← Incident database

campfire-2026 · Disclosed 2026-04-03

CAMPFIRE: leaked GitHub credentials and cloud access

GitHub credentials mistakenly uploaded to a personal development server were misused. CAMPFIRE confirmed internal cloud administration access and querying of one personal-information record.

CredentialsConfiguration / exposure

Outcome: Confirmed breach

Entry path and evidence

  • Reported fact

    An employee mistakenly uploaded GitHub credentials to a personal development server.

    [s1]5. 原因
  • Assessment

    The company assesses that information obtained from GitHub enabled acquisition of cloud credentials.

    [s1]5. 原因
  • Reported fact

    One queried personal record was confirmed; 225,846 people are potentially affected, not a confirmed exfiltration count.

    [s1]3. 流出した可能性のある情報

Timeline

  1. Incident disclosed. [s1]

Reported response

  • Reported fact

    The company reported disconnecting GitHub, revoking and rotating credentials, and stopping affected cloud resources.

    [s1]4. 対応

Evidence relevant to prevention

Operational controls to inspect

Inspect secret exposure in published files and cloud privileges reachable from GitHub; verify old-key revocation.

Editorial assessment; not a determination of liability. [s1]

Unknowns and AI involvement

AI involvementUnknown

The cited sources do not establish attacker use of AI; absence of evidence is not evidence of absence.

Incomplete logs prevent a complete determination of accessed or exfiltrated information.

Sources

  1. [s1] CAMPFIRE · Primary source

    不正アクセスに関する調査結果と再発防止策について ↗

    Published 2026-06-02 · Reviewed 2026-10-02