Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Samsung Source Code Leak 2022: How Lapsus$ Published…
Breach analysis Incident: 4 Mar 2022

Samsung Source Code Leak 2022: How Lapsus$ Published 190GB of Code Holding 6,695 Secrets

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
On this page

On 4 March 2022, the Lapsus$ extortion group published about 190GB of what it said was confidential Samsung data, including source code for Galaxy device security features, bootloaders, activation servers and Samsung account authentication. On 7 March Samsung confirmed a security breach involving "some source codes relating to the operation of Galaxy devices", and said no personal information of consumers or employees was included. The NHI problem was inside the code. GitGuardian scanned the leak and reported 6,695 secrets, including thousands of private keys, 80 AWS IAM keys, 62 GitHub Enterprise tokens and 115 Google OAuth2 credentials. It did not test whether they were valid, but estimated that about 10% could give access to external services such as AWS, GitHub, Artifactory and Google. The secrets were published to anyone who downloaded the torrent. No misuse of them has been reported, and Samsung has not said how Lapsus$ got in.

Key takeaways

  • Lapsus$ leaked about 190GB of Samsung data in three archives on 4 March 2022, according to BleepingComputer; Samsung confirmed on 7 March that the breach involved source code for Galaxy devices.
  • GitGuardian found 6,695 secrets in the leaked code, including 2,408 RSA private keys, 80 AWS IAM keys, 62 GitHub Enterprise tokens and 26 Artifactory tokens; the figures are the vendor's, and the keys were not validated.
  • GitGuardian estimated about 90% of the keys were for Samsung's internal services and about 10% for external services such as AWS, GitHub, Artifactory and Google.
  • This is an exposure with no confirmed misuse: the secrets were published, but no use of them has been reported, and Samsung said it did not expect any impact on its business or customers.
  • The identity lesson: stolen source code is a stolen credential store whenever secrets are committed to it, and publishing the code publishes the keys.

At a glance

OrganisationSamsung Electronics
WhenData leaked by Lapsus$ on 4 March 2022; Samsung confirmed the breach on 7 March 2022; GitGuardian published its secrets analysis on 9 March 2022
AttackerLapsus$ data extortion group, which leaked the data
Entry pointNot disclosed by Samsung
Identities abusedSecrets in the leaked code: private keys, AWS IAM keys, GitHub Enterprise and Artifactory tokens, Google OAuth2 and Google Cloud credentials, bearer tokens and passwords
ImpactAbout 190GB of source code and data published; 6,695 secrets exposed per GitGuardian; no confirmed misuse; Samsung said no personal data of consumers or employees was included
CategoryNHI. Incident class: exposure, no confirmed misuse (secrets published in leaked source code)

What happened

Lapsus$ had leaked NVIDIA data days earlier (see the NVIDIA code-signing certificates page) when it turned to Samsung. BleepingComputer reported on 4 March 2022 that the group had shared about 190GB of data in three compressed archives through a torrent with more than 400 peers. Lapsus$ described the contents as source code for every Trusted Applet in Samsung's TrustZone environment, algorithms for biometric unlock, bootloader source for recent devices, confidential Qualcomm source code, the source for Samsung's activation servers and source code for Samsung account authentication, including APIs and services. The third archive was described as Samsung GitHub repositories covering mobile defence engineering, the Samsung account backend, Samsung Pass and other services. BleepingComputer did not verify these claims at the time.

Samsung confirmed the breach on 7 March. "We were recently made aware that there was a security breach relating to certain internal company data," it said in a statement quoted by The Register. "According to our initial analysis, the breach involves some source codes relating to the operation of Galaxy devices, but does not include the personal information of our consumers or employees." Samsung added: "Currently, we do not anticipate any impact to our business or customers." The Register noted that Lapsus$ did not appear to have demanded a private ransom, and had dumped the data to apply pressure instead.

Two days later GitGuardian, which sells secrets detection tools, published its scan of the leaked code. Using more than 350 detectors, and leaving out its generic high-entropy and generic password detectors, it found 6,695 secrets. Private keys made up the largest share: 2,408 RSA, 1,062 elliptic curve, 744 encrypted and 532 generic. It also found 495 Base64 basic authentication credentials, 378 bearer tokens, 231 username and password pairs, 115 Google OAuth2 credentials, 81 Google Cloud keys, 80 AWS IAM keys, 62 GitHub Enterprise tokens and 26 Artifactory tokens.

GitGuardian said it did not validate the keys because of ongoing investigations, so it could not say how many were still live. It estimated that about 90% were for Samsung's internal services and about 10% could grant access to external services, and singled out the "just over 600" authentication tokens as the main concern because they could open other systems. GitGuardian's Mackenzie Jackson said internal source code "contains an increased amount of sensitive data yet remains a very leaky asset."

Timeline

DateEvent
25 February 2022NVIDIA confirms it is investigating a cyber incident later claimed by Lapsus$.
4 March 2022Lapsus$ leaks about 190GB of Samsung data in three archives via torrent.
7 March 2022Samsung confirms a breach involving source code for Galaxy devices and says no personal data of consumers or employees was included.
9 March 2022GitGuardian reports 6,695 secrets in the leaked Samsung code.

How it happened: the identity attack path

  1. Intrusion. Lapsus$ gained access to internal Samsung data by a route Samsung has not disclosed.
  2. Source code taken. The group took source code for device security, bootloaders, activation servers and account authentication, including content described as Samsung GitHub repositories.
  3. Secrets inside the code. The code contained 6,695 secrets, according to GitGuardian, from private keys to cloud and source control tokens.
  4. Public release. Lapsus$ published the archives by torrent, so every secret in the code became available to anyone who downloaded it.
  5. Exposure without confirmed use. No misuse of the secrets has been reported; their validity was not tested publicly.

Impact

  • Confirmed: Samsung confirmed a breach involving source code relating to the operation of Galaxy devices.
  • Claimed: Lapsus$ said the leak included TrustZone Trusted Applets, biometric unlock algorithms, bootloaders, Qualcomm code, activation servers and account authentication code; Samsung did not confirm the detail.
  • Secrets exposed: 6,695 secrets per GitGuardian, of which about 10% were estimated to reach external services; validity unknown and no misuse confirmed.
  • Not affected: personal information of consumers or employees, according to Samsung's initial analysis.
  • Potential: GitGuardian warned that leaked keys could give attackers access to internal infrastructure, and that exposed code could affect Samsung's ability to secure device updates.

What this means for NHI governance

Samsung's breach is usually remembered as a source code leak. For NHI governance it is a secrets leak. Nearly seven thousand credentials, many of them private keys and tokens for cloud and development platforms, sat in code that a single intrusion could copy and a single torrent could distribute. Whether or not any were still valid, every one had to be treated as compromised the moment the archive went public. Twitch's leak in 2021 showed the same pattern.

The fix is the same each time: keep secrets out of code, so a code leak is only a code leak; scan repositories and their history continuously so the inventory of exposed secrets is known before an attacker publishes it; and make rotation fast enough that thousands of keys can be replaced in days rather than months. Our Secrets Management Guide and Leaked Credential Response Playbook cover these controls.

Recommendations

  • Revoke and rotate every secret in leaked code. Treat all keys and tokens in a published repository as compromised, starting with those that reach external services. See the Leaked Credential Response Playbook.
  • Remove secrets from source code. Move keys and tokens into a secrets manager and load them at runtime. See our Secrets Management Guide.
  • Scan repositories and history before attackers do. Continuous secrets scanning gives you the inventory you will need on the day code leaks.
  • Protect private keys in hardware. Thousands of private keys in source code suggests keys used as files; signing and encryption keys belong in HSMs or key management services. See our Cryptographic Key Management Guide.
  • Scope cloud and platform tokens narrowly. A leaked token that reaches one bucket or repository does far less harm than one that reaches everything. See our API Key Management Guide.
  • Practise mass rotation. Test that you can rotate hundreds of credentials quickly, with owners recorded for each.

Frequently asked questions

What did Lapsus$ steal from Samsung?

Lapsus$ leaked about 190GB of data it said included source code for Samsung's TrustZone Trusted Applets, biometric unlock, bootloaders, activation servers and account authentication. Samsung confirmed the breach involved some source code relating to the operation of Galaxy devices.

Was customer data exposed in the Samsung leak?

Samsung said its initial analysis found the breach did not include the personal information of consumers or employees, and that it did not anticipate any impact on its business or customers.

How many secrets were in the leaked Samsung code?

GitGuardian reported 6,695 secrets, including private keys, AWS IAM keys, GitHub Enterprise and Artifactory tokens and Google credentials. It did not validate them, and estimated about 10% could reach external services.

NVIDIA Code-Signing Certificates Stolen 2022 · Twitch Breach 2021 · Samsung ChatGPT Source Code Leak 2023 · Secrets Management Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Most organisations do not know how many secrets their own source code holds until someone else counts them. We help teams find and remove secrets from code, assign owners and build the rotation capacity a leak demands. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org