HomeNewsBreachesAbout
Account
red-hat-gitlab-2025

RedHat Gitlab Breach

Dec 30, 2025

227,438 rows

Added on Dec 31, 2025

Search the Leak

Email

What happened in the RedHat Gitlab Breach?

DataBreach.com Team · December 30th 2025, 7:00 pm EST

In early October 2025, Red Hat confirmed a significant security breach affecting a self-hosted GitLab instance used exclusively by its consulting division. The threat actor, known as the Crimson Collective (later aligning with the Scattered LAPSUS$ Hunters cartel), successfully exfiltrated 570GB of data.

While Red Hat’s core product code (RHEL, OpenShift) was not compromised, the breach exposed thousands of "Customer Engagement Reports" (CERs) containing sensitive architectural blueprints, network diagrams, and hardcoded credentials belonging to Red Hat's enterprise clients.

For media inquiries, contact us at contact@databreach.com