/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Code42 analysis: there were ~65M attempts by staff to steal source code from their companies in Q2, up from about 20M in each of the previous three quarters

Hannah Murphy / Financial Times :

Financial Times Hannah Murphy

Context & Ripple Effects

Code42's finding lands mid-arc in a run of source-code incidents: US investigators were already probing the Codecov breach earlier that spring, where an auditing tool's compromise exposed some of its 29K customers. The new twist is direction of travel — not outsiders breaking into repositories, but roughly three times more attempts by employees themselves to exfiltrate the code they work beside.

The prior coverage had established that departing staff are the classic insider vector — one report found 60% of insider threats involve employees leaving their jobs, often forwarding content to personal email. Code42's Q2 spike suggests that behavior scaled up sharply during the period, giving vendors and CISOs alike fresh ammunition to argue source code needs the same loss-prevention discipline as customer data.

First-order effects

  • Security teams at software companies must treat their own engineers' endpoints as the primary exfiltration surface, shifting monitoring budget toward egress controls and departure workflows rather than only the network perimeter.
  • Code42, which sells exactly this insider-risk visibility, now has a headline dataset that pressures peers' customers to justify existing DLP spend or expand it.

Second-order effects

  • Competing data-loss-prevention and endpoint-security vendors are forced to publish their own telemetry or concede the 'insider source-code theft' narrative to Code42, turning threat statistics into a marketing battleground.
  • Boards and insurers begin pricing source-code exfiltration as a distinct risk category alongside ransomware, since the Codecov episode showed a supply-chain tool can expose thousands of customers at once.

Third-order effects

  • If attempt volumes stay elevated, source code gets governed like regulated data — access tiering, offboarding automation, and audit trails become standard — while later episodes like Dropbox's phished GitHub repos and Microsoft's Midnight Blizzard source-repo access blur the line between insider risk and nation-state tradecraft, a convergence later framed by Verizon's analysis of internal-actor incidents.
  • The pattern points toward insider-threat analytics consolidating into the same platforms that already watch endpoints, making employee-monitoring capability a baseline expectation of enterprise security suites rather than a niche product.

The trend: Corporate source code is becoming a contested asset class in cybersecurity, with insider exfiltration attempts, supplier-chain compromises, and state-sponsored repo access converging on the same repositories.