Ransomware victim disclosure
← All victimsGITHUB INTERNAL
Claimed by Lapsus$ · listed 5 hours ago
Status timeline
- ListedJun 13, 2026
- Data leakeddate unknown
At a glance
- Group
- Lapsus$
- Status
- Data leaked
- Country
- United States
- Sector
- Technology
- Listed on leak site
- Jun 13, 2026
About the victim
AI dossier — public-source company profileGitHub is a web-based platform for version control and collaborative software development, owned by Microsoft. It provides tools for code hosting, CI/CD workflows, security scanning, and AI-assisted development through services like GitHub Copilot, used by millions of developers and enterprises worldwide.
- Industry
- Software Development Platform / Developer Tools
Attack summary
Severity: critical — Confirmed exfiltration of internal platform data from a major infrastructure provider serving millions of developers and enterprises. Exposure of GitHub's core systems could impact software supply chain security at scale.Lapsus$ claimed to have exfiltrated data from GitHub's internal systems, stating 'Everything for the main platform is there.' The group indicated no ransom demand and threatened to publish the data for free if no buyer was found.
Data the group says was taken
AI dossier — extracted from the leak post- Internal platform source code/data
- GitHub internal systems data
What the group claims
Everything for the main platform is there. No ransom, we do not care about extorting Github. If no buyer is found, we leak for free.
Sources
- Victim sitegithub.com
Source
Indexed 5 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

