logo

EmeraldWhale's Massive Git Breach Highlights Config Gaps

ID: 87d7d290-2f8d-5580-b63e-e4c9a150f6c4

STIX ID: report--87d7d290-2f8d-5580-b63e-e4c9a150f6c4

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-11-01

Date Updated: 2026-04-21

Author: Kristina Beek, Associate Editor, Dark Reading

...
...

Researchers uncovered the EmeraldWhale campaign, a global operation that harvested hardcoded credentials and cloud secrets by scanning for exposed Git configuration files and misconfigured cloud services (including an exposed S3 bucket). The attackers cloned over 10,000 private repositories, dumped more than 15,000 credentials, used phishing and custom tools to obtain access, and monetized the data by selling target lists on underground marketplaces, highlighting the need to secure source code, secrets, and cloud configurations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.