Red Hat
Disclosed Oct 2, 202511 months agoConfirmed
Crimson Collective steals Red Hat consulting GitLab repositories
Red Hat confirmed a security incident involving a GitLab instance used by its consulting business after the Crimson Collective claimed to have stolen about 570GB from 28,000 internal repositories, including around 800 Customer Engagement Reports with customer infrastructure details and tokens. ShinyHunters later joined the extortion.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Oct 2, 2025 |
| Attack | Hacking |
| Data exposed | Source code, Internal documents, Credentials and tokens, Other |
| Sector | Tech · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Red Hat security updateaccess.redhat.com · The organization | The organization |
| Red Hat confirms security incident after hackers breach GitLab instancebleepingcomputer.com · News | News |
| Red Hat data breach escalates as ShinyHunters joins extortionbleepingcomputer.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Oct 2, 2025 |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research), confirmed by Research. Record counts are as reported. Not legal advice.