2026 Vodafone — Lapsus$ dumps ~7.1GB internal source code after GitHub compromise (May)
Data compromised
Internal application source code and testing configs—not customer records per company statement
Technical writeup
Cybernews reported May 11, 2026 that Lapsus$ publicly dumped approximately 7.1 gigabytes of Vodafone internal source code—including OnePortal and Cyberhub repositories and testing environments—after alleging Vodafone refused ransom negotiations following a March 2026 incident. Researchers suspected compromise of an internal GitHub account and noted hardcoded PostgreSQL credentials in leaked code. Vodafone confirmed a March incident tied to compromised third-party development software and said no customer data was affected; BreachHistory indexes the source-code exposure separately from consumer PII.
Root cause
Alleged internal GitHub account compromise leading to repository exfiltration