Gitloker

Primary motivation
financial-gain
Sophistication
intermediate
Resource level
team
Actor type
criminal
Profile updated
2026-07-07 12:15:47

Targeted industries: technology-and-telecommunications professional-services

Context

Gitloker is a threat actor group targeting GitHub repositories, wiping their contents, and extorting victims for their data. They use stolen credentials to compromise accounts, claim to have created a backup, and instruct victims to contact them on Telegram. The attackers leave a ransom note in the form of a README file, urging victims to negotiate the return of their data. GitHub is working to combat these evolving attacks and the vulnerabilities they exploit.

Reports & references

  • itsecurityguru.org — Guest Blog Proactive Application Security Learning From The Recent Github Extortion Campaigns (report)
  • bleepingcomputer.com — New Gitloker Attacks Wipe Github Repos In Extortion Scheme (report)

External references