Observed Signal · May 20, 2026 · Security Breach · Source: t3n · Impact: 4/5 · Sentiment: Negative

Team‑PCP steals 3,800 internal GitHub repositories

Executive Signal Summary

The hacker group Team‑PCP accessed approximately 3,800 internal GitHub repositories between May 18 and May 19, 2026, and is attempting to sell the stolen data. GitHub confirmed the incident on X and said no customer data was affected. According to GitHub, attackers used a compromised employee device that had a malicious Visual Studio Code extension installed; the impacted endpoint was isolated and incident response measures were taken. Team‑PCP, previously linked to a March 2026 supply‑chain attack and said to collaborate with the Ransomware‑as‑a‑Service operator Vect, is offering the GitHub data for sale and reportedly coordinated with the LAPSUS$ group in later negotiations.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

GitHub is a central developer collaboration platform; a breach of internal repositories elevates software supply‑chain risk, could expose sensitive code or credentials, and undermines trust in critical developer infrastructure.

SIGNAL RADAR

Track TargetVideo Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • Team‑PCP gained access to about 3,800 internal GitHub repositories between 2026-05-18 and 2026-05-19.
  • GitHub confirmed the breach publicly on X and stated that customer data was not affected.
  • GitHub said the attackers used a compromised employee device containing a malicious Visual Studio Code extension as the entry vector; the endpoint was isolated and incident response initiated.
  • Team‑PCP is offering the stolen data for sale (initially listing a $50,000 minimum; later reports say alliance with LAPSUS$ raised the demand to $95,000).
  • Team‑PCP previously executed a large supply‑chain attack in late March 2026 and has been reported to work with Vect, a Ransomware‑as‑a‑Service operator.
Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: t3n•Published: May 20, 2026
Original Coverage Title: “Angriff auf GitHub über kompromittiertes Gerät: Hacker stehlen 3.800 interne Repositories”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

FinancialsOct 1, 2026

Software Stocks Rally in Q3; Cramer Sees More Upside

In the third quarter, software stocks rebounded strongly as concerns about AI disrupting traditional business models eased. The iShares Expanded Tech-Software Sector ETF (IGV) rose 17%, while the semiconductor ETF fell 11%. Salesforce rallied 46%, helped by the launch of 'Claudeforce' with Anthropic, and Microsoft gained 37% on strong Copilot demand and Azure growth. Workday and Veeva also saw significant gains. Jim Cramer highlighted the comeback as the defining market story and remains bullish on Salesforce and Microsoft, while noting that higher interest rates pose a risk. Cybersecurity stocks like CrowdStrike also performed well. The article reflects market sentiment and investor perspectives but does not introduce new corporate events or significant AdTech developments.

Read assessment
CybersecurityOct 1, 2026

IGEL Brings Now & Next Security Summit to Dubai

IGEL, a global software company specializing in secure endpoint operating systems, announced it will host the Now & Next® Workspace & Endpoint Security Summit in Dubai on October 21, 2026, at the Dubai Knowledge Park. The one-day event will bring together IT and security executives to discuss endpoint security, resilience, and workspace delivery strategies in the Middle East. The summit is part of IGEL's flagship roadshow series, which has already visited European cities, Australia, and the US. Sponsors include Microsoft, Omnissa, and Lenovo. The event addresses the growing security threats in the region, citing the UAE Government Cybersecurity Council's report of 90,000 to 200,000 daily attack attempts. IGEL CEO Klaus Oestermann emphasized the need for better endpoint control and resilience, while VP of Sales Carsten Thomsen highlighted Dubai as a strategic meeting point for regional technology leaders.

Read assessment
SecurityOct 1, 2026

Cyberattacks: US, Israel, Ukraine Top Microsoft's 2026 List

Microsoft's Digital Defense Report 2026 reveals that the USA is the most targeted country, accounting for 25.5% of all observed attacks, followed by Israel (7.6%), Ukraine (4.8%), and Taiwan (3.9%). Germany is the only EU country in the top 10 with 1.7% of attacks. The report highlights geopolitical conflicts as a major driver, with Russian attackers focusing on Ukraine and NATO states, and Chinese groups targeting the Indo-Pacific and strategic tech hubs. Ransomware cases in Germany surged by 276% year-over-year, while globally, ransomware attacks on businesses increased by 15.8%. Microsoft warns that AI is accelerating attacks, making them faster, cheaper, and harder to detect, and notes that AI systems themselves are becoming targets. The report also highlights vulnerabilities in cloud systems, with unprotected systems being attacked on average within 5.3 hours. Microsoft recommends passkeys and phishing-resistant MFA to combat credential theft.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.