HomeSecurityRed Hat confirms data breach

Red Hat confirms data breach

Red Hat, the leading provider of open source software for enterprises, has officially confirmed a security breach, involving unauthorized access to the GitLab instance used by the Red Hat Consulting.

See also: Red Hat: Hackers claim breach of 28,000 private GitHub repositories

Red Hat confirms data breach

This confirmation comes after claims by the threat group known as the Crimson Collectivethat they extracted approximately 570GB of compressed data from 28,000 private repositories, marking one of the most significant source code breaches in recent cybersecurity history.

The breach specifically targeted a GitLab environment used for team collaboration on select customer engagements. According to the company's official statement, the malicious actor was able to gain access and copy sensitive data from this instance before security teams detected the intrusion.

The company immediately launched a comprehensive investigation, revoked the attacker's access, isolated the compromised instance, and contacted the appropriate law enforcement authorities.

The stolen data reportedly includes a vast array of sensitive technical information, including CI/CD secrets, pipeline configuration files, VPN connection profiles, infrastructure plans, Ansible playbooks, OpenShift deployment guides, container registry configurations, and Vault integration secrets.

See also: CISA: Race Condition vulnerability in the Linux kernel

Red Hat Enterprise Linux 8.2 - new improvements

Security researchers analyzing the breach data have identified references to thousands of organizations across multiple critical sectors, including major financial institutions like Citi, JPMC , and HSBC, telecommunications giants like Verizon and Telefonica, industrial companies like Siemens and Bosch, and even government entities like the U.S. Senate.

The breach represents a sophisticated supply chain attack vector that could potentially impact Red Hat's extensive customer ecosystem. The exposed repositories reportedly contain Infrastructure-as-Code (IaC), automated DevOps scripts, and credential management configurations that adversaries could use for secondary infiltration attempts against the company's consulting clients.

The presence of SSH keys, API tokens, and database connection strings within the compromised data creates multiple attack vectors for attackers seeking to establish persistent access to downstream. Security experts warn that leaked container registry configurations and Kubernetes deployment manifests could provide attackers with detailed plans to target cloud-native infrastructure across Red Hat’s entire customer base.

The exposure of GitLab CI/CD runner configurations and automated development pipelines is of particular concern to cybersecurity professionals, as these components often contain elevated privileges that are essential for enterprise software development and management.

See also: Sudo vulnerabilities allow root access on Linux distributions

Red Hat confirms data breach

Red Hat has implemented additional hardening measures to prevent further unauthorized access and said that preliminary analysis shows no impact to its core software supply chain or official software distribution channels. However, the company is continuing to conduct forensic analysis to determine the full extent of the impact on customers, with immediate notifications planned for any affected Red Hat Consulting customers.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS