LAPSUS$ Announces Permanent Shutdown, Claims Mercor Data Sold to Chinese Buyers

Published
Written by:
Lore Apostol
Lore Apostol
Cybersecurity Writer
Key Takeaways
  • Operation end: LAPSUS$ announced it is permanently ceasing operations after claiming to have met its financial objectives.
  • No more leaks: The group stated there will be no further communications, leaks, or access offerings.
  • Data sale: LAPSUS$ claimed Mercor user data, including biometric records and recordings, was sold to Chinese entities.

The threat actor LAPSUS$ has announced it is permanently ending operations, claiming to have met its financial objectives. The group explicitly stated there would be no further communications, no additional leaks, and no more access points from its side, which was intended to signal the end of its active operations.

LAPSUS$ Declares Permanent Shutdown

In its statement posted at lapsus[.]bz and cited by Dark Web Informer, LAPSUS$ framed the shutdown as a deliberate exit rather than a forced disruption, saying that "the operation is complete, our financial objectives have been thoroughly met, and we are choosing to retire on our own terms." 

LAPSUS$ also taunted investigators pursuing the group, writing that analysts had spent "months analyzing our methods, deploying countermeasures, and trying to trace infrastructure that was always ten steps ahead of you." 

LAPSUS$ claims | Source: Dark Web Informer
LAPSUS$ claims | Source: Dark Web Informer

The group also mocked TeamPCP, claiming it had "quietly worked alongside them from day one to the very end" while TeamPCP faced an FBI investigation and absorbed the consequences.

Mercor Data Allegedly Sold to Chinese Entities

LAPSUS$ also alleged that Mercor user data, including personal information, biometric records, and recordings, was sold to Chinese entities, but these claims remain unverified. The Mercor AI cyberattack claimed by LAPSUS$ was tied to the LiteLLM project compromise. Reports said the attribution of the Mercor breach was "murky," with evidence pointing toward TeamPCP.

In May, TeamPCP claimed the Mistral AI breach, while the company announced being impacted by the TanStack supply chain attack.   

In 2025, the threat actor teamed up with Scattered Spider and ShinyHunters to form the Scattered Lapsus$ Hunters (SLH) alliance.  In September 2025, the SLH announced its retirement as a theatrical exit, only to return in November with the announcement of the alliance’s focus on an Extortion-as-a-Service model

SLH offered $1,000 to women recruited for vishing campaigns in February. In April, LAPSUS$ claimed a Vodafone U.K. breach in a new alleged cyberattack.


For a better user experience we recommend using a more modern browser. We support the latest version of the following browsers: For a better user experience we recommend using the latest version of the following browsers: