Supply chain
β Supply Chain
Red Hat Consulting GitLab Breach - Crimson Collective (570GB, 800+ Enterprises)
Primary Source βIncident Details
On October 1, 2025, the cybercrime group Crimson Collective disclosed a breach of Red Hat’s consulting GitLab instance, claiming to have exfiltrated 570 GB of data from over 28,000 repositories. Red Hat confirmed unauthorized access to a GitLab instance used for internal Red Hat Consulting collaboration, immediately isolated the instance, and notified authorities. Stolen data reportedly includes Customer Engagement Reports (CERs) containing infrastructure configurations, network topologies, security assessments, vulnerability details, authentication tokens, API keys, database connection strings, CI/CD pipeline configurations, and VPN settings β for approximately 800 enterprise customer organizations. Affected organizations reportedly include Bank of America, Citi, JPMorgan Chase, HSBC, IBM, Cisco, Verizon, T-Mobile, AT&T, Boeing, NSA, U.S. Navy, Department of Energy, NIST, Mayo Clinic, and Kaiser Permanente. Nissan confirmed impact from the breach. FINRA issued a cybersecurity alert regarding the incident. The same Crimson Collective group was also responsible for the Brightspeed telecom breach (January 2026).
Technical Details
- Initial Attack Vector
- Crimson Collective gained unauthorized access to Red Hat's internal consulting GitLab instance used for customer engagement collaboration, exfiltrating approximately 570GB of compressed data from over 28,000 repositories
- Vendor / Product
- GitLab (self-hosted instance)
- Software Package
GitLab- Supply Chain Attack
- β Confirmed third-party / vendor compromise
Timeline
- 2025-10-01 Breach occurred
- 2025-10-02 Publicly disclosed
- 2025-10-10 Customers notified