The Register Home Page

back to article Cybercrims claim raid on 28,000 Red Hat repos, say they have sensitive customer files

A hacking crew claims to have broken into Red Hat's private GitLab repositories, exfiltrating some 570GB of compressed data, including sensitive documents belonging to customers.  An extortion group calling itself "the Crimson Collective" posted on Telegram that it accessed more than 28,000 internal repos and stole hundreds of …

  1. VoiceOfTruth Silver badge

    This is another example of why cyber so-called security is nigh on impossible for average Joe

    Yesterday we had the report about schools being hacked: https://www.theregister.com/2025/10/01/school_cyberattack_recovery/. Some bigwigs (it doesn't matter who, they all say the same thing, whether it's schools or hospitals or supermarkets) said effectively that "schools must do better cyber security".

    I call BS on that. They are empty words from people who don't have to do it.

    If Solarwinds can't do it, if Oracle can't do it, if Red Hat (apparently) can't do it, if M&S can't do it, if Harrods can't do it, if hospitals can't do it, if banks can't do it, then don't expect average Joe to be able to do it. I don't include Cisco in the aforementioned list as they seem to have adopted the ethos of 'backdoors and security holes by design'.

    We have AV vendors selling products which are mostly catching up with the latest strains of $malware. Their much-vaunted 'heuristics' seems to work some of the time, but not all the time. What hope is their for average Joe?

    1. Doctor Syntax Silver badge

      Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

      Why should Red Hat (or anyone else for that matter) store private information on Github rather than setting up their own, private repository? The answer, of course, is convenience. Let somebody else do it. In Red Hat's case they could scarcely claim they lack the skills. But it enlarges the attack surface. Maybe someone else in the Red Hat supply chain also had access to it and maybe somebody else had access to them.

      It's yet another supply chain attack and if companies don't know by now that long supply chains are vulnerable - especially to social engineering attacks on their staff - we can be sure the attackers do.

      1. VoiceOfTruth Silver badge

        Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

        >> Why should Red Hat (or anyone else for that matter) store private information on Github rather than setting up their own, private repository?

        I think by 'private repository' you mean 'in house'. I agree. I think many Reg readers would agree with the general statement 'in the cloud means on somebody else's computer'. Presumably it was cheaper and more convenient. Buy it in, don't build it...

        The problem with Red Hat runs deeper. Companies trusted Red Hat to do some work for them, presumably they couldn't do it themselves. So those companies put their data on another Red Hat's computers, complete with wordy legal agreements. Red Hat then put their customers' data on another GitHub's computers, complete with wordy legal agreements. One hack now means (I'm guessing here) dozens of affected companies down the line.

        This should be cause for a big re-think. But that won't happen. We'll get the usual platitudes about how "security is important to us", as they do insecure things.

        1. Doctor Syntax Silver badge

          Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

          "This should be cause for a big re-think. But that won't happen."

          It might not happen to those in the supply chain. But as the M&Ss of this world who've been hit review their operations (as they should) or those not yet hit look around, they're the ones likely to be making the big re-think.

        2. that one in the corner Silver badge

          Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

          > Presumably it was cheaper and more convenient

          "We need to let the clients and our in-house team share access to these repos; can we let them log into one of our servers? Maybe we could do something to isolate each client with their own server instance?"

          "Anyone around here know how to set that up? No? Ok, nice idea, but no go: GitHub it is."

          1. Doctor Syntax Silver badge

            Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

            This is Red Hat. Somebody there should know.

            1. Anonymous Coward
              Anonymous Coward

              Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

              *Was* RedHat. Now IBM have had their grubby hands on it, there is no knowing what mess there is there now.

            2. stiine Silver badge

              Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

              You're presuming that IBM didn't make them redundant, aren't you.

        3. Doctor Syntax Silver badge

          Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

          "I think by 'private repository' you mean 'in house'"

          Like I said, private. The one needs the other.

    2. EricM Silver badge

      Re: What hope is there for average Joe?

      Basically: In every instance you mentioned: Complexity killed.

      Therefore, to "do better cyber security":

      Reduce complexity and put "keep it simple" back on the priority list.

      Avoid complex and convenient all-in-one solutions that promise to integrate everything with everything "seamlessly" (example: Office365, Entra ID, Azure).

      Avoid complex runtimes that could scale (usually) far beyond your needs but introduce their own set of problems (example: Kubernetes).

      Avoid snake oil security products that promise to make you secure by just installing them (example: _every_ big Cybersecurity vendor).

      Deploy only, what is essentially needed, keep the number of technology dependencies to a minimum. Manage your SBOM by starting to reduce it with priority.

      Deploy only solutions your team is able to fully understand.

      Don't "manage" the remaining, now fully understood security problems, solve them.

      A reasonable level of security is not "nigh impossible" but can be damn inconvenient... You act slower, more expensive and deploy less new "solutions", that are less "integrated"...

      An organization needs to accept that trade off - instead of pushing for the deploy of the latest and shiniest tools and gadgets.

    3. sitta_europea

      Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

      " ... AV vendors selling products which ... work some of the time ..."

      For about the last five years I've been measuring the success of over a dozen vendors at spotting malware in our incoming email.

      The way it works is that when my own software spots something dangerous, it sends it to one of the multi-vendor scanning sites and logs the results.

      I manually check every result.

      From just under 8500 tests since early 2021 here are the bald, rough, average percentage success results:

      % VENDOR

      ------------------------------------

      83.6 fortinet.com

      80.3 cyren.com

      76.3 avast.com

      71.0 gdatasoftware.com

      66.9 kaspersky.com

      65.1 bitdefender.com

      64.9 escanav.com

      60.9 ikarussecurity.com

      59.0 sophos.com

      51.0 f-secure.com

      45.3 drweb.com

      43.8 eset.com

      17.6 anti-virus.by

      13.5 k7computing.com

      5.9 f-prot.com

      4.3 trendmicro.com

      3.8 clamav.net

      These results do mask some changes - for example Avast seems to have improved considerably this year - but as you can see, even the best aren't nearly good enough and everything else ranges from mediocre (missing around one in six) to pretty much hopeless in my view (rather worse than missing 19 out of 20). They also show results for pretty basic installations, it's possible to get better results from anything with a bit of (significant, diligent and non-trivial) work.

      Despite what the banks, the health services and our governments will try to tell us, if We The People use consumer-grade computing there is no realistic way that we can properly protect ourselves from these threats. Using hardware and software which is far removed from consumer-grade, I protect my nearest and dearest, my own business, and a couple of other businesses. AFAICT more or less everybody else is at great risk - as the pages of El Reg bear witness.

      Even with the huge amount of effort that I put into security, I can't give any guarantees. I have never used Internet banking. Given my age, it seems likely that I never will.

      1. Anonymous Coward
        Anonymous Coward

        Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

        I don't actually doubt your results — the reality is likely much worse — but I can see a potential if minor methodological flaw where your system's false negatives penalize those systems that have the same failing. Ideally all the incoming† email should scanned and scored by all systems and those results compared.

        † I also advocate scanning outgoing email as being of equal or greater importance.

        1. Anonymous Coward
          Anonymous Coward

          Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

          re: scanning outbound email

          Only if you care about your customers.

      2. FirstTangoInParis Silver badge

        Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

        > I have never used Internet banking.

        You already have no choice in this matter. Branches are closing or have already closed en masse with staff powerless to explain why, even when the branch is in a prime position in the local well-used shopping centre and regularly has queues of people waiting to be served. You cannot even speak to a human who works for the bank unless you hold a considerable bucket load of money with them or are a business when they will allocate you a human. You get a chatbot who is dumb as can be and will parrot the web site you have already read to get an answer. On asking to chat to a human, one bank at least effectively emails the one human who still works there, who sends back the same web site garbage after at least 2 hours.

        If you have offspring, they will have to do the internet banking for you. Give them Power of Attorney and let them haggle it out with the bots.

    4. Lee D Silver badge

      Re: This is another example of why cyber so-called security is nigh on impossible for average Joe

      Literally how I presented cybersecurity to a school's management, staff, etc.

      We can't defend against it. We absolutely cannot. We can do some stuff but so much is just generic computing nowadays that I'm far more reliant on staff not clicking an email than Microsoft not screwing up the system. Our security is literally in the hands of untrained random people.

      We can only hope to "outrun the other guy being chased by the bear". That's it.

      If we were ever particularly targetted... we're dead in the water. Even our cyberinsurers agree on that. All we can do is hope to stay under the radar, not give off "we have dumb IT" vibes on our websites and services, and cross our fingers.

      The only real solution is a return to actual, limited, permissioned IT. You want to add a student record? Press 1. You want to Edit? Press 2.

      If you don't limit the interface, but instead every doughnut is running a full Windows OS with a thousand apps and programs, with access to huge Sharepoints and OneDrive and clicking on thousands of emails in a program that automatically opens them in whatever it feels like.. it's already game over.

      The old terminal system I used in an international haulage firm 30+ years ago as part of my work experience was infinitely more secure than anything we have nowadays. You could only press certain buttons. You could only do certain things. You could only do that from certain locations. It worked. Everyone had what they needed and nothing more.

      I remember them - at the time - trying to show off their new (Windows 95/98?) machine and how it was the future of their business and even as a geeky kid back then... I was thinking, that's not a great idea. So now everyone is "running as admin", everyone can modify all files on that drive, and it's full of nonsense like Active Desktop and loaded up with games, etc. I honestly had to do a kind of "Yeah, that sounds... interesting" thing when they kept crowing about how wonderful it all was that they would have different desktop backgrounds etc. And all I could think of was the number of times that my classmate and I had compromised my school's 3.1 / Netware / 95 network repeatedly with some stupendously simple things (literally "admin-rights" on Netware and complete control of the machines... I'm not joking).

      Sorry, but general purpose computing and cloud computing too... they are basically just huge great bullseyes on all our backs. We're not going to get away from that. It's like trying to lock up a prisoner who is allowed to do anything they like, and roam anywhere they like, and interact with anyone they like, and bring in any visitor they like...

  2. Anonymous Coward
    Anonymous Coward

    And Then There's The "Security vs Privacy" Thing

    So......all my important documents are like this:

    (1) Plain text versions are air-gapped (off line)

    (2) Online versions are encrypted using chacha20 (three passes, three keys).

    (3) Of course, the three keys are stored somewhere very remote (online, off line, who knows)

    Now these online documents might not be particularly "secure"......but I guess they are "private"????

  3. John Brown (no body) Silver badge

    Why are Red Hat not confirming or denying this?

    I thought even the USA had woken up to legally mandated minimum time from discovery to public disclosure of hacking events. Or is that just local State legislation in a few States and not a Federal thing? Considering the list of affected customer types, it sounds like it's critical that they admit or deny ASAP. (Being part of IBM, I'd guess they may have contacted some of the more "important" customers and made them sign NDAs before disclosing what has been stolen)

  4. Anonymous Coward
    Anonymous Coward

    Following own advice?

    I'm very much interested to learn about the investigation report and recommendations. That would be interesting to see if the company follows its own advice.

  5. Anonymous Coward
    Anonymous Coward

    Cloud

    I guess people are finding the cloud has its downsides.

    Extracting the data is one thing. I hope this has triggered rafts of code security checks, who knows what may have been slipped in.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like