HomeSecurityRed Hat: Hackers claim breach of 28,000 private GitHub repositories

Red Hat: Hackers claim breach of 28,000 private GitHub repositories

A ransomware group, known as the Crimson Collective, claims to have breached Red Hat's private GitHub repositories, obtaining nearly 570GB of compressed data from 28,000 internal repositories.

Red Hat Hackers breach GitHub repositories

This data theft is considered one of the most significant breaches in the history of technology, as it involves the unauthorized extraction of source code and sensitive confidential information.

See also: Extortion emails claim Oracle E-Business Suite data theft

The stolen repositories are reportedly linked to thousands of organizations across multiple industries, including major banks, telecommunications, airlines, and government agencies. Notable names cited include Citi, Verizon, Siemens, Bosch, JPMC, HSBC, Merrick Bank, Telstra, Telefonica, and even the US Senate.

The variety of customers reported highlights the potential scale and risk to critical supply chains worldwide — if the allegations of the breach are accurate.

Red Hat: Hackers claim breach of 28,000 private GitHub repositories

Red Hat: Critical data breach

What makes Crimson Collective’s claims particularly troubling is the nature of the leaked content. Initial reviews indicate that the stolen data includes credentials, CI/CD secrets, pipeline configuration files, VPN connection profiles, infrastructure blueprints, inventories, Ansible playbooks, OpenShift deployment guides, CI/CD runner instructions, container registry configurations, Vault integration secrets, backup files, and GitHub/GitLab configuration templates.

See also: New WireTap attack extracts Intel SGX ECDSA key

Attackers could use the stolen information for secondary attacks or extortion attempts. Security professionals warn that exposed credentials and infrastructure details can become very dangerous, especially for organizations that rely heavily on automated DevOps and Infrastructure-as-Code (IaC) paradigms.

Red Hat is not alone in facing the risk of credentials or configuration files appearing in unexpected code repositories. Recent security research has highlighted the dangers of Shadow IT, where personal or side project repositories by employees inadvertently expose sensitive corporate secrets (sometimes by providing privileged access to internal corporate containers or cloud infrastructure). This exposure can lead to systemic risks beyond the original organization, affecting users and partners.

See also: OneLogin bug allows API Keys to be used to steal OIDC secrets

Red Hat: Hackers claim breach of 28,000 private GitHub repositories

This breach appears to be a powerful illustration of the multi-layered risk of the supply chain: attack paths can traverse CI/CD systems, container registries, automation playbooks, and public/private configuration backups, multiplying the impact for both Red Hat and its customers.

The Red Hat has not yet made a public statement confirming or denying any connection with its own infrastructure. The claims of the Crimson Collective and their possible impacts on the entire industry continue to evolve. All eyes remain focused on Red Hat, its customers, and the global supply chain as researchers strive to limit what may be one of the broadest source code disclosures recorded.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS