Internal source code and data belonging to the New York Times were leaked to the 4chan forum after being stolen from GitHub repositories in January 2024, the Times confirmed.
See also: New Gitloker attacks delete GitHub repos

As first reported by VX-Underground, the internal data was leaked on Thursday by an anonymous user who posted a torrent to a 273GB file containing the stolen data.
"Basically all of the source code owned by The New York Times Company, 270 GB," the 4chan forum post states.
The malicious user shared a text file containing a complete list of the 6,223 folders that had been stolen from the New York Times GitHub repository.
The folder names indicate that a wide variety of information has been stolen, including IT documentation, infrastructure tools, and source code, which reportedly includes the viral game Wordle.
See also: GitHub warns of SAML auth bypass flaw
A “readme” file states that the malicious actor used an exposed GitHub token to gain access to the company’s repositories and steal data.

In a statement, the Times said the breach occurred in January 2024 after credentials for a third-party cloud-. A follow-up email confirmed that the code platform was GitHub. The New York Times said the breach of its GitHub account did not affect internal company systems and had no impact on its operations.
The Times leak is the second to be published on 4chan this week, the first being a leak of 415 MB of stolen internal documents for Disney's Club Penguin game .
It is not known whether it was the same person who carried out the New York Times and Disney GitHub breaches .
See also: Hackers exploit GitHub and FileZilla to spread Cocktail malware
Source code theft, such as that of the New York Times from the GitHub repository, is a serious security breach that can have significant implications for companies and developers. When source code is stolen, sensitive information, including proprietary algorithms, business logic, and proprietary techniques, can be exposed. Such a breachnot only undermines the integrity and reputation of the affected organization, but also carries the risk of financial loss and legal complications. Protecting source code through strong security measures, such as encryption, access controls, and regular security audits, is crucial to preventing such incidents and safeguarding intellectual property.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
