Report: Microsoft’s GitHub Account Gets Hacked

GitHub bug bounty program

The Shiny Hunters hacking group said it stole 500 GB of data from the tech giant’s repositories on the developer platform, which it owns.

Hackers have broken into Microsoft’s GitHub account and stolen 500 GB of data from the tech giant’s own private repositories on the developer platform, according to published reports.

A group that calls itself Shiny Hunters claims it stole and then leaked the data, which did not appear to include any critical or sensitive information. The data was then posted on hacker forum, according to a multiple reports.

This modus operandi behind the Shiny Hunters cybergang is slightly different than how the group has operated in the past. Researchers last week observed Shiny Hunters stealing log-in data for 91 millions users of Indonesia’s largest e-commerce platform, Tokopedia, and then selling it on the dark web for $5,000.
In its latest hack, the group provided a screenshot to reporters at news site Hack Read that showed a list of private files from Microsoft’s open-source developer repository to prove their infiltration of the company’s private account. The list includes files such as Rust for the Windows Runtime and Wssd Cloud Agent.

“This access led them to download approximately 500 GB of data which they planned to sell at first rebut then later just decided to let it go for free in Robin-Hood style,” according to the report.

One way the hackers did that was to post 1 GB of the data on a hacker forum and allow users to access it through the site’s built-in credits, according to reports. However, the data used Chinese text and other references that suggested it might not actually be from Microsoft.

Still, while the leaked data seems to mainly be comprised of code samples, test projects, eBooks, and the like, the breach—which probably happened on March 28–does appear to be legitimate. Under the Breach, a data-breach monitoring firm, Tweeted the Hack Read post and told the publication that it was highly likely that Microsoft had been hacked.

Shiny Hunters told Hack Read that they no longer have access to Microsoft’s GitHub account, so the company has time to investigate and inform its users of any consequences of the breach, according to the report. Microsoft has yet to respond to Hack Read’s request for breach confirmation.

GitHub is a popular software development platform that provides hosting software to about 40 million developers, who use it for version control of their software. Microsoft acquired GitHub for $7.5 billion in October 2018.

The platform is no stranger to cyber-attacks, and has experienced some notable data breaches before that affected developer repositories. In 2016, threat actors used credentials that had been compromised in other breaches to try to access developer repositories, forcing a password reset of those accounts, researchers said.

The next year, owners of Github repositories were the target of a phishing campaign spreading the Dimnie malware, which can steal data through keyloggers and modules that take screenshots, according to researchers.

Inbox security is your best defense against today’s fastest growing security threat – phishing and Business Email Compromise attacks. On May 13 at 2 p.m. ET, join Valimail security experts and Threatpost for a FREE webinar, 5 Proven Strategies to Prevent Email Compromise. Get exclusive insights and advanced takeaways on how to lockdown your inbox to fend off the latest phishing and BEC assaults. Please register here for this sponsored webinar.

Suggested articles

have i been pwned open source

Have I Been Pwned Set to Go Open-Source

Fully opening the door to allow people to contribute to – and notably, tinker with – the code for the data-breach information service will be an entirely next-level effort, according to founder Troy Hunt.

Augmenting AWS Security Controls

Augmenting AWS Security Controls

Appropriate use of native security controls in AWS and other CSPs is fundamental to managing cloud risk and avoiding costly breaches.

Discussion

  • James Hinks on

    If MS cannot protect their own account how can they protect our accounts with our intellectual property?
  • Gary on

    It was most likely a case of password re-use than anything else.
  • Henrich on

    MS has nothing with it, they just own Github Inc, and Github Inc is still separate company.
  • Jj on

    Unreliable Microsoft as usual

Leave A Comment

 

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Subscribe to our newsletter, Threatpost Today!

Get the latest breaking news delivered daily to your inbox.