logo

How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign

ID: 0615d4d7-b0f3-5d39-b176-521f20169784

STIX ID: report--0615d4d7-b0f3-5d39-b176-521f20169784

Feed Name: Wiz Blog

Threat Score
75/100

Date Published: 2026-08-13

Date Updated: 2026-08-13

Author: Eden Abergil

...
...

Wiz CIRT investigated a mid-May–early June 2026 campaign in which attackers used compromised GitHub Personal Access Tokens to enumerate and mass-clone private repositories across multiple organizations, potentially exposing secrets (cloud credentials, API keys, private keys) and enabling follow-on abuse; the report reconstructs the attack timeline (reconnaissance, validation, mass cloning), prescribes containment and investigation steps (revoke tokens, expand timeline, identify leak source, assess blast radius, rotate credentials, hunt for misuse), and publishes IOCs (three user-agent strings and numerous AWS IPs) and detection recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.