Red Hat confirmed a data breach in October 2025 after the Crimson Collective extortion group claimed to have breached a GitLab instance used for Red Hat Consulting. The incident involved the theft of nearly 570 GB of compressed data, including over 28,000 internal repositories.
The exfiltrated data included customer engagement reports with architecture diagrams and network maps, configurations, network topologies, authentication tokens, API keys, and CI/CD pipeline information. Approximately 800 organizations globally were impacted by this breach. While Red Hat initiated customer notifications, no official breach notification letters or state Attorney General filings have been detailed in available sources. The company stated that its main infrastructure, GitHub, and product environments were unaffected, with the breach limited to the Consulting GitLab instance.
Details are still emerging, and Red Hat continues to undertake forensic remediation. It is important to note that specific individual counts for affected U.S. residents have not been publicly confirmed by Red Hat.