/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

The New York Times confirms its internal source code and data leaked on 4chan after being stolen using an exposed GitHub token in January 2024

Wordle apparently included Pierluigi Paganini / Security Affairs : New York Times source code compromised via exposed GitHub token Threads: Jacky Liang / @jjackyliang : exposed tokens strike again Mastodon: Jason Lefkowitz / @jalefkowit@vmst.io : The New York Times accidentally leaked one GitHub token, and it resulted in their complete 273GB source code library getting stolen  —  https://www.bleepingcomputer.com/ ... X: @vxunderground : Today on 4chan someone leaked the source code (?) to the New York Times. They leaked 270GB of data They wrote that the New York Times has 5,000+ source code repositories, with less than 30 being encrypted (?). It is 3,600,000 files in total Note: We haven't reviewed the data @0xorbs : Damn they're just ripping everybody, makes sense, the US economies internal infrastructure online is ages old. Major companies are using systems from the 70s still. Also 98% of banking/ATM systems in the world use only 1 coding language & its devs are all retired, old or dead. @igorbrigadir : Wonder if it's just code or article metadata too? Would be a super interesting dataset to dig through! Alex Ivanovs / @stackdiary : The New York Times leak does include sensitive information - I was able to identify a database of ~1k users (email, name and surname, hashed passwords) It's going to be a rough weekend for them. https://stackdiary.com/... #databreach #cybersecurity #infosec @toowoke2joke : @vxunderground Finally a way around their paywall. @vxunderground : This is the 2nd time this week proprietary information has been leaked onto 4chan. A few days Club Penguin files were stolen from Disney's internal network and leaked onto 4chan. Forums: Hacker News : New York Times source code leaked See also Mediagazer

BleepingComputer Lawrence Abrams

Context & Ripple Effects

The incident puts a concrete credential-management failure behind a large internal-code exposure at the New York Times. It follows earlier reporting that researchers could extract NYT staff email addresses by bypassing model privacy safeguards, highlighting distinct routes by which internal organizational information can become exposed.

The case also sits alongside [[a:850206|Microsoft’s disclosure that its source-code repositories and internal systems were accessed]] after a separate January intrusion. In both cases, code repositories become a high-value target because a single access path can reach far beyond one application or team.

First-order effects

  • The New York Times must assess and contain the exposed GitHub credential’s reach across roughly 5,000 repositories, while treating the posted code and data as potentially accessible to third parties.
  • Public availability of the stolen archive raises the immediate risk that implementation details, embedded secrets, or internal operational information can be identified and misused.

Second-order effects

  • The exposure makes token rotation, repository-access reviews, and secret-scanning more urgent for organizations using GitHub, particularly where a credential can span many repositories.
  • The incident reinforces the operational cost of repository compromises: remediation extends beyond removing leaked code to reviewing downstream systems and any credentials or data present in the archive.

Third-order effects

  • If similar incidents persist, source-code security will increasingly be governed as an identity-and-access-control problem, with short-lived credentials and narrower repository permissions becoming more important than perimeter controls alone.
  • The broader pattern may push companies to treat code archives as data-breach material, since leaked repositories can combine proprietary software with internal data and operational context.

The trend: Large codebase leaks are increasingly driven by overprivileged or exposed access credentials, shifting cyber defense toward continuous credential hygiene and tightly scoped repository access.

Discussion

  • @jjackyliang Jacky Liang on threads
    exposed tokens strike again
  • @vxunderground @vxunderground on x
    Today on 4chan someone leaked the source code (?) to the New York Times. They leaked 270GB of data They wrote that the New York Times has 5,000+ source code repositories, with less than 30 being encrypted (?). It is 3,600,000 files in total Note: We haven't reviewed the data
  • @0xorbs @0xorbs on x
    Damn they're just ripping everybody, makes sense, the US economies internal infrastructure online is ages old. Major companies are using systems from the 70s still. Also 98% of banking/ATM systems in the world use only 1 coding language & its devs are all retired, old or dead.
  • @igorbrigadir @igorbrigadir on x
    Wonder if it's just code or article metadata too? Would be a super interesting dataset to dig through!
  • @stackdiary Alex Ivanovs on x
    The New York Times leak does include sensitive information - I was able to identify a database of ~1k users (email, name and surname, hashed passwords) It's going to be a rough weekend for them. https://stackdiary.com/... #databreach #cybersecurity #infosec
  • @toowoke2joke @toowoke2joke on x
    @vxunderground Finally a way around their paywall.
  • @vxunderground @vxunderground on x
    This is the 2nd time this week proprietary information has been leaked onto 4chan. A few days Club Penguin files were stolen from Disney's internal network and leaked onto 4chan.