Last updated 1 month ago
Vodafone, a major international telecommunications company, sustained a source code leak claimed by the Lapsus$ extortion group. The company confirmed limited access to GitHub files through compromised third-party development software. No discovery date was provided, but the incident was publicly disclosed in the week of 18th May 2026. The number of affected records or users was not disclosed.
The attack chain involved the compromise of third-party development software, which was used as an initial access vector to gain unauthorized entry into Vodafone's GitHub repositories. The threat actor, Lapsus$, is known for extortion-driven data theft and has previously targeted technology and telecommunications firms. The exfiltrated data consisted of source code from the affected repositories; no customer or employee personal data was reported as compromised.
No further post-incident developments were reported in the article. There is no mention of regulatory involvement, litigation, ransom payment, or specific remediation milestones.
Compromised third-party development software led to unauthorized access to GitHub repositories
Vodafone's breach underscores the critical need for rigorous third-party software security assessments and continuous monitoring of access to code repositories. The incident highlights that even limited exposure through a development partner can lead to significant intellectual property loss, emphasizing the importance of enforcing least-privilege access and implementing robust supply chain security controls.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Threat Actor
Continent
Country
Industry
Attack Vector
Threat Actor