North America
Red Hat
On October 2, Red Hat confirmed that its consulting GitLab instance had been compromised, allegedly affecting data from more than 800 organizations across sectors such as banking, telecom and government.
A day earlier, on October 1, the cybercrime group known as Crimson Collective publicly disclosed the breach, claiming to have stolen 570GB of compressed data from more than 28,000 repositories. The stolen data reportedly includes Customer Engagement Reports (CERs) tied to major organizations, including Bank of America, JPMorgan Chase, Verizon, AT&T, the U.S. Navy, the U.S. Senate and the National Security Agency. Red Hat has since confirmed that unauthorized access occurred in a GitLab instance used for internal Red Hat Consulting activities.
While the company stated that the incident is confined to its consulting GitLab environment, the cybercrime group continues to share samples of the allegedly stolen repositories, claiming the breach is much larger than Red Hat's initial assessment.
How it could affect your business
When a major vendor is compromised, security teams should quickly assess any direct business relationships with the affected organization. It's important to review shared credentials, access permissions and sensitive infrastructure details to ensure your systems haven't been indirectly exposed.
