logo

Red Hat confirms security incident after hackers claim GitHub breach

ID: da078db8-44ab-52b6-b891-d1c1c0c966a9

STIX ID: report--da078db8-44ab-52b6-b891-d1c1c0c966a9

Feed Name: Bleeping Computer

Threat Score
78/100

Date Published: 2025-10-02

Date Updated: 2026-07-18

Author: Lawrence Abrams

...
...

Red Hat confirmed unauthorized access to a self-managed GitLab instance used by its Consulting division after an extortion group calling itself the Crimson Collective claimed to have stolen ~570GB from ~28,000 repositories, including Customer Engagement Reports that may contain sensitive infrastructure details and authentication tokens. The attackers posted directory listings and a CER index naming many high-profile organizations; Red Hat says the issue was isolated to the Consulting GitLab instance, removed unauthorized access, implemented hardening, and is notifying affected customers while investigations continue.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.