← Capgemini

2022 Internal breach — 20GB data

2022 Unknown records affected Share on X

Data compromised

Source code, credentials, API keys, internal data

Technical writeup

Hacker claimed theft of 20GB of sensitive data including source code, private keys, employee credentials (usernames, password hashes), API keys, internal project details, cloud configs. Investigation revealed internal threat: consultant arrested May 2022 for encrypting sensitive data and demanding Bitcoin ransom.

Root cause

Internal threat; insider attack.

References