• News/
  • https://www.bleepingcomputer.com/news/security/red-hat-confirms-security-incident-after-hackers-claim-gitlab-breach/

Red Hat confirms security incident after hackers claim GitLab breach

BleepingComputer
·
Lawrence Abrams
·
Published Oct 2, 2025
·
Updated

Correction: After publishing, Red Hat confirmed that it was a GitLab account breach, not GitHub. An extortion group calling itself the Crimson Collective claims to have breached Red Hat's private GitLab repositories, stealing nearly 570GB of compressed data across 28,000 internal projects. This data allegedly includes approximately 800 Customer Engagement Reports (CERs), which can contain sensitive information about a customer's network and platforms. A CER is a consulting document prepared for clients that often contains infrastructure details, configuration data, authentication tokens, and other information that could be abused to breach customer networks. Red Hat confirmed that it suffered a security incident related to its consulting business, but would not verify any of the attacker's claims regarding the stolen GitLab repositories and customer CERs. "Red Hat is aware of reports regarding a security incident related to our consulting business and we have initiated necessary remediation steps," Red Hat told BleepingComputer. "The security and integrity of our systems and the data entrusted to us are our highest priority. At this time, we have no reason to believe the security issue impacts any of our other Red Hat services or products and are highly confident in the integrity of our software supply chain." While Red Hat did not respond to any further questions about the breach, the hackers told BleepingComputer that the intrusion occurred approximately two weeks ago. The...

Read full article

Affected Software

1 affected component
Red Hat GitLab

Frequently Asked Questions

1

What has Red Hat confirmed, and what remains unverified?

Red Hat confirmed a security incident related to its consulting business and said it initiated remediation steps. It did not verify the Crimson Collective's claims that private GitLab repositories or customer engagement reports were stolen.

2

Which customers could be affected if the attackers' claims are accurate?

The alleged stolen data includes roughly 800 Customer Engagement Reports prepared for consulting clients. These reports can contain customer network and platform details, infrastructure information, configuration data, and authentication tokens.

3

Why would stolen Customer Engagement Reports pose a security risk?

Such reports may provide information that could be abused to breach customer networks, including infrastructure details, configuration data, and authentication tokens. The presence of these reports in the alleged theft has not been confirmed by Red Hat.

4

Was the claimed breach of GitHub or GitLab?

The article was corrected to state that the claimed breach involved a Red Hat GitLab account, not GitHub.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203