South Korean police have confirmed that a large number of authentication credentials used to access GitHub, a developer platform operated by Microsoft, were leaked externally, and have taken emergency security measures in response.
The National Investigation Headquarters under the Korean National Police Agency said Tuesday it had distributed a security advisory containing emergency measures and recommendations "to prevent additional damage from the leak of GitHub access credentials."
According to the headquarters, the leaked information consists of GitHub "personal access tokens," or PATs — authentication credentials that users can employ in place of passwords.
"There is a risk that cyber attackers could use PATs to obtain information needed to access information and communications systems, and then steal sensitive data such as personal information or corporate secrets," the headquarters said, urging users to exercise particular caution.
The headquarters recommended that GitHub users immediately revoke any previously issued PATs. It also called on users to follow security best practices — including diversifying account access permissions and regularly checking the security status of their computers — to prevent further damage.
Following notification from the headquarters, GitHub took security measures of its own, including sending alerts to users whose PATs had been compromised.
Park Woo-hyun, the agency's cyber investigation review officer, said the case marked an instance of attackers targeting not only corporate networks but also development infrastructure. "Companies and individual developers should take security precautions, and immediately report any criminal damage or suspicious signs," he said.
arin@heraldcorp.com
