Security News > 2024 > June > New York Times warns freelancers of GitHub repo data breach

The New York Times notified an undisclosed number of contributors that some of their sensitive personal information was stolen and leaked after its GitHub repositories were breached in January 2024.
"The New York Times recently communicated to some of our contributors regarding an incident that resulted in the exposure of some of their personal information," a Times spokesperson told BleepingComputer.
As BleepingComputer reported over the weekend, a 273GB torrent file containing The New York Times' stolen data was leaked on the 4chan message board on Thursday.
"Around June 6, 2024, a post on another third-party site made this data publicly available, including a file that contained some of your personal information," the Times confirmed in data breach notification letters sent to affected contributors.
The Times advises anyone affected by this data breach to be cautious of unexpected emails, phone calls, or messages requesting personal information like usernames, passwords, and date of birth which could be used to gain access to their accounts without permission.
New York Times source code stolen using exposed GitHub token.
News URL
Related news
- GrubHub data breach impacts customers, drivers, and merchants (source)
- HPE notifies employees of data breach after Russian Office 365 hack (source)
- Fintech giant Finastra notifies victims of October data breach (source)
- US drug testing firm says data breach impacted 3.3 million people (source)
- US drug testing firm DISA says data breach impacts 3.3 million people (source)
- Background check, drug testing provider DISA suffers data breach (source)
- Data breach at Japanese telecom giant NTT hits 18,000 companies (source)
- PowerSchool previously hacked in August, months before data breach (source)
- Western Alliance Bank notifies 21,899 customers of data breach (source)
- Sperm donation giant California Cryobank warns of a data breach (source)