How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign
ID: 0615d4d7-b0f3-5d39-b176-521f20169784
STIX ID: report--0615d4d7-b0f3-5d39-b176-521f20169784
Feed Name: Wiz Blog
Wiz CIRT investigated a mid-May–early June 2026 campaign in which attackers used compromised GitHub Personal Access Tokens to enumerate and mass-clone private repositories across multiple organizations, potentially exposing secrets (cloud credentials, API keys, private keys) and enabling follow-on abuse; the report reconstructs the attack timeline (reconnaissance, validation, mass cloning), prescribes containment and investigation steps (revoke tokens, expand timeline, identify leak source, assess blast radius, rotate credentials, hunt for misuse), and publishes IOCs (three user-agent strings and numerous AWS IPs) and detection recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
