
Korean police have confirmed that access credentials for GitHub, a software development platform used by companies and developers at home and abroad, were leaked externally on a large scale, and have launched emergency security measures.
The National Office of Investigation under the Korean National Police Agency said on the 14th that it had confirmed that numerous Personal Access Tokens (PAT) for GitHub accounts had been leaked externally, and distributed an emergency security advisory to companies and individual developers.
A personal access token is an authentication method that allows users to access private GitHub repositories. If an attacker exploits it, there is a possibility of gaining unauthorized access to private repositories to obtain access information for key systems, or to steal sensitive data such as personal information and corporate secrets.
Police recommended that companies and individual developers using private GitHub repositories immediately check for unauthorized access to their repositories, revoke existing personal access tokens, and issue new ones. In particular, they advised users to check whether there had been abnormal access records over the past one to three months, and whether source code had been downloaded or altered from unused IP addresses or outside working hours.
To prevent further damage, police also requested compliance with basic security guidelines, including applying multi-factor authentication (MFA) for access permissions, minimizing and segmenting access permissions, prohibiting the inclusion of key system access information within source code, and conducting regular checks on the security status of developer PCs.
Police are investigating how the personal access tokens were leaked, while requesting security measures from the affected token users and GitHub. GitHub notified police that it had completed necessary security measures, including revoking the leaked tokens and warning the relevant users.
Police said they will promptly share additional threat information with related agencies and companies as soon as it is confirmed, and strengthen the public-private cooperation system to respond to similar cyberattacks.
"This is a case where we detected that attackers targeted not only companies' information and communications networks but also their software development infrastructure," said Park Woo-hyun, cyber investigation examiner at the Korean National Police Agency. "If criminal damage has occurred or you find suspicious signs, please report it immediately."






