• News/
  • https://www.zdnet.com/article/cybercrooks-breach-red-hats-private-gitlab-repos-what-we-know-about-affected-customers/

Cybercrooks breach Red Hat's private GitLab repos - what we know about affected customers

ZDNet
·
Steven Vaughan-Nichols
·
Published Oct 3, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. A security breach will occur in every company's life. This time, it's Linux and cloud powerhouse Red Hat's turn. A newly surfaced cybercrime group calling itself Crimson Collective (also known as Eye Of Providence) claimed responsibility for breaching Red Hat's private GitLab repositories and stealing customer information and confidential source code. Also: Hackers stole 1 billion records from Salesforce customer databases with this simple trick - don't fall for it The group made the claim late Thursday on Telegram, posting screenshots allegedly showing directory listings from internal Red Hat projects. Red Hat has confirmed the breach. Red Hat stated: "We recently detected unauthorized access to a GitLab instance used for internal Red Hat Consulting collaboration in select engagements. We promptly launched a thorough investigation, removed the unauthorized party's access, isolated the instance, and contacted the appropriate authorities. Our investigation, which is ongoing, found that an unauthorized third party had accessed and copied some data from this instance." The hackers claim to have swiped almost 570GB of data from 28,000 internal development repositories. This data allegedly includes approximately 800 Customer Engagement Reports (CERs). Red Hat CERs are detailed documents from Red Hat's consulting services that contain sensitive information about client environments, such as architecture diagrams, network configu...

Read full article

Affected Software

1 affected component
Red Hat GitLab

Frequently Asked Questions

1

Which Red Hat environment was affected?

Red Hat said the unauthorized access involved a GitLab instance used for internal Red Hat Consulting collaboration in select engagements. The article does not identify the specific customers or engagements affected.

2

What has Red Hat confirmed versus what is only claimed by the attackers?

Red Hat confirmed that an unauthorized third party accessed and copied some data from the GitLab instance. Crimson Collective claims it stole customer information and confidential source code, and posted screenshots it said showed internal project directory listings.

3

What response actions has Red Hat taken?

Red Hat said it removed the unauthorized party's access, isolated the affected instance, launched an investigation, and contacted appropriate authorities. Its investigation remains ongoing.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203