GitHub detected unauthorized access to internal repositories on May 19, 2026. TeamPCP claims to have stolen data from nearly 4,000 private repositories and is selling the dataset on dark web forums with asking prices exceeding $50,000. The Google Threat Intelligence Group identified TeamPCP as UNC6780, a financially motivated actor. Changpeng Zhao urged developers to rotate API keys on May 20, 2026.
Sep 28, 2026 · 6 sources
Sep 28, 2026 · 8 sources
Sep 27, 2026 · 2 sources
Sep 26, 2026 · 2 sources
Story comments
Loading comments…