Data Breaches

New York Times Responds to Source Code Leak

The New York Times has issued a statement after someone leaked source code allegedly belonging to the news giant. 

The New York Times has issued a statement after someone leaked source code allegedly belonging to the news giant. 

The New York Times has issued a statement after someone leaked a significant amount of source code allegedly belonging to the news giant. 

Reports emerged on Friday that someone had leaked 270 Gb of source code allegedly taken from The New York Times on the 4chan bulletin board. 

The leaker claimed to have obtained 5,000 repositories and a total of 3.6 million files, including source code for Wordle and other games. 

Stack Diary reported that the leaked data also includes a WordPress database storing information on roughly 1,500 users, including names, email addresses, and password hashes. The exposed data also reportedly includes authentication URLs and associated passwords, API tokens and secret keys. 

In a ‘readme’ file placed next to the leaked files, the hacker claimed to have gained access to the data after finding “a GitHub token that had access to the repositories”.

Contacted by SecurityWeek, The New York Times said it was aware of the incident and clarified that the data breach occurred in January 2024, “when a credential to a cloud-based third-party code platform was inadvertently made available”. 

“The issue was quickly identified and we took appropriate measures in response at the time,” a spokesperson for The Times said. “There is no indication of unauthorized access to Times-owned systems nor impact to our operations related to this event. Our security measures include continuous monitoring for anomalous activity.”

Advertisement. Scroll to continue reading.

Related: Intel Confirms UEFI Source Code Leak as Security Experts Raise Concerns

Related: Microsoft Says Russian Gov Hackers Stole Source Code After Spying on Executive Emails

Related: Mercedes Source Code Exposed by Leaked GitHub Token

Related Content

Data Breaches

A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Data Breaches

The company unintentionally disclosed users’ information to a third party impersonating a government agency.

Data Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

Data Breaches

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

Data Breaches

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.

Data Breaches

In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.

Data Breaches

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version