Crimson Collective are trying to extort Redhat
They've stolen about 500gb of data related to corporate customers. File list:
Crimson Collective are trying to extort Redhat
They've stolen about 500gb of data related to corporate customers. File list:
@GossiTheDog This has Big Oof written all over it.
It could get very messy very quickly.
@briankrebs @decio also posts by “antonio howell”, name of a British actor. Crimson Collective’s first victim is Claro - a telco which was one of the first victims of.. drumroll.. LAPSUS$
@decio @GossiTheDog I haven't seen anyone else mention this, but the posts from the Crimson Collective were signed "Miku", which is a nickname used by Thalha Jubair, the 19 y/o in the UK I wrote about last week who was charged in a ton of Scattered Spider ransom activity https://krebsonsecurity.com/2025/09/feds-tie-scattered-spider-duo-to-115m-in-ransoms/
@GossiTheDog 👍 thx
the 2nd proof link https://archive.ph/WqCdu
It’s not 570gb that was stolen btw, there’s group said they were still compressing at that point - they claim it was about half way. Also, it’s compressed so uncompressed.. it’s a lot more either way.
@GossiTheDog thank you VERY much for continuing to post this stuff. Definitely making my life better. If there's a way I can support you, let me know
Redhat statement:
https://www.redhat.com/en/blog/security-update-incident-related-red-hat-consulting-gitlab-instance
@GossiTheDog So it's just a GitLab instance that was breached? Ok...could've been much worse.
@GossiTheDog Always makes me laugh when they say, "We have now implemented additional hardening measures"
Why not just harden it properly in the first place 😂
LAPSUS$ have now listed the breach at Redhat on their portal.
They have posted CER - Consulting Engagement Requests, very sensitive info, for AMEX, Atos, HSBC, Walmart, NHS Scotland amongst others. I have authenticated the data is real.
Shout out to @briankrebs btw who noted, correctly, that the nickname being used for Crimson Collective posts was prior linked to a member of LAPSUS$ in the UK (who is supposed to be remanded in custody - the NCA may want to check he doesn't an Amazon Fire stick in his cell.
This is the portal post btw, basically the extortion note (not all of it).
The LAPSUS$ Red Hat dump also has a file tree up - 370,852 directories, 3,438,976 files
The Red Hat Consulting LAPSUS$ saga continues - in the past hour they've released a 2.2gb ZIP file.
I think a whole bunch of orgs probably need to start rotating certificates and such. #threatintel
@GossiTheDog that file tree is now zero length by the way. I tried downloading it multiple times and each time I end up with nothing.
@GossiTheDog alright, thanks. I was looking at the txt file becuase it said "tree" at the end.
@GossiTheDog did you see all the Ansible playbooks for Apache Guacamole?
GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.
All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.