EmeraldWhale's Massive Git Breach Highlights Config Gaps
ID: 87d7d290-2f8d-5580-b63e-e4c9a150f6c4
STIX ID: report--87d7d290-2f8d-5580-b63e-e4c9a150f6c4
Feed Name: Dark Reading
Date Published: 2024-11-01
Date Updated: 2026-04-21
Author: Kristina Beek, Associate Editor, Dark Reading
Researchers uncovered the EmeraldWhale campaign, a global operation that harvested hardcoded credentials and cloud secrets by scanning for exposed Git configuration files and misconfigured cloud services (including an exposed S3 bucket). The attackers cloned over 10,000 private repositories, dumped more than 15,000 credentials, used phishing and custom tools to obtain access, and monetized the data by selling target lists on underground marketplaces, highlighting the need to secure source code, secrets, and cloud configurations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
