People search GitHub data breach timeline because the brand sits on billions of accounts, credentials, and cloud workloads. BreachHistory indexes 3 GitHub-linked incidents. This page maps every attested event through 2026 with internal links to canonical records.
Why GitHub breach history matters
GitHub operates in Software (United States). Across indexed rows, recurring themes include mixed intrusion and disclosure events. Understanding the chronological pattern helps security teams, customers, and regulators separate confirmed disclosures from forum marketing.
Full timeline through 2026
2026 — unauthorized access to internal repositories via poisoned VS Code extension (May 20)
Unverified claim — treat actor counts cautiously. On May 20, 2026, GitHub posted the first message in a public incident thread stating it is sharing additional details on unauthorized access to GitHub’s internal repositories. The company said it detected and contained a compromise of an employee device involving a poisoned Visual Studio Code extension, removed the malicious extension version, isolated the endpoint, and began incident response immediately. GitHub did not publish a customer record count or confirm end-user repository content exposure in the opening Exposed categories include GitHub internal repositories (forensic scope pending); no attested github.com user/customer PII volume in initial post. No attested victim count is published for this row yet. See the github-internal-repositories-vsce 2026 r and canonical BreachHistory entry.
2024 — — Secrets
Cataloged incident. Breach. Secrets. Exposed categories include Names, emails, addresses, and other PII. No attested victim count is published for this row yet. See the github2024 and canonical BreachHistory entry.
2013 — — GitHub: A hacker or hackers compromised some of the user…
Cataloged incident. A hacker or hackers compromised some of the user accounts of GitHub. The hackers used a brute force attack to expose passwords. GitHub reset the passwords of users who were affected. Exposed categories include Personal information. No attested victim count is published for this row yet. See the github2013 and canonical BreachHistory entry.
Patterns and analysis
- Mixed intrusion and disclosure events — appears across multiple GitHub catalog entries; prioritize controls that address this class of failure.
- Record-count hygiene — BreachHistory indexes actor-cited figures separately from company-confirmed totals; read each row's technicalWriteup before treating counts as fact.
- 2026 monitoring — New disclosures roll into this timeline as they are verified or labeled unverified per catalog policy.
What to do if you may be affected
- Step 1: Enable phishing-resistant MFA on every account tied to this brand.
- Step 2: Use unique passwords and a password manager—breach rows often involve credential reuse.
- Step 3: Monitor official company breach notices and regulator filings, not dark-web downloads.
- Step 4: Bookmark the GitHub company page for new 2026+ disclosures.
Canonical BreachHistory hub
Explore every indexed row: breachhistory.com/github · Latest: github-internal-repositories-vsce2026.
Sources: BreachHistory catalog (3 rows for GitHub), company and regulator disclosures cited in individual breach records.