Deloitte Data Breach: Alleged Leak of Source Code & GitHub Credentials

A threat actor using the alias “303” allegedly claimed to have breached the company’s systems and leaked sensitive internal data on a dark web forum. The alleged breach reportedly involves GitHub credentials and source code from internal project repositories belonging to Deloitte’s U.S. consulting division. According to reports emerging from cybersecurity monitoring services, the threat […] The post Deloitte Data Breach: Alleged Leak of Source Code & GitHub Credentials appeared first on Cyber Security News.

May 31, 2025 - 05:40
 0
Deloitte Data Breach: Alleged Leak of Source Code & GitHub Credentials

A threat actor using the alias “303” allegedly claimed to have breached the company’s systems and leaked sensitive internal data on a dark web forum.

The alleged breach reportedly involves GitHub credentials and source code from internal project repositories belonging to Deloitte’s U.S. consulting division.

According to reports emerging from cybersecurity monitoring services, the threat actor posted details of the alleged compromise on a well-known dark web forum, claiming to have accessed and exfiltrated critical development resources.

The leaked data allegedly includes GitHub credentials that could potentially grant unauthorized access to Deloitte’s internal development infrastructure, as well as source code from proprietary projects.

This latest incident adds to Deloitte’s ongoing cybersecurity challenges. The consulting firm has faced multiple breach allegations in recent months, including claims from the Brain Cipher ransomware group in December 2024, which Deloitte denied, stating that any compromised data originated from “a single client’s system which sits outside of the Deloitte network”. The company emphasized that “no Deloitte systems have been impacted” during that incident.

Alleged Deloitte Breach
Alleged Deloitte Breach

However, Deloitte’s history with credential leaks dates back several years. In 2017, security researchers discovered that Deloitte’s corporate VPN passwords, usernames, and operational details had been exposed in a public-facing GitHub repository.

The threat actor with the alias “303” has been linked to previous cybersecurity incidents, including an alleged breach of an Indian software company in December 2024 that affected major insurance providers. This pattern suggests the threat actor may be part of a broader campaign targeting large corporations and government entities.

The consulting giant has not provided a prompt response to inquiries seeking clarification or comment on the recent allegations that have come to light. As the investigations progress and further details emerge.

Live Credential Theft Attack Unmask & Instant Defense – Free Webinar

The post Deloitte Data Breach: Alleged Leak of Source Code & GitHub Credentials appeared first on Cyber Security News.