-
A new site using the LAPSUS$ name claims the group has returned under ‘Chapter II.’
-
The message mentions TeamPCP, which worked with LAPSUS$ during major supply chain attacks in 2O26.
-
The new site’s identity remains unproven. Researchers still need to verify its PGP key, infrastructure, and activity.
Recent developments suggest the LAPSUS$ name is back online, months after a previous LAPSUS$-branded site announced shutting things down. A new site calling itself ‘LAPSUS$ GROUP Chapter II’ put up a PGP-signed message. It also mentions TeamPCP and touts the new operation as a continuation of their earlier work.
What makes this claim stand out is that TeamPCP and LAPSUS$ teamed up for some big supply chain attacks this year. Still, just because this new site exists doesn’t mean the original LAPSUS$ crew is behind it.
The real question is whether the new message’s PGP signature connects to one of LAPSUS$’s old keys. At this point, nobody’s shown proof of that, so we can’t say for sure if the original group is back.
A Sudden Return After a Claimed Shutdown
In July, a website using the LAPSUS$ name posted a statement saying the group had permanently stopped. The July 22 message claimed the operators had reached their financial goals. It also said they would publish no more leaks, sell no more access, or issue further messages.
The statement also claimed that attackers had sold data taken from Mercor to Chinese companies. No independent source has confirmed that claim.
More importantly, researchers never fully proved that the July site belonged to the original LAPSUS$ operators. BreachNews reported that no independent evidence tied the site or its PGP signature to the group. That leaves the shutdown message with the same attribution problem now facing ‘Chapter II.’
Threat groups can reuse old names, copy websites, or take over old infrastructure. A PGP signature can offer stronger evidence, but researchers must first link the key to a known actor.
TeamPCP Gives the New Claim Some Context
The TeamPCP reference matters because the group played a major role in 2O26 supply chain attacks. Researchers linked TeamPCP to attacks involving Trivy, LiteLLM, KICS, npm packages, Docker images, and other developer tools. The campaign targeted software developers and used stolen credentials to reach more organizations.
In March, Wiz said TeamPCP had worked with LAPSUS$ to make money from stolen credentials. Later reports also linked LAPSUS$ to data that TeamPCP stole and offered for sale.
The GitHub case drew particular attention. TeamPCP advertised about 3,800 stolen internal repositories for $50,000 in May. Flare later reported that LAPSUS$ listed the same data for $95,000.
Sophos also reported that TeamPCP confirmed a partnership with LAPSUS$ tied to the Checkmarx incident. That history makes the new message worth watching. But it does not prove that the same operators are behind it.
The PGP Key is the Biggest Clue
PGP lets people use cryptographic keys to sign their messages. A valid signature on a message means the message truly came from the real private key holder and hasn’t been altered. That alone does not prove the person’s identity.
For this case, researchers need to compare the “Chapter II” signature with a public key that they already trust as belonging to LAPSUS$. If the same key signs both messages, confidence in a link to the earlier group would rise.
Public reporting has not yet established that link. Researchers also need to check other clues. These include reused infrastructure, contact accounts, writing habits, victim choices, and attack methods.
A real continuation should leave more evidence than a website using a familiar name. The issue matters because criminals can reuse popular group names. Microsoft originally tracked LAPSUS$ as DEV-0537 and described its use of social engineering, SIM swapping, stolen credentials, and attacks against MFA.
The challenge of verifying who the LAPSUS operators were behind the Vodafone claim. The incident underscores why PGP verification and other technical evidence are essential before attributing new activity to the LAPSUS$ brand.
The group’s track record also explains why the name is valuable. After the attacks on Microsoft, NVIDIA, Samsung, Okta, and many other companies, LAPSUS$ became globally known.
Chapter II may be Real, but the Evidence Remains thin
Fortunately, there is at least one sign that security analysts are aware of the new name. The WatchGuard ransomware tracker lists ‘LAPSUS$ Chapter II’ as an active data broker group with the first appearance in August 2O26.
This is valuable information to know. It neither proves the involvement of the former LAPSUS$ members nor confirms the authenticity of the PGP key on the website.
There are other reports to explain why security analysts need to be cautious. Hackers are known to use the established brands and names that already have a good reputation.
The most accurate conclusion is limited at the moment. A new threat actor is using the name ‘LAPSUS$ Chapter II’ and saying that it has a connection to TeamPCP. At least one security company is currently tracking this name as an active threat actor, but there is no public evidence that the original LAPSUS$ hackers are back.
The next important piece of evidence could be found via PGP verification, infrastructure reuse, or confirmation of a new victim.