-
LAPSUS$ reportedly says it has reached its financial goals and will stop its cybercrime activities.
-
The group allegedly plans to stop releasing leaks, selling access, and making further public statements.
-
Questions remain about the announcement, its PGP signature, and claims linked to data allegedly taken from Mercor.

The cybercrime group LAPSUS$ has reportedly claimed that it is ending its operations permanently. Dark Web Informer shared the claim, while BreachNews also reported on the alleged shutdown. A statement appeared on a website that presented itself as part of the LAPSUS infrastructure.
The message reportedly said the group had chosen to close its operations on its own decision. The group allegedly claimed that it had already reached the financial goals it wanted. For that, the statement reportedly said LAPSUS$ no longer had a reason to continue.
The message also claimed the group would stop several activities linked to its operations. Those activities reportedly include publishing new data leaks and selling access to hacked systems. The group also allegedly said it would stop making further public communications.
The announcement reportedly included messages aimed at investigators and other cybercrime groups. TeamPCP was among the actors that the statement allegedly mentioned. The message presented the shutdown as a choice made by the group itself.
It did not reportedly describe the decision as a result of police action or other problems. However, the announcement has not been confirmed as a genuine statement from the original group.
LAPSUS$ Shutdown Claim Raises Questions
BreachNews reported that the announcement included a PGP signature. A PGP signature can help people check whether a message came from a known source. However, BreachNews said it could not independently confirm several important details about the statement. The report said researchers could not confirm that the website still belonged to the original LAPSUS$ members.
The report also raised questions about whether the PGP signature truly belonged to the group. That leaves the real source of the announcement unclear for now. The uncertainty matters because cybercrime groups have announced their endings before.
Some groups later returned under new names or formed new groups after announcing their retirement. Others have also appeared again with new websites and different online identities. For that reason, the latest LAPSUS$ statement does not prove that the group has ended permanently.
Researchers may therefore continue to watch for signs of new activity linked to the group. The announcement has also attracted attention because of claims involving Mercor. Mercor is an AI recruiting and data-training company that suffered a security incident earlier this year. The alleged LAPSUS$ statement reportedly claimed that the group obtained data from Mercor.
The statement also allegedly claimed that Chinese entities later bought the stolen information. The data reportedly included personal information belonging to people connected to the company. The claims also mentioned biometric records, voice recordings, and videos showing people’s faces.
The scale of the alleged data theft has been reported elsewhere, hackers have claimed 4TB of data stolen from Mercor AI in a supply chain attack.
However, no independent evidence currently confirms that the alleged sale actually happened. BreachNews also reported that it could not independently verify those claims. The alleged Mercor connection has already appeared in earlier reports about cybercrime activity.
Mercor Data Claims Add Another Layer
TechCrunch reported in March that Mercor confirmed a security incident. The incident reportedly involved the compromise of the open-source LiteLLM project. TeamPCP was linked to that incident, according to the report.
At the same time, LAPSUS$ separately claimed that it had targeted Mercor. The group also allegedly claimed that it obtained data from the company. However, TechCrunch reported that the exact source of the alleged data remained unclear.
The report also said it was not clear whether LAPSUS$ carried out the original intrusion. That leaves questions about how the group may have obtained the information it claimed to possess. TechCrunch later reported another claim involving a large amount of alleged Mercor data.
A hacker group reportedly claimed that it held about 4TB of data from the company. The alleged dataset reportedly contained candidate profiles and personally identifying information. It also allegedly included information about employers, source code, and API keys. However, Mercor did not publicly confirm that the dataset was genuine.
The company also did not confirm the full amount of information allegedly taken. Mercor reportedly said it was investigating the security incident. The latest LAPSUS$ announcement therefore connects with an already complex series of claims.
Several groups have appeared in reports involving the company and its alleged stolen information. The available reports also do not clearly establish who obtained the data first. They also do not confirm whether all the alleged data came from the same incident. The new statement now adds another claim to that unresolved story.
Group’s Future Remains Unclear
For now, the reported LAPSUS$ shutdown remains an unconfirmed claim. The statement says the group reached its financial goals and decided to stop operating. It also reportedly says the group will no longer publish leaks or sell access.
However, the identity of the people behind the statement has not been independently confirmed. The website’s connection to the original LAPSUS$ operators also remains uncertain. The PGP signature may offer a way to check the message’s source. However, BreachNews has not independently confirmed that the signature belongs to the group. The claims about Mercor also remain unverified.
No independent evidence currently confirms that the alleged data sale to Chinese entities occurred. The available information also does not confirm that LAPSUS$ carried out the original Mercor intrusion. These unanswered questions make it difficult to confirm what the latest announcement truly means.
The group may have genuinely decided to end its activities after reaching its financial goals. However, the available information does not yet prove that LAPSUS$ has permanently disappeared. The announcement could therefore remain the group’s final public message, but that has not been confirmed.
For now, the reported shutdown should be treated as a claim rather than a confirmed conclusion. The future of LAPSUS$ remains unclear until researchers can verify who made the announcement.
They would also need to confirm the website’s connection to the original group. Until then, the alleged permanent shutdown remains another unresolved development surrounding LAPSUS$.