Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

SailPoint Discloses GitHub Repository Hack

The incident occurred on April 20 and did not affect customer data in the company’s production and staging environments.

Software security

Identity management and governance provider SailPoint has disclosed a cybersecurity incident involving its GitHub repositories.

In a filing with the Securities and Exchange Commission (SEC), the company revealed that the incident occurred on April 20 and was immediately contained.

“On April 20, 2026, we detected unauthorized access to a subset of our GitHub repositories. Our incident response team quickly terminated the unauthorized activity and resolved the issue,” the SEC filing reads.

[ Read: Ransomware Group Takes Credit for Trellix Hack ]

According to SailPoint, the repositories were compromised through a vulnerability in a third-party application. The underlying issue has been addressed, it said.

SailPoint said its investigation into the incident, conducted in collaboration with a third-party cybersecurity firm, has found no evidence that “customer data in our production or staging environments were accessed or that our services were interrupted.”

Advertisement. Scroll to continue reading.

The company told the SEC that it had directly notified customers if their information was stored in the accessed repositories.

“[We] informed our customers generally that no additional actions are required at this time,” SailPoint’s SEC filing reads.

SailPoint has not shared additional information on the attack, nor on the type of data that might have been compromised.

It did not name the threat actor responsible for the incident, and it’s unclear if the intrusion is related to the recent spree of software supply chain attacks claimed by the TeamPCP hacking group.

SecurityWeek has emailed SailPoint for additional information on the cyberattack and will update this article if the company responds.

Related: Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

Related: ‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials

Related: Over 500 Organizations Hit in Years-Long Phishing Campaign

Related: Government, Scientific Entities Hit via Daemon Tools Supply Chain Attack

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Sumo Logic has appointed Chris Malone as CEO and Conor Burns as CFO.

Nozomi Networks has appointed co-founder Andrea Carcano as CEO.

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.