EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2025-red-hat-gitlab-breach
058/430

File EL-0373HighOngoingData Breach / Supply Chain / Third-Party Data Exfiltration

Red Hat Consulting GitLab Breach

Also filed as Red Hat Crimson Collective Breach · Red Hat 570GB GitLab Leak

Major breach of a Red Hat Consulting GitLab instance resulting in the theft of 570GB of data, including thousands of internal repositories and ~800 Customer Engagement Reports (CERs).

  • #gitlab
  • #consulting-data
  • #source-code
  • #customer-data
  • #supply-chain
Notoriety8/10
Event
15 Sept 2025
Disclosed
2 Oct 2025
Target
Red Hat
Actor
Crimson Collective
Scale
570 GB
Status
Ongoing

01Summary

In mid-September 2025, the Crimson Collective gained unauthorized access to a self-hosted GitLab instance used by Red Hat Consulting. They exfiltrated ~570GB of compressed data from over 28,000 private repositories. The stolen data included sensitive Customer Engagement Reports containing architecture diagrams, network maps, credentials, and client configurations for hundreds of major organizations.

02Background

Red Hat Consulting provides enterprise services to many large organizations. This incident highlights risks in consulting repositories that often contain highly sensitive client environment details.

03Key revelations

  1. 01Extreme risk of embedded credentials in consulting deliverables.
  2. 02Supply chain exposure through professional services divisions.

04Technical analysis

Attackers accessed a dedicated GitLab environment used for client collaboration. No evidence of impact to Red Hat’s core products (RHEL, OpenShift) or public code repositories.

Attack vector
Unauthorized access to internal GitLab instance
Attack method
Data exfiltration and extortion
Initial access
Unknown (under investigation)
Exfiltration
Bulk data extraction

05Threat actor

Crimson Collective – extortion-focused group specializing in targeting development and consulting repositories.

Aliases

  • Scattered LAPSUS$ Hunters

Attribution sources

  • Red Hat official statement
  • BleepingComputer
  • Dark Reading

06Victims and impact

Additional victims

  • Over 800 client organizations (banks, telecoms, government agencies)

Countries affected

  • Global

07Data exposed

Data types

  • Internal Repositories
  • Customer Engagement Reports
  • Architecture Diagrams
  • Credentials
  • Client Configurations

08Financial damage

Significant reputational damage and potential downstream risk to Red Hat clients.

09Timeline

  1. 2025-09-15Approximate date of initial breach.
  2. 2025-10-01Crimson Collective publicly claims breach.
  3. 2025-10-02Red Hat confirms the incident.

10Reaction and fallout

Public reaction

Concern over potential exposure of critical infrastructure details.

Political impact

Raised questions about cybersecurity practices of major vendors serving government and critical infrastructure.

11Legal

Ongoing investigations.

12Aftermath

Security improvements

  • Isolation and hardening of consulting environments

13Significance and legacy

Significance

One of the largest consulting/supply-chain breaches of 2025, impacting hundreds of major organizations indirectly.

Legacy

Increased scrutiny on how vendors handle client data in professional services repositories.

14Disclosure and media

Authentication
Hacker claims and Red Hat confirmation

Publishing organisations

  • BleepingComputer
  • Dark Reading
  • Red Hat

15Field notes

  1. 01The breach exposed consulting reports for major clients including banks, telecoms, and U.S. government agencies.

16Resolution

Red Hat isolated the instance and continues investigation; data has been leaked.

17Sources

Official documents

  • Red Hat Security Update

References

  1. [1]Red Hat official blog
  2. [2]BleepingComputer reports
Fact sheetEL-0373

Dates

Event
15 Sept 2025
Started
15 Sept 2025
Discovered
1 Oct 2025
Disclosed
2 Oct 2025
Ongoing
Yes

Target

Organisation
Red Hat, Inc.
Type
Technology Company
Sector
Software / Open Source
Country
United States

Actor

Name
Crimson Collective
Type
Criminal Gang
Motivation
Financial gain through extortion and potential sale of sensitive consulting and client data.
Attribution
High
Status
Active
Arrested
No
Convicted
No

Data

Volume
570 GB
Sensitivity
High
Published
Yes
Sold (dark web)
Yes

Money

Crypto
Likely Bitcoin

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.