GitHub detected unauthorized access to internal repositories on May 19, 2026. TeamPCP claims to have stolen data from nearly 4,000 private repositories and is selling the dataset on dark web forums with asking prices exceeding $50,000. The Google Threat Intelligence Group identified TeamPCP as UNC6780, a financially motivated actor. Changpeng Zhao urged developers to rotate API keys on May 20, 2026.
Aug 10, 2026 · 3 sources
Aug 10, 2026 · 8 sources
Aug 9, 2026 · 9 sources
Aug 8, 2026 · 2 sources
Story comments
Loading comments…