ShinyHunters claims to have stolen 500GB+ of data from Microsoft's private GitHub repositories; Microsoft says it is investigating the claims
A hacker claims to have stolen over 500GB of data from Microsoft's private GitHub repositories, BleepingComputer has learned.
Context & Ripple Effects
This claim lands mid-campaign: researchers had already documented ShinyHunters hawking what it claimed was roughly 200M stolen records from at least 13 companies on the dark web since May 1, so the Microsoft allegation reads as an escalation from consumer-data bazaars to a platform vendor's own private repositories.
The target choice also fits a longer arc around Microsoft's GitHub hygiene — three years later, researchers would find a repo run by Microsoft's AI research unit exposing 38TB of sensitive data, including secret keys and Teams chat logs — making this alleged theft an early data point in a recurring pattern rather than a one-off.
First-order effects
- Microsoft is forced into an active investigation of its private GitHub estate while the claim is unverified, with its source code and internal tooling exposure — not customer data — as the thing it must rule out publicly.
- ShinyHunters gains negotiating material either way: proof of a breach against the highest-profile name yet in its string of targets, or publicity from Microsoft merely having to respond.
Second-order effects
- Enterprises running their own private repos on GitHub face renewed pressure to audit access controls and secrets handling, since the alleged victim is the platform's owner itself.
- The other companies in ShinyHunters' claimed haul of 13-plus victims now share a threat actor whose profile rises with each named target, raising the likelihood they become follow-on leak or extortion subjects.
Third-order effects
- If the pattern holds — unverified claims forcing investigations, then later confirmed exposures like the 38TB AI-unit repo — private developer repositories get treated as breach surface on par with production infrastructure, pushing secrets scanning and repo auditing into standard security practice.
- ShinyHunters' longevity, resurfacing years later in an attack on the European Commission, suggests claim-first extortion against large institutions becomes a durable operating model rather than a 2020 moment.
The trend: Data-theft crews like ShinyHunters are shifting from selling bulk consumer records to targeting the private development infrastructure of the platforms themselves, with unverified claims doing reputational work before any verification.