Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 20 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Guest Blog: Ox Security on learning from the Recent GitHub Extortion Campaigns

by The Gurus
June 13, 2024
in Data Protection, Insight
Guest Blog: Ox Security on learning from the Recent GitHub Extortion Campaigns
Share on FacebookShare on Twitter

A new threat actor group known as Gitloker has launched an alarming campaign that wipes victims’ GitHub repositories and attempts to extort them. Victims are finding their repositories erased, replaced only by a solitary README file bearing the message: “I hope this message finds you well. This is an urgent notice to inform you that your data has been compromised, and we have secured a backup.” This note is followed by instructions to contact the attackers via Telegram to negotiate the return of their data.

These attackers appear to be using the stolen GitHub credentials of users who have not enabled two-factor authentication (2FA). Over recent months, GitHub-related security incidents have increased. GitHub, along with GitLab and other popular development platforms, have increasingly become prime targets for threat actors, given the sensitivity of the data created and stored there. These platforms are exploited under the strategy known as LOTS (Living Off Trusted Sites), where attackers leverage the credibility of well-known sites to carry out their malicious activities.

Monitor Access Controls for Safer Dev Environments

These attacks are far from isolated events; they’re part of a broader and troubling trend. Our data shows that between 93-97% of OX Security users have activated two-factor authentication (2FA), which helps keep accounts, data, and secrets private. But looking at 2FA use in isolation doesn’t tell the whole story; according to the 2024 Verizon Data Breach Investigations Report (DBIR), 61% of breaches involve stolen credentials—including breaches on GitHub/GitLab and Bitbucket. While large businesses are more likely to deploy and require 2FA/MFA, data from the Cyber Readiness Institute shows that only 54% of SMBs do not implement MFA and only 28% of SMBs require it. This missing control leaves businesses’ repositories vulnerable.

What’s more, we know that breaches, especially those involving credentials, are increasing. The Gitlocker campaign is just one glaring example. And it shows that, when it comes to your code and your secrets, one set of compromised credentials could expose thousands (if not millions) of data points. One set of compromised credentials could lead to millions of lines of lost code, productivity, and competitive advantage.

This trend highlights a critical vulnerability within the software development community: the reliance on centralized systems that are often not sufficiently secured. These platforms are integral to developers’ daily operations, making them prime targets for cyber adversaries. To counteract such threats, organizations must adopt a proactive approach to security, ensuring these essential systems are well-protected.

Understanding the New Attack Methods

The methods used in these scenarios are diverse and growing more complex, encompassing tactics from simple repository wipes to sophisticated extortion campaigns. Also, the frequency of these attacks is on the rise, which makes management and response efforts more challenging. Adversaries are consistently employing tried-and-true methods of social engineering to gain personal and professional information or manipulate individuals into granting access to sensitive systems.

The industry has recently witnessed a marked increase in “man-in-the-middle” attacks, in which attackers intercept and manipulate ongoing transactions and data transfers. Further, supply chain attacks are becoming more common, since a single compromised component can affect entire networks of dependencies. These incidents underscore the need for organizations to adopt a holistic and layered approach to security, emphasizing continuous monitoring, employee training, and the adoption of cutting-edge security technologies.

Backing Up Repository Data: Who’s Responsible?

When it comes to protecting GitHub data, it is crucial to understand who is responsible for creating backup. GitHub’s built-in features may not be adequate for restoring older versions, especially during major data loss incidents. It’s advisable for organizations to implement their own backup solutions that can capture daily snapshots of repositories and securely store them across multiple locations. This dual approach not only provides redundancy but also ensures that backups remain accessible even if the primary cloud service is compromised.

The decision between using GitHub’s backup capabilities and managing your own comes down to control, compliance, and risk management. Organizations, particularly those dealing with sensitive or regulatory-bound data, should consider third-party backups essential. The backup process can be automated and integrated into the development workflow, ensuring that even in the event of a breach, recovery will be swift and complete, minimizing downtime and loss while limiting cumbersome manual processes.

By understanding and implementing backup strategies, companies can protect themselves against the most catastrophic outcomes of cyber attacks, ensuring business continuity and safeguarding their valuable intellectual property.

Moving Forward

The reality is, GitHub-related attacks are evolving, but so are our methods to combat them. The Gitloker extortion campaign is a poignant reminder of the vulnerabilities inherent in relying on single-factor authentications and centralized systems. As attackers refine their strategies and broaden their targets, the potential damage from compromised credentials and data breaches could be devastating.

To effectively combat these threats, organizations must enforce stringent security protocols, including the widespread adoption of multi-factor authentication and regular audits of access controls. Additionally, the implementation of comprehensive backup solutions, continuous monitoring and access reviews are paramount to ensure that sensitive data remains protected across all fronts.

ShareTweet
Previous Post

Men’s Mental Health Week: Resource Guide

Next Post

Survey Finds Growing Number of Tech Tools Makes Cybersecurity Professionals Feel “Out of Control”

Recent News

AI Needs Human Expertise: How Securonix and Acora Are Transforming Security Operations

AI Needs Human Expertise: How Securonix and Acora Are Transforming Security Operations

June 19, 2026
75% of Organisations Have Gaps in Core Security Controls, Research Finds

More than 60% of Organisations Report Cyberattacks Spreading Beyond Email Into Teams, Slack and SMS, Finds New Research From KnowBe4

June 19, 2026
Frontline Workers Twice as Likely to Use Unapproved AI

VerifyLabs.AI Brings Deepfake Detection to Android After a recent IOS release

June 19, 2026
Proton removes the last barrier to leaving Google Workspace

Proton removes the last barrier to leaving Google Workspace

June 17, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol