logo

Red Hat confirms security incident after hackers breach GitLab instance

ID: 89e2cd3d-3bc9-5fe7-a6a4-4f650b2a8c19

STIX ID: report--89e2cd3d-3bc9-5fe7-a6a4-4f650b2a8c19

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2025-10-02

Date Updated: 2026-07-17

Author: Lawrence Abrams

...
...

Red Hat confirmed unauthorized access to a self-managed GitLab instance used by its Consulting division after an extortion group claiming the name Crimson Collective said it exfiltrated ~570GB from ~28,000 repositories including approximately 800 consulting engagement reports (CERs) that may contain sensitive configuration details and authentication tokens for many high-profile customers; the group published directory listings and attempted extortion. Red Hat says the issue is isolated to the consulting GitLab instance, has removed access, implemented additional hardening, is contacting affected customers, and continues its investigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.