Red Hat experienced a significant security incident involving the unauthorized access and exfiltration of data from its private GitHub repositories. The extortion group known as the Crimson Collective claimed responsibility for the breach, stating they stole approximately 570GB of compressed data, which included over 28,000 internal projects and hundreds of Customer Engagement Reports (CERs). These CERs are consultancy documents that often contain highly sensitive information such as architecture diagrams, configuration details, authentication tokens, database connection strings, and network maps, effectively providing blueprints of customer IT environments. The attackers published file listings and shared samples of the stolen data, which were verified by journalists to contain configuration snippets and references to customer systems. The group asserted that the compromised data spanned from 2020 to 2025 and involved major organizations across banking, telecom, government, airlines, and public-sector sectors, with specific mentions of companies like Citi, Verizon, Siemens, Bosch, JPMC, HSBC, and even the U.S. Senate. The Crimson Collective also claimed to have found authentication tokens and other credentials within the repositories and CERs, which they allegedly used to access downstream customer infrastructure. They stated that they attempted to warn affected customers but were ignored. Red Hat confirmed the security incident related to its consulting business but did not verify the full extent of the attackers' claims or the specific details of the breach. The company emphasized that, at the time, there was no evidence the incident impacted other Red Hat services or products, and they expressed confidence in the integrity of their software supply chain. The breach was first disclosed by the attackers on Telegram, where they posted a full file tree, CER list, and screenshots as proof. The incident has raised concerns about the exposure of sensitive customer data and the potential for further attacks leveraging the stolen credentials and infrastructure details. Red Hat has not publicly disclosed how the attackers gained access or whether they received any extortion demands, though the Crimson Collective claimed to have contacted the company and received only a generic response. The breach highlights the risks associated with storing sensitive customer information and credentials in internal repositories and the potential downstream impact on customers when such data is compromised. Security researchers have warned that the exposed information could be used to target Red Hat's clients with tailored attacks, given the detailed nature of the stolen CERs. The incident underscores the importance of robust access controls, credential management, and rapid incident response in protecting both corporate and customer assets.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
Rapid7 published research describing Crimson Collective as a cloud-focused threat group targeting AWS environments using stolen long-term access keys, privilege escalation, snapshot abuse, and SES-based extortion notes. The report connected the group to the Red Hat incident and provided new technical details on its operations.
New reports said the Red Hat attackers were collaborating with a group referred to as 'Scattered Lapsus$ Hunters' to intensify extortion pressure. Coverage described the effort as an escalation of the campaign beyond the initial breach claim.
Additional reporting said the stolen consulting data related to more than 5,000 enterprise customers and included sample engagement reports and exposed certificates. These disclosures expanded the apparent scope and potential downstream impact of the breach.
GitLab stated that the incident involved Red Hat's self-managed GitLab Community Edition instance, not GitLab-managed infrastructure. This clarified that the breach was limited to Red Hat's own deployment.
As the investigation progressed, Red Hat involved authorities and began directly notifying impacted consulting customers. Customers were advised to rotate credentials and review their environments for possible exposure.
Red Hat acknowledged unauthorized access to the GitLab instance, said some data was copied, and began containment and remediation measures such as isolating the affected system and revoking access. The company stated there was no evidence its software supply chain, products, or other services were impacted.
On or before the first public reports, Crimson Collective publicly claimed it had exfiltrated roughly 570GB of data from about 28,000 Red Hat internal repositories, including around 800 customer engagement records. The group said the material contained credentials, infrastructure details, and consulting data tied to major enterprises and government entities.
After stealing data, the extortion group Crimson Collective contacted Red Hat and demanded payment. Red Hat did not comply with the demand.
Attackers gained unauthorized access to a self-hosted GitLab instance used by Red Hat Consulting and copied data from internal repositories. Multiple reports say the intrusion occurred about two weeks before public disclosure.
24 references tracked. Mallory keeps watching after this page renders.
finra.org
Open sourcedarkreading.com
Open sourcebleepingcomputer.com
Open sourcetheregister.com
Open sourcebleepingcomputer.com
Open source404media.co
Open sourcesecurityaffairs.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.