Gitloker
- Primary motivation
- financial-gain
- Sophistication
- intermediate
- Resource level
- team
- Actor type
- criminal
- Profile updated
- 2026-07-07 12:15:47
Targeted industries: technology-and-telecommunications professional-services
Context
Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to compromise accounts, claim to have created a backup, and instruct victims to contact them on Telegram. The attackers leave a ransom note in the form of a README file, urging victims to negotiate the return of their data. GitHub is working to combat these evolving attacks and the vulnerabilities they exploit.
Reports & references
- itsecurityguru.org — Guest Blog Proactive Application Security Learning From The Recent Github Extortion Campaigns (report)
- bleepingcomputer.com — New Gitloker Attacks Wipe Github Repos In Extortion Scheme (report)