The New York Times confirms its internal source code and data leaked on 4chan after being stolen using an exposed GitHub token in January 2024
Wordle apparently included Pierluigi Paganini / Security Affairs : New York Times source code compromised via exposed GitHub token Threads: Jacky Liang / @jjackyliang : exposed tokens strike again Mastodon: Jason Lefkowitz / @jalefkowit@vmst.io : The New York Times accidentally leaked one GitHub token, and it resulted in their complete 273GB source code library getting stolen — https://www.bleepingcomputer.com/ ... X: @vxunderground : Today on 4chan someone leaked the source code (?) to the New York Times. They leaked 270GB of data They wrote that the New York Times has 5,000+ source code repositories, with less than 30 being encrypted (?). It is 3,600,000 files in total Note: We haven't reviewed the data @0xorbs : Damn they're just ripping everybody, makes sense, the US economies internal infrastructure online is ages old. Major companies are using systems from the 70s still. Also 98% of banking/ATM systems in the world use only 1 coding language & its devs are all retired, old or dead. @igorbrigadir : Wonder if it's just code or article metadata too? Would be a super interesting dataset to dig through! Alex Ivanovs / @stackdiary : The New York Times leak does include sensitive information - I was able to identify a database of ~1k users (email, name and surname, hashed passwords) It's going to be a rough weekend for them. https://stackdiary.com/... #databreach #cybersecurity #infosec @toowoke2joke : @vxunderground Finally a way around their paywall. @vxunderground : This is the 2nd time this week proprietary information has been leaked onto 4chan. A few days Club Penguin files were stolen from Disney's internal network and leaked onto 4chan. Forums: Hacker News : New York Times source code leaked See also Mediagazer
Context & Ripple Effects
The incident puts a concrete credential-management failure behind a large internal-code exposure at the New York Times. It follows earlier reporting that researchers could extract NYT staff email addresses by bypassing model privacy safeguards, highlighting distinct routes by which internal organizational information can become exposed.
The case also sits alongside [[a:850206|Microsoft’s disclosure that its source-code repositories and internal systems were accessed]] after a separate January intrusion. In both cases, code repositories become a high-value target because a single access path can reach far beyond one application or team.
First-order effects
- The New York Times must assess and contain the exposed GitHub credential’s reach across roughly 5,000 repositories, while treating the posted code and data as potentially accessible to third parties.
- Public availability of the stolen archive raises the immediate risk that implementation details, embedded secrets, or internal operational information can be identified and misused.
Second-order effects
- The exposure makes token rotation, repository-access reviews, and secret-scanning more urgent for organizations using GitHub, particularly where a credential can span many repositories.
- The incident reinforces the operational cost of repository compromises: remediation extends beyond removing leaked code to reviewing downstream systems and any credentials or data present in the archive.
Third-order effects
- If similar incidents persist, source-code security will increasingly be governed as an identity-and-access-control problem, with short-lived credentials and narrower repository permissions becoming more important than perimeter controls alone.
- The broader pattern may push companies to treat code archives as data-breach material, since leaked repositories can combine proprietary software with internal data and operational context.
The trend: Large codebase leaks are increasingly driven by overprivileged or exposed access credentials, shifting cyber defense toward continuous credential hygiene and tightly scoped repository access.