Supply chain β›“ Supply Chain

Red Hat Consulting GitLab Breach - Crimson Collective (570GB, 800+ Enterprises)

πŸ“… 2025-10-01 🏒 GitLab (self-hosted instance)
Primary Source β†—

Incident Details

On October 1, 2025, the cybercrime group Crimson Collective disclosed a breach of Red Hat’s consulting GitLab instance, claiming to have exfiltrated 570 GB of data from over 28,000 repositories. Red Hat confirmed unauthorized access to a GitLab instance used for internal Red Hat Consulting collaboration, immediately isolated the instance, and notified authorities. Stolen data reportedly includes Customer Engagement Reports (CERs) containing infrastructure configurations, network topologies, security assessments, vulnerability details, authentication tokens, API keys, database connection strings, CI/CD pipeline configurations, and VPN settings β€” for approximately 800 enterprise customer organizations. Affected organizations reportedly include Bank of America, Citi, JPMorgan Chase, HSBC, IBM, Cisco, Verizon, T-Mobile, AT&T, Boeing, NSA, U.S. Navy, Department of Energy, NIST, Mayo Clinic, and Kaiser Permanente. Nissan confirmed impact from the breach. FINRA issued a cybersecurity alert regarding the incident. The same Crimson Collective group was also responsible for the Brightspeed telecom breach (January 2026).

Technical Details

Initial Attack Vector
Crimson Collective gained unauthorized access to Red Hat's internal consulting GitLab instance used for customer engagement collaboration, exfiltrating approximately 570GB of compressed data from over 28,000 repositories
Vendor / Product
GitLab (self-hosted instance)
Software Package
GitLab
Supply Chain Attack
βœ… Confirmed third-party / vendor compromise

Timeline

  1. 2025-10-01 Breach occurred
  2. 2025-10-02 Publicly disclosed
  3. 2025-10-10 Customers notified