On 23 February 2022 NVIDIA became aware of a cybersecurity incident against its IT resources, later tied publicly to Lapsus$. According to NVIDIA’s customer help disclosure, the actor took employee passwords and some proprietary information and began leaking material online. Later reporting put roughly 71,335 NTLM hashes in circulation, and every employee had to change passwords. Public reporting does not establish how the first foothold was won.

What is documented is post-foothold damage: reusable workforce credential material left the environment, NTLM hashes suitable for offline and pass-the-hash style abuse circulated, and proprietary files hit the open web. NVIDIA’s primary notice does not document MFA fatigue, helpdesk resets, AiTM phishing, or any other named interactive MFA path for this breach. Microsoft’s separate DEV-0537 tracking of Lapsus$ group techniques is adjacent context for the actor, not proof of how NVIDIA was entered.

If you want the prevention angle on what MFA can and cannot claim after password and NTLM material is already stolen, read the related article on mfa2point0.com.

FAQ

What did Lapsus$ actually take from NVIDIA?

Lapsus$ took employee passwords and other credential material plus some proprietary information from NVIDIA during the February 2022 intrusion. According to NVIDIA’s disclosure, the actor began leaking material online, and all employees were required to change passwords. Later public reporting cited roughly 71,335 NTLM hashes circulating from the incident. Public reporting does not establish a full inventory of every file class beyond the password material and proprietary information NVIDIA confirmed.

How did the attackers get into NVIDIA in the first place?

Public reporting does not establish the initial access method for the NVIDIA Lapsus$ intrusion. NVIDIA’s primary notice confirms a cybersecurity incident impacting IT resources and later theft of employee passwords and proprietary information. It does not name a phishing kit, helpdesk reset, MFA fatigue campaign, device-code flow, or other workforce login step. Treat any specific “how they logged in” story that is not in that notice as unproven for this breach.

Why did NVIDIA force every employee to change passwords?

NVIDIA forced company-wide password changes because employee passwords and related credential material had been stolen and were being exposed. Once reusable password secrets and NTLM hashes leave the environment, defenders cannot assume those secrets stay private. A mass reset is containment for credential material already in attacker hands, not proof of which login ceremony failed on day one.

Did this breach defeat MFA at the login screen?

Public reporting does not establish that MFA was defeated, bypassed, or even challenged at a NVIDIA workforce login for this incident. The confirmed problem is theft and leak of employee password material and NTLM hashes after the actor already had a network position. Offline hash circulation and pass-the-hash style reuse are post-foothold credential problems. They are not the same story as a live OTP relay or push-approval phishing kit at sign-in.

Are the ~71,335 NTLM hashes the same as a live Microsoft 365 session theft?

No. The roughly 71,335 NTLM hashes reported in later coverage are offline credential material, typically useful for hash replay and pass-the-hash style movement after a foothold, not a captured cloud SSO cookie from a proxied login. NVIDIA’s disclosure centers on employee passwords, credential material, proprietary leaks, and mandatory password changes. Public reporting does not establish AiTM session-cookie harvest as the documented NVIDIA path.