01Summary
In mid-September 2025, the Crimson Collective gained unauthorized access to a self-hosted GitLab instance used by Red Hat Consulting. They exfiltrated ~570GB of compressed data from over 28,000 private repositories. The stolen data included sensitive Customer Engagement Reports containing architecture diagrams, network maps, credentials, and client configurations for hundreds of major organizations.
02Background
Red Hat Consulting provides enterprise services to many large organizations. This incident highlights risks in consulting repositories that often contain highly sensitive client environment details.
03Key revelations
- 01Extreme risk of embedded credentials in consulting deliverables.
- 02Supply chain exposure through professional services divisions.
04Technical analysis
Attackers accessed a dedicated GitLab environment used for client collaboration. No evidence of impact to Red Hat’s core products (RHEL, OpenShift) or public code repositories.
- Attack vector
- Unauthorized access to internal GitLab instance
- Attack method
- Data exfiltration and extortion
- Initial access
- Unknown (under investigation)
- Exfiltration
- Bulk data extraction
05Threat actor
Crimson Collective – extortion-focused group specializing in targeting development and consulting repositories.
Aliases
- Scattered LAPSUS$ Hunters
Attribution sources
- Red Hat official statement
- BleepingComputer
- Dark Reading
06Victims and impact
Additional victims
- Over 800 client organizations (banks, telecoms, government agencies)
Countries affected
- Global
07Data exposed
Data types
- Internal Repositories
- Customer Engagement Reports
- Architecture Diagrams
- Credentials
- Client Configurations
08Financial damage
Significant reputational damage and potential downstream risk to Red Hat clients.
09Timeline
- 2025-09-15Approximate date of initial breach.
- 2025-10-01Crimson Collective publicly claims breach.
- 2025-10-02Red Hat confirms the incident.
10Reaction and fallout
Public reaction
Concern over potential exposure of critical infrastructure details.
Political impact
Raised questions about cybersecurity practices of major vendors serving government and critical infrastructure.
11Legal
Ongoing investigations.
12Aftermath
Security improvements
- Isolation and hardening of consulting environments
13Significance and legacy
Significance
One of the largest consulting/supply-chain breaches of 2025, impacting hundreds of major organizations indirectly.
Legacy
Increased scrutiny on how vendors handle client data in professional services repositories.
14Disclosure and media
- Authentication
- Hacker claims and Red Hat confirmation
Publishing organisations
- BleepingComputer
- Dark Reading
- Red Hat
15Field notes
- 01The breach exposed consulting reports for major clients including banks, telecoms, and U.S. government agencies.
16Resolution
Red Hat isolated the instance and continues investigation; data has been leaked.
17Sources
Official documents
- Red Hat Security Update
References
- [1]Red Hat official blog
- [2]BleepingComputer reports









