Executive Summary
In October 2025, Red Hat, an IBM subsidiary, confirmed a data breach after the Crimson Collective threat group accessed and exfiltrated information from a self-managed GitLab Community Edition instance used for the company’s consulting projects. Attackers reportedly stole over 28,000 code repositories containing project specifications, code samples, internal communications, and potentially sensitive artifacts such as credentials and configuration data shared with consulting customers. The incident did not impact any other Red Hat services or products, and the company promptly launched an investigation, isolated the affected system, and notified relevant authorities and affected customers.
This breach highlights growing risks associated with supply chain exposures, particularly when attackers target development and collaboration platforms where sensitive operational data may be stored. The incident is indicative of rising threats from organized cybercrime groups seeking intellectual property, credentials, and internal communications for downstream exploitation.
Why This Matters Now
The Red Hat consulting data breach underscores the dangers posed by inadequate segmentation and insufficient controls on internal development platforms, especially as threat actors increasingly target supply chain and third-party software ecosystems. Organizations must act now to secure collaborative environments and protect customer data shared during engagements.
Attack Path Analysis
The attacker initially compromised Red Hat's self-managed GitLab Community Edition instance, likely exploiting a vulnerability or misconfiguration to gain unauthorized access. They escalated privileges to extract repository data containing consulting project artifacts, tokens, and configurations. Using internal access, the adversary potentially moved laterally within the GitLab instance to enumerate and access additional resources. Command and control was established through maintained session or remote access, allowing sustained interaction with the environment. The attacker exfiltrated data including over 28,000 repositories to external infrastructure. The impact was limited to data exposure and potential reputational damage, without evidence of disruption or destructive actions.
Kill Chain Progression
Initial Compromise
Description
The threat actor gained unauthorized access to Red Hat's self-managed GitLab CE instance via exploitation of misconfiguration, unpatched software, or valid credentials.
Related CVEs
CVE-2025-10725
CVSS 9.8A critical vulnerability in Red Hat OpenShift AI allows unauthorized access to sensitive data.
Affected Products:
Red Hat OpenShift AI – < 4.9.4
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Valid Accounts
Exploit Public-Facing Application
Create Account
Windows Management Instrumentation
Remote Services
Impair Defenses
Data from Local System
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Implement Strong Access Controls
Control ID: 8.2.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Art. 9
CISA ZTMM 2.0 – Identity and Access Management
Control ID: Identity – 3.2 – Least Privilege
NIS2 Directive – Incident Handling and Response
Control ID: Art. 21(2)(d)
ISO/IEC 27001:2022 – Management of Privileged Access Rights
Control ID: A.9.2.3
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Critical exposure through GitLab repositories containing source code, credentials, and tokens. Data theft threatens intellectual property and software supply chain integrity across development environments.
Information Technology/IT
High risk from compromised consulting data including network configurations, access controls, and infrastructure specifications. Requires enhanced zero trust segmentation and multicloud visibility controls.
Professional Training
Consulting engagement data breach exposes project specifications and internal communications. Threatens client confidentiality and requires strengthened egress security and policy enforcement measures.
Management Consulting
Direct impact from Red Hat consulting data theft affecting customer project details and communications. Highlights need for encrypted traffic and enhanced threat detection capabilities.
Sources
- Red Hat confirms breach of GitLab instance, which stored company’s consulting datahttps://cyberscoop.com/red-hat-gitlab-attack-consulting-data/Verified
- Security update: Incident related to Red Hat Consulting GitLab instancehttps://www.redhat.com/en/blog/security-update-incident-related-red-hat-consulting-gitlab-instanceVerified
- FAQ: Data breach of Red Hat's self-managed GitLab instancehttps://support.gitlab.com/hc/en-us/articles/23301188655900-FAQ-Data-breach-of-Red-Hat-s-self-managed-GitLab-instanceVerified
- Cybersecurity Alert – Red Hat Security Incidenthttps://www.finra.org/rules-guidance/guidance/red-hat-security-incident-20251010Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Application of CNSF and Zero Trust controls—such as segmentation, egress policy enforcement, encrypted traffic, and anomaly detection—would have restricted initial access, contained attacker movement, and limited or detected data exfiltration from the compromised GitLab instance.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline policy and enforcement would reduce risk of unauthorized access.
Control: Zero Trust Segmentation
Mitigation: Microsegmentation restricts privilege boundaries and access exposure.
Control: East-West Traffic Security
Mitigation: Internal traffic monitoring and segmentation block unauthorized lateral exploration.
Control: Threat Detection & Anomaly Response
Mitigation: Anomaly detection triggers timely alerts on suspicious behaviors.
Control: Egress Security & Policy Enforcement
Mitigation: Outbound policy enforcement and FQDN filtering block unauthorized data transfers.
Full-path encryption obscures data in transit from eavesdropping or interception.
Impact at a Glance
Affected Business Functions
- Consulting Services
- Customer Data Management
Estimated downtime: 7 days
Estimated loss: $5,000,000
Unauthorized access to Red Hat's GitLab instance resulted in the exposure of consulting engagement data, including project specifications, code snippets, and internal communications. Sensitive customer information, such as network configurations and authentication tokens, was also compromised.
Recommended Actions
Key Takeaways & Next Steps
- • Enforce Zero Trust Segmentation and microsegmentation to restrict resource access based on identity and least privilege.
- • Deploy and monitor egress filtering and policy enforcement to prevent unauthorized outbound data transfers from critical services.
- • Implement comprehensive east-west traffic visibility and lateral movement controls for improved detection and response to unauthorized exploration within cloud workloads.
- • Enable real-time anomaly and threat detection to alert and investigate abnormal remote access, privilege use, or data exfiltration patterns.
- • Mandate encrypted traffic for all sensitive communications, including internal and hybrid connections, to safeguard data in transit and limit exposure.



