logo

Hackers find 15,000 credentials by scanning for git configuration

ID: 98a5e926-8b0c-5020-bd14-dd4570ed8dee

STIX ID: report--98a5e926-8b0c-5020-bd14-dd4570ed8dee

Feed Name: CyberScoop

Threat Score
65/100

Date Published: 2024-10-30

Date Updated: 2026-04-21

Author: Christian Vasquez

...
...

Sysdig discovered an open Amazon S3 bucket holding more than 1 TB of data attributed to an operation called EMERALDWHALE that harvested over 15,000 cloud and email service credentials by targeting exposed Git configuration files. The collected data included validated keys, access to private repositories and malicious tools; researchers observed activity from August–September and assessed the credentials are being used for spam, phishing and resale on underground markets, highlighting automated, low-effort but high-impact leakage paths from exposed repositories and configuration files.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.