The hacker group Crimson Collective claimed to have gained access to one of Red Hat's internal GitLab servers and downloaded 570GB of compressed data containing information from 28,000 repositories. Among other things, the captured data included around 800 Customer Engagement Reports (CERs) containing confidential information about the platforms and network infrastructures of Red Hat clients who received consulting services.
The screenshots and examples presented by the attackers mention the acquisition of data related to about 800 Red Hat clients, including Vodafone, T-Mobile, Siemens, Boeing, Bosch, 3M, Cisco, DHL, Adobe, American Express, Verizon, JPMC, HSBC, Ericsson, Merrick Bank, Telefonica, Bank of America, Delta Air Lines, Walmart, Kaiser, IBM, SWIFT, IKEA, and AT&T, as well as the U.S. Navy's Surface Warfare Development Center, the U.S. Federal Aviation Administration, the U.S. Federal Emergency Management Agency, the U.S. Air Force, the U.S. National Security Agency, the U.S. Patent and Trademark Office, the U.S. Senate, and the House of Representatives.
It is claimed that the captured repositories contain information about client infrastructure, configuration, authentication tokens, and profiles VPN, inventory data, Ansible playbooks, OpenShift platform settings, CI/CD runners, backups, and other data that could be used to orchestrate an attack on clients' internal networks. The attackers attempted to contact Red Hat for extortion but received only a template response suggesting they report the vulnerability to the security team.
Red Hat confirmed the security incident but did not provide details or comment on the content of the leak. It was only mentioned that the breached GitLab server was used in the consulting division and the company took necessary steps to investigate and recover. Red Hat representatives claim they have no reason to believe that the breach affected any other services or products of the company, apart from one server GitLab.
Supplement: Red Hat has published an initial incident report. The report does not provide details, only stating that the company has initiated an investigation, during which it was found that an unknown individual gained access to the GitLab server used for managing projects by the Red Hat Consulting team and downloaded some data from it.
Regarding the data that the attacker extracted, it has been claimed that it contained project specifications, code samples, and internal informational materials about consulting services. At this stage of the incident analysis, no leaks of important personal data have been identified.
It is not specified how the attacker gained access to the GitLab server, but it was noted that the attack did not exploit the vulnerability (CVE-2025-10725) discovered yesterday in OpenShift AI Service, which allows an authenticated non-privileged user, such as a researcher using a Jupyter notebook, to gain cluster administrator rights with full access to all services, data, and applications running in the cluster, as well as root access to the cluster nodes.
Source: opennet.ru
