Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Deloitte Breach Claim 2025: Hacker “303” Alleges Leak…
Breach analysis Incident: 30 May 2025

Deloitte Breach Claim 2025: Hacker “303” Alleges Leak of GitHub Credentials and Source Code

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 6 min read
Claimed Category: NHI
Attack route: Not disclosed Identities: Source control token
On this page

On 30 May 2025, a threat actor using the alias "303" claimed on a dark web forum to have breached Deloitte and published what it said were internal GitHub credentials and source code from repositories belonging to Deloitte's US consulting division. According to Cyber Kendra, the posted material included configuration files and repository information that appeared to come from Deloitte's internal systems, and GitHub credentials that could grant access to the company's development environment. Deloitte had not responded to requests for comment at the time of reporting, and the claim remains unconfirmed. Reporting on this incident is limited: we found only a small number of independent accounts, and none from Deloitte. What the claim describes, however, is a familiar pattern: source control credentials exposed alongside code, giving whoever holds them a route into build systems and private repositories.

Key takeaways

  • A threat actor called "303" claimed in May 2025 to have leaked Deloitte GitHub credentials and source code from its US consulting division.
  • The claim is unconfirmed; Deloitte had not responded to requests for comment when it was reported.
  • Cyber Kendra reported that the leak included configuration files and repository information appearing to come from Deloitte's internal systems.
  • Deloitte denied a separate breach claim by the Brain Cipher ransomware group in December 2024.
  • The identity lesson: a GitHub credential is a key to code, pipelines and the secrets inside them, and should be short-lived, scoped and monitored.

At a glance

OrganisationDeloitte (US consulting division, according to the claim)
WhenClaim posted 30 May 2025
AttackerA threat actor using the alias "303" (claimed)
Entry pointNot disclosed
Identities abusedGitHub credentials for internal repositories, according to the claim
ImpactAlleged leak of GitHub credentials, configuration files and proprietary source code; unconfirmed by Deloitte
CategoryNHI. Incident class: claimed breach (source control credentials and code; unconfirmed)

What happened

Cyber Kendra reported that "a threat actor claiming the alias "303" reportedly posted internal GitHub credentials and proprietary source code on a dark web forum," and that "The alleged breach specifically targets Deloitte's U.S. consulting division, potentially exposing critical development infrastructure to unauthorized access." Citing cybersecurity monitoring services, it said the actor "published configuration files and repository information that appear to originate from Deloitte's internal systems." A summary of Cybersecurity News' report, published by Rankiteo, described the data as "GitHub credentials and source code from internal project repositories belonging to Deloitte's U.S. consulting division."

Deloitte had not commented. "Deloitte has not yet responded to requests for comment regarding these latest allegations. The full scope and validity of the alleged breach remain unconfirmed," Cyber Kendra wrote. It also noted that "303" had previously been linked to an alleged December 2024 breach of an Indian software company that affected insurance providers.

The claim followed others. In December 2024, the Brain Cipher ransomware group made breach allegations that Deloitte denied, saying "no Deloitte systems have been impacted" and attributing any compromised data to "a single client's system which sits outside of the Deloitte network," Cyber Kendra reported. Cyber Kendra also recalled that in 2017 security researchers found Deloitte corporate VPN passwords, usernames and operational details exposed in a public GitHub repository.

Timeline

DateEvent
2017Researchers find Deloitte VPN credentials in a public GitHub repository, according to Cyber Kendra.
December 2024Brain Cipher claims a Deloitte breach; Deloitte denies its systems were affected.
30 May 2025"303" posts alleged Deloitte GitHub credentials and source code.

How it happened: the identity attack path

  1. Initial access. Not disclosed; the claim does not say how the credentials were obtained.
  2. Credentials collected. GitHub credentials for internal repositories were allegedly obtained.
  3. Code accessed. Source code from proprietary projects was allegedly taken.
  4. Publication. Credentials, configuration files and code were posted on a dark web forum.
  5. Unconfirmed. Deloitte had not commented at the time of reporting.

Impact

  • Claimed: GitHub credentials, configuration files and source code from Deloitte's US consulting division.
  • Potential: access to development environments, build systems or private repositories if the credentials were valid.
  • Confirmed: nothing; Deloitte has not confirmed a breach.

What this means for NHI governance

Even as a claim, this case shows why source control credentials deserve the same care as production keys. A GitHub token or password gives access to code, and code repositories often hold more secrets in configuration files, pipeline definitions and history. For a consulting firm, repositories may also contain client work, so one exposed credential can reach far beyond the firm itself.

The controls are well understood: fine-grained, short-lived tokens instead of passwords and classic personal access tokens, secret scanning on every repository including history, and alerts on unusual cloning or access from new locations. See our Secrets Management Guide and CI/CD Pipeline Identity Security Guide.

Recommendations

  • Use short-lived, scoped GitHub credentials. Prefer GitHub Apps or fine-grained tokens with expiry. See our NHI Authentication Guide.
  • Scan repositories and history for secrets. Configuration files often hold credentials. See our Secrets Management Guide.
  • Treat a credible leak claim as an incident. Rotate the named credentials while investigating. See the Leaked Credential Response Playbook.
  • Monitor source control access. Alert on bulk cloning and logins from unusual locations. See the ITDR Guide.
  • Keep client material out of shared repositories. Separate client work to limit what one credential can reach.

Frequently asked questions

Was Deloitte breached in 2025?

A threat actor called "303" claimed in May 2025 to have leaked Deloitte GitHub credentials and source code. Deloitte had not confirmed the claim when it was reported.

What did the "303" leak allegedly contain?

GitHub credentials, configuration files and source code from internal repositories of Deloitte's US consulting division, according to the claim.

Why is reporting on this incident limited?

Only a few outlets covered the claim and Deloitte made no public statement, so the details come from the attacker's post as described by reporters.

SpotBugs Token Leak 2025 · CrewAI GitHub Token Exposure 2025 · Secrets Management Guide · CI/CD Pipeline Identity Security Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Source control credentials open doors to code, pipelines and client work. We help teams replace long-lived tokens, scan for secrets and respond quickly to leak claims. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org