It was GitHub in this report: https://www.theregister.com/2025/10/02/cybercrims_claim_raid_on_28000/
Now in this report it’s: GitLab
Which is it ? Or is it actually both?
Perhaps Microsoft (GitHub) and GitLab have something to say…
What started as cyber crew bragging has now been confirmed by Red Hat: someone gained access to its consulting GitLab system and walked away with data. The IBM-owned open source giant said in a blog post on Thursday that "an unauthorized third party had accessed and copied some data from a Red Hat Consulting-managed, dedicated …
Kind of useless of Redhat not to fess up just what was "taken".
I mean, "stole the Linux kernel source code" would be ludicrous, but "documents of the secret bonus deals when Redhat sold out to IBM" would possibly be enlightening and embarrassing.
Hmm, maybe I just provided the explanation to my first sentence.
>> confirmed by Red Hat: someone gained access to its consulting GitLab system
The crims got hold of customer data. But don't worry. Red Hat itself is OK. None of its staff are effected.
>> copied some data
It's always this magical 'some' when some cirm gets in. It should be made an SI unit: some - more than zero but probably a huge amount, and quite possibly everything.
Looking at the updates on the story being posted elsewhere, I would expect that Red Hat is likely to pay a very heavy price.
I can certainly imagine some very strained meetings and conversations between Red Hat and clients affected by this breach.
Is the Red Hat Consultancy brand toast?