Dormant GitHub Accounts Help Attackers Stay Hidden and Map Corporate Orgs

Colleagues, I’d like to highlight a cybersecurity development: attackers are increasingly abusing dormant GitHub accounts for covert reconnaissance.
According to Datadog Security Labs, they are gathering intelligence at scale via the GitHub API: public repositories, users, and relationships between accounts and orgs.
In some cases, compromised OAuth tokens and PATs are also used, along with old accounts that have been inactive for years.
Importantly, some scenarios went beyond data discovery and included attempts to clone private repositories.
Why it matters: each request may look harmless on its own, but together they allow attackers to build an accurate map of your GitHub ecosystem.
How do you monitor suspicious activity in GitHub?
#cybersecurity #GitHub #ThreatIntelligence

