← AstraZeneca

2026 AstraZeneca — LAPSUS$ alleged ~3GB internal data (private sale claim, unconfirmed)

2026 Unknown records affected Share on X

Data compromised

Alleged: source code, cloud/IaC configs, credentials, employee directory metadata

Technical writeup

March 2026: LAPSUS$-linked actors allegedly exfiltrated ~3GB from AstraZeneca. Trade and security blogs described alleged content including source code (e.g. Java, Angular, Python), AWS/Azure-style cloud and Terraform configurations, secrets/tokens, GitHub Enterprise–related employee metadata, and contractor access details. Reporting noted a shift toward private sale and password-protected proof samples rather than a full public dump; consultants and dark-web trackers (e.g. DailyDarkWeb-style coverage referenced on X March 23, 2026) discussed seriousness pending vendor confirmation. AstraZeneca had not broadly confirmed scope in early public reporting. Independent verification of impact was still under discussion.

Root cause

Alleged intrusion by LAPSUS$-affiliated actors; dev/cloud pipeline exposure (claimed)

References