Checkmarx confirmed that material LAPSUS$ circulated matched GitHub repository exfiltration, with press summaries describing a ~96 GB pack and an access chain involving Trivy-related supply-chain credential exposure. Early company statements said end-customer databases were out of scope for GitHub but committed to notifications if PII appeared in code or configs.
Canonical record: Checkmarx / LAPSUS$ GitHub 2026 on BreachHistory.
Sources: BleepingComputer, Checkmarx