ShinyHunters claims to have stolen 500GB+ of data from Microsoft's private GitHub repositories; Microsoft says it is investigating the claims
A hacker claims to have stolen over 500GB of data from Microsoft's private GitHub repositories, BleepingComputer has learned.
Context & Ripple Effects
The claim against Microsoft lands in the middle of a broader ShinyHunters campaign: within two weeks, researchers describe the group hawking what it claims is ~200M stolen records from at least 13 companies since May 1, with the Microsoft GitHub theft as one entry in that inventory a multi-company haul being sold on the dark web. Microsoft's only confirmed posture at this stage is an investigation — the 500GB figure and the private-repo target remain the attacker's assertions.
The arc that follows makes this claim an early data point rather than a one-off: three years later, researchers found a Microsoft AI research unit GitHub repo exposing 38TB of sensitive data, including secret keys and staff chat logs, and by 2026 ShinyHunters claimed a 350GB+ theft from the European Commission an attack the EC said spared its internal systems. The through-line is that repository-scale data exposure at large organizations keeps recurring, whether by intrusion or misconfiguration.
First-order effects
- Microsoft must scope what its private GitHub repositories actually held — source code, credentials, and internal documentation are the assets at stake — while GitHub, its own subsidiary, becomes the contested attack surface rather than just a product it sells.
- ShinyHunters gains negotiating material either way: a verified theft feeds its dark-web sales, and even an unverified claim forces Microsoft to spend investigation effort answering it publicly.
Second-order effects
- Enterprise customers weighing Microsoft cloud and developer-tool contracts get a fresh data point on the company's internal security hygiene, giving rivals an opening to pitch their own repository-access controls during renewals.
- Other organizations named in ShinyHunters' 13-company campaign face the same playbook — a public claim, a forced investigation, and pressure to confirm or deny before the data is monetized.
Third-order effects
- Private code repositories are consolidating as a first-class breach target, and the pattern in this coverage — intrusion claims in 2020, a 38TB misconfiguration in 2023, a claimed EC theft in 2026 — suggests organizations will treat repo auditing, secret scanning, and access review as standing security functions rather than periodic cleanups.
- Claim-then-investigate extortion normalizes attackers setting the public narrative before victims can verify scope, shifting disclosure dynamics toward attacker-controlled announcements.
The trend: Private code repositories are becoming a recurring, high-value target for extortion groups, with attacker claims increasingly setting the disclosure agenda for large organizations.