Red Hat, one of the world's leading open source software companies and a subsidiary of the IBM, is facing extortion from the notorious cybercrime group ShinyHunters, following a data breach revealed last week.

Samples of stolen “Customer Engagement Reports” (CERs) – confidential documents containing technical information about customers – have already appeared on a leak website operated under the control of ShinyHunters, with a warning that the entire material will be made public on October 10th if the ransom demand is not met.
From “Crimson Collective” to ShinyHunters: A hacker alliance
The story began when the Crimson Collective group claimed to have extracted 570 GB of compressed data from more than 28,000 internal Red Hat repositories. The files included about 800 CER reports, documents containing technical details of infrastructure, networks, and platforms of customers, which allegedly include big names like Walmart, HSBC, Bank of Canada , and the Department of Defense.
After receiving no response to the ransom demand, the Crimson Collective announced that they had joined forces with ShinyHunters – a well-known group with a long history of attacks and extortion – to escalate the pressure on Red Hat.
See also: LinkedIn sues ProAPIs for data scraping
In their joint statement via Telegram, the hackers stated: "On April 4, 1949, the great NATO was created, but what if today's new alliance was bigger than that? But for a greater purpose, to destroy companies."
«What if Crimson's brilliance extended even further?».
"Regarding the current announcement that concerns us, we will be working with ShinyHunter for future attacks and releases," Crimson Collective threat actors told BleepingComputer.
This report suggests a coordinated hacking alliance, targeting not only Red Hat but also other major technology companies.

Red Hat confirms breach
Red Hat confirmed the breach to BleepingComputer, explaining that its GitLab presence, which was used for internal consulting services. According to the company, the incident does not affect its core products or infrastructure , but remains under investigation.
However, the existence of exposed Customer Engagement Reports raises concerns, as such reports may reveal technically sensitive information that could be exploited for future cyberattacks against third parties.
ShinyHunters as an “extortion as a service” (EaaS)
ShinyHunters is known in the global cybersecurity community as a group with a number of high-profile attacks. According to analysts, it has now transformed into an “Extortion-as-a-Service” (EaaS) model — a model where it acts as an extortion intermediary on behalf of other groups.
As the group itself revealed in communication with BleepingComputer, it receives 25% to 30% of the revenue from ransom payments, while the remaining 70-75% is attributed to the original perpetrators.
See also: Huawei – Data Breach: Hacker says he is selling source code
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This model is reminiscent of the practices of ransomware-as-a-service (RaaS) gangs, where malware is delivered “on demand” and the profits are shared.
A new “extortion ecosystem” in cyberspace
ShinyHunters is not the only group to follow this practice. Groups like Lapsus$ and RansomedVC have also adopted hybrid business models, combining hacking techniques, extortion, and publicity through “data leak portals” – websites where samples of stolen data are published to pressure victims.
ShinyHunters' new extortion website now hosts listings not only from Red Hat, but also from S&P Global , which had previously denied claims of a breach. However, recently posted data samples appear to be from internal company files , also due for release on October 10th .
Politically and psychologically motivated attacks
Beyond the financial benefits, the hackers’ announcements also show an ideological undertone. The Crimson Collective and ShinyHunters use rhetoric of “anti-capitalist activism,” presenting their attacks as a “reaction to corporate dominance and data exploitation.
Experts warn that such narratives function as propaganda, designed to legitimize criminal actions and attract new hackers with ideological motivations.

Security community reaction
Cybersecurity analysts see the Red Hat incident as a wake-up call for how companies manage internal repositories and advisory reports .
See also: Data breach at Doctors Imaging Group
Experts recommend immediately strengthening monitoring of GitLab/GitHub environments, separating production and consulting project environments, and implementing Zero Trust policies to limit damage in the event of a breach.
Towards a new wave of “professional blackmail”
The Red Hat incident confirms the transition of cybercrime to a more structured, “operational” form. Extortion is no longer a spontaneous act of individual hackers, but a service to third parties, with contracts, profit shares and even “customer support.”
If ShinyHunters continues to expand their network, we may see the birth of a full EaaS ecosystem, where any cybercriminal can “rent” extortion infrastructure — with businesses being the next wave of targets.
Red Hat's message and the stakes
Although Red Hat has not publicly responded to the latest threats, its stance so far shows a determination not to give in.
But the case highlights something deeper: in a world where transparency and trust are central values of open source, such an attack threatens not just one company — but the entire philosophy of collaboration and security on which the modern technology ecosystem is based.
Source: www.bleepingcomputer.com
