The Crimson Collective is a cybercrime group that leaked 570GB of data from Red Hat GitHub repositories in 2025.
Analyst brief
The Crimson Collective is a cybercrime group that claimed to have compromised Red Hat's private GitHub repositories in September 2025. The group targets organizations in the Technology sector, specifically aiming at source code repositories and sensitive customer data. Their primary TTP involved exfiltrating 570GB of data, including Customer Engagement Reports with network configurations and tokens, and leaking proof on a Telegram channel. Defenders should monitor for anomalous GitHub access activity, alert customers about potentially exposed network data (tokens, infrastructure details), and strengthen repository security audits.
Crimson Collective
unknown
The Crimson Collective is a cybercrime group that claimed to have compromised Red Hat's private GitHub repositories in September 2025. The group asserted it had stolen 570GB of data from Red Hat's private GitHub repositories, including 28,000 projects and approximately 800 Customer Engagement Reports (CERs) containing sensitive network data. CERs often contain sensitive information including infrastructure details, configurations, and tokens that attackers could exploit to target customers' networks. The group shared proof of the breach on a Telegram channel, including a full file tree, CER list, and screenshots. The U.S.-based multinational software company confirmed the data breach but did not verify the Crimson Collective's claims. The group also claimed to have gained access to some of Red Hat's client infrastructure and stated they had warned the company but were ignored.
What type of data did the Crimson Collective claim to have stolen from Red Hat?+
The Crimson Collective claimed to have exfiltrated 570GB of data from Red Hat's GitHub repositories, including approximately 800 Customer Engagement Reports (CERs) and network configurations.
How did the Crimson Collective prove the Red Hat breach?+
The group shared proof of the breach on a Telegram channel, including a full file tree and samples of the CERs.