Police Warn of Mass GitHub Access Token Leak, Urge Security Steps

Numerous Personal Access Tokens Leaked Externally Corporate Secrets and Other Sensitive Data at Risk of Theft

Society|
|
By Lee Yoo-jin
||
Police file photo - Seoul Economic Daily Society News from South Korea
Police file photo

Korean police have confirmed that access credentials for GitHub, a software development platform used by companies and developers at home and abroad, were leaked externally on a large scale, and have launched emergency security measures.

The National Office of Investigation under the Korean National Police Agency said on the 14th that it had confirmed that numerous Personal Access Tokens (PAT) for GitHub accounts had been leaked externally, and distributed an emergency security advisory to companies and individual developers.

A personal access token is an authentication method that allows users to access private GitHub repositories. If an attacker exploits it, there is a possibility of gaining unauthorized access to private repositories to obtain access information for key systems, or to steal sensitive data such as personal information and corporate secrets.

Police recommended that companies and individual developers using private GitHub repositories immediately check for unauthorized access to their repositories, revoke existing personal access tokens, and issue new ones. In particular, they advised users to check whether there had been abnormal access records over the past one to three months, and whether source code had been downloaded or altered from unused IP addresses or outside working hours.

To prevent further damage, police also requested compliance with basic security guidelines, including applying multi-factor authentication (MFA) for access permissions, minimizing and segmenting access permissions, prohibiting the inclusion of key system access information within source code, and conducting regular checks on the security status of developer PCs.

Police are investigating how the personal access tokens were leaked, while requesting security measures from the affected token users and GitHub. GitHub notified police that it had completed necessary security measures, including revoking the leaked tokens and warning the relevant users.

Police said they will promptly share additional threat information with related agencies and companies as soon as it is confirmed, and strengthen the public-private cooperation system to respond to similar cyberattacks.

"This is a case where we detected that attackers targeted not only companies' information and communications networks but also their software development infrastructure," said Park Woo-hyun, cyber investigation examiner at the Korean National Police Agency. "If criminal damage has occurred or you find suspicious signs, please report it immediately."

Original reporting by Lee Yoo-jin for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Pre-register
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

Pre-register for SIGNAL English Edition — a premium subscription bringing Korean capital markets coverage (M&A, IPOs, private equity, fund flows) to global institutional investors. First access to the 50% introductory rate.