Red Hat Confirms Data Breach After Hackers Claim to Steal 570GB of Private GitHub Repositories
Red Hat has confirmed a security incident involving unauthorized access to its internal GitLab instance used by the Red Hat Consulting team.
Red Hat has confirmed a security incident involving unauthorized access to its internal GitLab instance used by the Red Hat Consulting team.
The incident involved the exfiltration of approximately 570GB of compressed data from 28,000 private repositories by an unauthorized group. This represents a significant source code breach.
Compromise of Private GitLab Repository
The breach specifically targeted a GitLab environment utilized for collaboration within Red Hat Consulting during selected client engagements.
According to Red Hat's official statement, unauthorized access allowed for the copying of sensitive data before the company detected the intrusion. Red Hat has since revoked the attacker's access, isolated the compromised instance, and notified law enforcement authorities.
The stolen data includes a range of technical assets such as CI/CD secrets, pipeline configuration files, VPN connection profiles, infrastructure blueprints, Ansible playbooks, OpenShift deployment guides, container registry configurations, and Vault integration secrets.
Red Hat has confirmed a security incident involving unauthorized access to its internal GitLab instance used by the Red Hat Consulting team.
Analysis of the breach data identified references to various organizations across critical sectors, including financial institutions, telecommunications companies, industrial firms, and government entities.
This incident highlights a sophisticated supply chain attack vector with potential impacts on Red Hat's customer ecosystem. The exposed repositories contain Infrastructure-as-Code templates, DevOps automation scripts, and credential management configurations that could be leveraged for further attacks.
Additionally, the presence of SSH keys, API tokens, and database connection strings within the compromised data creates multiple attack vectors. The leaked container registry configurations and Kubernetes deployment manifests provide attackers with detailed blueprints for targeting cloud-native infrastructures.
The exposure of GitLab CI/CD runner configurations and automated deployment pipelines is of particular concern, as these components often contain elevated privileges necessary for enterprise software deployment and management.
Red Hat has implemented additional measures to prevent further unauthorized access and stated that preliminary analysis indicates no impact on their primary software supply chain or official software distribution channels. The company is conducting further forensic analysis to determine the full scope of customer impact and plans to notify affected clients directly.
This incident is unrelated to the recently disclosed CVE-2025-10725 vulnerability affecting Red Hat OpenShift AI services.
Based on reporting by Cyber Security News.
