Hackers claim massive breach of Red Hat’s consulting data
- Hackers shared proof, and Red Hat has launched an investigation.
- An extortion group says it stole 570 GB of Red Hat consulting data affecting 800 organisations.
Hackers claim to have broken into Red Hat’s GitLab system and stolen a massive amount of data tied to its consulting work. The breachif confirmed, could affect hundreds of major organisations across government, finance, telecom, and other industries, potentially exposing them to follow-up attacks.
An extortion group calling itself Crimson Collective announced on Telegram that it had accessed more than 28,000 Red Hat repositories, taking roughly 570 GB of data. Among the files were Customer Engagement Reports (CERs), which typically contain details about how client networks are designed and secured. These reports are meant to guide consulting work, but in the wrong hands, hackers can use Red Hat’s data as a blueprint for targeted attacks.
The hackers shared a full file tree, a list of the stolen reports, and screenshots to support their claims. On X, multiple users reposted parts of the file tree, revealing the names of major organisations affected. These reportedly include the NSA, the Department of Energy, the National Institute of Standards and Technology (NIST), IBM, Citi, Verizon, Siemens, Bosch, J.P. Morgan Chase, HSBC, Telefonica, and other large companies and agencies.
Screenshots posted by the hackers showed folders packed with technical data. These included configuration files, server inventories, VPN details, automation scripts, code deployment runners, container registry information, secret-management links, backups, and exported GitHub and GitLab configurations. For attackers, this kind of material can reveal how systems are structured, making it easier to spot weaknesses.
“Source code and consulting engagement reports (CERs), if leaked, can help attackers analyse internal company infrastructure and software running on that infrastructure. This makes it significantly easier and faster to identify vulnerable attack vectors for potential attackers,” said Aras Nazarovas, an information security researcher at Cybernews.
The hackers also claimed they had already used some of the stolen data to access client systems. Cybernews has not been able to independently verify those claims or the full scope of the breach.
Red Hat responds after hackers breach consulting GitLab
Red Hat confirmed the breach after hackers posted proof of the attack online, saying the incident involves a GitLab environment used by its consulting team. It stressed that this system is separate from its main software infrastructure and GitHub repositories.
“The security incident we are investigating is related to a GitLab instance used solely for Red Hat Consulting on consulting engagements, not GitHub,” said Stephanie Wonderlick, Red Hat’s VP of Brand Experience + Communication.
The company said it quickly removed the attacker’s access, isolated the affected system, and launched a full investigation with authorities. Early findings showed that an unauthorised third party accessed and copied some data. Red Hat emphasised that the breached GitLab system usually doesn’t contain sensitive personal information, and so far, it has found no evidence of such data being included.
Red Hat also published a security update to clarify the situation. It stated that the incident has no known impact on its software supply chain, product downloads, or other customer-facing services. The company added that the breach is unrelated to a separate critical vulnerability recently discovered in Red Hat OpenShift AI.
Ripple effects beyond Red Hat
While Red Hat works to contain the breach, the potential impact reaches much further. The stolen consulting reports and configuration files contain highly detailed information about clients’ internal networks. For attackers, this kind of information can remove one of the hardest parts of any cyberattack: reconnaissance. Instead of spending time mapping out a target’s systems, they already have the map in hand.
That could allow attackers to move quickly to steal data, disrupt services, or gain long-term access without detection. It’s not just the affected companies that could feel the impact. Many of them run critical services that people rely on daily, from financial transactions to telecommunications.
For organisations that have worked with Red Hat’s consulting teams, security experts recommend immediate steps. This includes reviewing and tightening access controls, changing passwords and tokens, and closely monitoring for unusual activity that could signal an attempted breach. Even if the hackers’ claims are exaggerated, treating this incident seriously can help limit potential fallout.
A supply chain security wake-up call
This breach is another reminder that cybersecurity isn’t limited to protecting your own systems. Weaknesses in partners, vendors, or consulting firms can open the door to serious risks. Even trusted, well-established organisations are not immune to breaches, and those breaches can have ripple effects across industries.
As Nazarovas noted, “the recent breach at Red Hat has shown us how even the most trusted organisations, that have been setting industry best practices for years, aren’t immune to serious data breaches.”
The incident underlines why supply chain security remains one of the toughest problems in cybersecurity. A single compromise in a trusted partner’s system can expose countless others, creating knock-on effects that are difficult to contain.
Want to experience the full spectrum of enterprise technology innovation? Join TechEx in Amsterdam, California, and London. Covering AI, Big Data, Cyber Security, IoT, Digital Transformation, Intelligent Automation, Edge Computing, and Data Centres, TechEx brings together global leaders to share real-world use cases and in-depth insights. Click here for more information.
TechHQ is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
TNG – Latest News & Reviews

