Code42 analysis: there were ~65M attempts by staff to steal source code from their companies in Q2, up from about 20M in each of the previous three quarters
Hannah Murphy / Financial Times :
Context & Ripple Effects
Code42's finding lands mid-arc in a run of source-code incidents: US investigators were already probing the Codecov breach earlier that spring, where an auditing tool's compromise exposed some of its 29K customers. The new twist is direction of travel — not outsiders breaking into repositories, but roughly three times more attempts by employees themselves to exfiltrate the code they work beside.
The prior coverage had established that departing staff are the classic insider vector — one report found 60% of insider threats involve employees leaving their jobs, often forwarding content to personal email. Code42's Q2 spike suggests that behavior scaled up sharply during the period, giving vendors and CISOs alike fresh ammunition to argue source code needs the same loss-prevention discipline as customer data.
First-order effects
- Security teams at software companies must treat their own engineers' endpoints as the primary exfiltration surface, shifting monitoring budget toward egress controls and departure workflows rather than only the network perimeter.
- Code42, which sells exactly this insider-risk visibility, now has a headline dataset that pressures peers' customers to justify existing DLP spend or expand it.
Second-order effects
- Competing data-loss-prevention and endpoint-security vendors are forced to publish their own telemetry or concede the 'insider source-code theft' narrative to Code42, turning threat statistics into a marketing battleground.
- Boards and insurers begin pricing source-code exfiltration as a distinct risk category alongside ransomware, since the Codecov episode showed a supply-chain tool can expose thousands of customers at once.
Third-order effects
- If attempt volumes stay elevated, source code gets governed like regulated data — access tiering, offboarding automation, and audit trails become standard — while later episodes like Dropbox's phished GitHub repos and Microsoft's Midnight Blizzard source-repo access blur the line between insider risk and nation-state tradecraft, a convergence later framed by Verizon's analysis of internal-actor incidents.
- The pattern points toward insider-threat analytics consolidating into the same platforms that already watch endpoints, making employee-monitoring capability a baseline expectation of enterprise security suites rather than a niche product.
The trend: Corporate source code is becoming a contested asset class in cybersecurity, with insider exfiltration attempts, supplier-chain compromises, and state-sponsored repo access converging on the same repositories.