Data Breaches

SailPoint Discloses GitHub Repository Hack

The incident occurred on April 20 and did not affect customer data in the company’s production and staging environments.

Software security

Identity management and governance provider SailPoint has disclosed a cybersecurity incident involving its GitHub repositories.

In a filing with the Securities and Exchange Commission (SEC), the company revealed that the incident occurred on April 20 and was immediately contained.

“On April 20, 2026, we detected unauthorized access to a subset of our GitHub repositories. Our incident response team quickly terminated the unauthorized activity and resolved the issue,” the SEC filing reads.

[ Read: Ransomware Group Takes Credit for Trellix Hack ]

According to SailPoint, the repositories were compromised through a vulnerability in a third-party application. The underlying issue has been addressed, it said.

SailPoint said its investigation into the incident, conducted in collaboration with a third-party cybersecurity firm, has found no evidence that “customer data in our production or staging environments were accessed or that our services were interrupted.”

Advertisement. Scroll to continue reading.

The company told the SEC that it had directly notified customers if their information was stored in the accessed repositories.

“[We] informed our customers generally that no additional actions are required at this time,” SailPoint’s SEC filing reads.

SailPoint has not shared additional information on the attack, nor on the type of data that might have been compromised.

It did not name the threat actor responsible for the incident, and it’s unclear if the intrusion is related to the recent spree of software supply chain attacks claimed by the TeamPCP hacking group.

SecurityWeek has emailed SailPoint for additional information on the cyberattack and will update this article if the company responds.

Related: Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

Related: ‘PCPJack’ Worm Removes TeamPCP Infections, Steals Credentials

Related: Over 500 Organizations Hit in Years-Long Phishing Campaign

Related: Government, Scientific Entities Hit via Daemon Tools Supply Chain Attack

Related Content

Artificial Intelligence

The open-weight Antares models are designed to pinpoint known vulnerabilities in codebases faster and at a fraction of the cost of larger AI models.

Artificial Intelligence

Indirect prompts hidden in a repository can lead to Claude Code spawning a reverse shell on the developer’s machine.

Application Security

The security defects allow unauthenticated users to take control of the open source software supply chain.

Funding/M&A

Israel-based Entro specializes in non-human identity and credential security solutions, and it will enable SailPoint to enhance its products.

Data Breaches

Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated.

Malware & Threats

At least one threat actor has adopted the recently released malware source code in attacks against NPM developers.

Cybercrime

Grafana appears to have been targeted by Coinbase Cartel, a cybercrime group linked to ShinyHunters, Scattered Spider, and Lapsus$.

Malware & Threats

The hacking group is encouraging miscreants to use the code in supply chain attacks, promising monetary rewards.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version