2026 GitHub — South Korea police confirm 500+ PAT leak; 54 countries (Jul)
Data compromised
Per Chosun/Open Source For You/Korea Herald summaries: 500+ GitHub account authentication credentials (personal access tokens); 370 accounts in 54 countries identified, 200+ additional accounts with nationality not yet confirmed; 30+ South Korean accounts; tokens could enable repository access, source-code theft, and downstream supply-chain compromise
Technical writeup
Law-enforcement-confirmed credential leak — reported July 14, 2026. South Korea's National Police Agency National Office of Investigation confirmed a large-scale leak of GitHub personal access tokens after finding a suspect in an unrelated cybercrime case possessed another person's GitHub token. Police said more than 500 account credential units were involved, with nationalities verified for 370 accounts across 54 countries and over 200 accounts still being traced; more than 30 affected accounts were tied to South Korea. Authorities notified Microsoft (GitHub's operator), Interpol, and affected organizations, and issued a security advisory urging developers and companies to rotate tokens and audit repository access. Police described this as the first time South Korean authorities independently identified a GitHub token leak and formally shared findings with Interpol. BreachHistory indexes the police-attested 500+ credential count as recordsAffected 500.
Root cause
Large-scale leak of GitHub personal access tokens discovered during unrelated cybercrime investigation; South Korean National Police Agency confirmed and notified Microsoft, Interpol, and affected account owners