chain security protocols by thoroughly vetting third-party vendors and continuously monitoring their access to internal systems.
  • Conduct regular security assessments and penetration testing on critical applications and cloud infrastructure to identify and remediate vulnerabilities proactively.
  • Enhance monitoring for unusual network activity and data exfiltration attempts, particularly from systems managing sensitive intellectual property and supply chain logistics.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackBreachSecurityThreat

Share Article

Jennifer sherman

Jennifer sherman

Jennifer is a cybersecurity news reporter covering data breaches, ransomware campaigns, and dark web markets. With a background in incident response, Jennifer provides unique insights into how organizations respond to cyber attacks and the evolving tactics of threat actors. Her reporting has covered major breaches affecting millions of users and has helped organizations understand emerging threats. Jennifer combines technical knowledge with investigative journalism to deliver in-depth coverage of cybersecurity incidents.

Previous Post

Critical Trivy Vulnerability CVE-2023-45288 Exposes Credentials

Next Post

Crunchyroll Data Breach: 100GB of User Data Allegedly Exfiltrated

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Microsoft ends support for Windows 11 24H2 Home and Pro editions
August 19, 2026
CISA Adds Critical Microsoft SharePoint Auth Bypass (CVE-2023-29357) to KEV
August 19, 2026
Ransomware Gangs Impersonate Recovery Firms, Demand Up to $60,000
August 19, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us