Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months
Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

Key points
- Over 50 dormant GitHub accounts, some registered up to five years ago, sent waves of automated scanning traffic targeting organisations and their members from at least October 2025.
- The campaign used GitHub's public API, the system that lets software talk to GitHub's servers, to map companies and their employees alongside the code projects those employees work on.
- Criminals also used accidentally exposed login tokens from real GitHub users to access private, non-public repositories.
- Datadog, the cloud-security company that spotted the activity, confirmed data was successfully stolen from some targeted organisations.
- The fake accounts disguised their traffic by naming themselves after everyday analytics or dashboard tools.
A network of throwaway GitHub accounts, left untouched for years before being activated, spent months quietly mapping thousands of companies and their software projects, according to research by cloud-security firm Datadog. We covered Datadog's earlier findings on this campaign on 8 July 2026, when the automated snooping was already blending cleanly into normal traffic.
GitHub is the world's largest platform for storing and sharing software code, used by organisations to host projects and coordinate developers.
The accounts ran automated scanners against GitHub's API, pulling back lists of organisations, their members, the code repositories (essentially folders of software files) they maintain, and the accounts they follow. No password was needed: GitHub makes much of that information publicly available.
Why would criminals bother mapping information that is already public?
Public data is the starting point. By stitching together employee names, the projects they contribute to, and the tools a company appears to use, criminals can build a detailed picture of a target before attempting anything more serious. It's the digital equivalent of watching a building for weeks before testing the doors.
Datadog says the accounts worked in bursts lasting one to three weeks, using fake names designed to sound like legitimate software tools to avoid the suspicious labels security teams watch for.
In at least one case the operation moved beyond public data. The criminals found login tokens, digital keys, that real GitHub users had accidentally published inside their own code. Using those tokens, the attackers accessed private repositories over a window of just a few minutes. In a small number of cases, files were actually stolen.
Over 50 accounts have taken part since at least October 2025, across multiple overlapping waves of activity, first reported by SecurityWeek.
For developers and businesses on GitHub, the practical steps aren't complicated. Check that no API keys or access tokens have been accidentally included in uploaded code. Enable GitHub's audit log streaming feature, which records a running history of who accessed what and when. Review which applications have permission to touch your repositories and revoke anything unfamiliar.
Datadog also recommends building a baseline of what normal API traffic looks like in your environment, so unusual bursts stand out quickly.
This campaign is a reminder that reconnaissance doesn't need a single successful login to be useful. By the time attackers try a door, they've already drawn the floor plan.



