logo

New Gitloker attacks wipe GitHub repos in extortion scheme

ID: 5557c615-45e3-5fc4-aff6-516614c254db

STIX ID: report--5557c615-45e3-5fc4-aff6-516614c254db

Feed Name: Bleeping Computer

Threat Score
65/100

Date Published: 2024-06-06

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Attackers operating under the Telegram handle "Gitloker" are actively compromising GitHub accounts—apparently using stolen credentials—wiping repository contents, and leaving a README claiming they backed up victims' data and instructing victims to contact them on Telegram for recovery/extortion. The campaign has impacted dozens of repositories; the report also recalls prior GitHub breaches and advises users to enable MFA, review keys/apps, and monitor account activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.