First LastPass, now Slack and CircleCI. The hacks go on (and will likely worsen)

new year, new hack disclosures —

Don’t expect victims to be forthcoming. Their alerts conceal more than they reveal.


Shot of a person looking at a hacking message on her monitor reading

In the past 24 hours, the world has learned of serious breaches hitting chat service Slack and software testing and delivery company CircleCI, though giving the companies’ opaque wording—“security issue” and “security incident,” respectively—you’d be forgiven for thinking these events were minor.

The compromises—in Slack’s case, the theft of employee token credentials and for CircleCI, the possible exposure of all customer secrets it stores—come two weeks after password manager LastPass disclosed its own security failure: the theft of customers’ password vaults containing sensitive data in both encrypted and clear text form. It’s not clear if all three breaches are related, but that’s certainly a possibility.

The most concerning of the two new breaches is the one hitting CircleCI. On Wednesday evening, the company reported a “security incident” that prompted it to advise customers to rotate “all secrets” they store on the service. The alert also informed customers that it had invalidated their Project API tokens, an event requiring them to go through the hassle of replacing them.

CircleCI says it’s used by more than 1 million developers in support of 30,000 organizations and runs nearly 1 million daily jobs. The potential exposure of all those secrets—which could be login credentials, access tokens, and who knows what else—could prove disastrous for the security of the entire Internet.

A lack of transparency

CircleCI is still tight-lipped about precisely what happened. Its advisory never used the words “breach,” “compromise,” or “intrusion,” but that’s almost certainly what happened. Exhibit A is the statement: “At this point, we are confident that there are no unauthorized actors active in our systems,” suggesting that network intruders were active earlier. Exhibit B: the advice that customers check internal logs for unauthorized access between December 21 and January 4.

Taking the statements together, it’s not a stretch to suspect threat actors were active inside CircleCI’s systems for two weeks. That’s plenty of time to collect an unimaginable amount of some of the industry’s most sensitive data.

Slack’s advisory, meanwhile, is similarly opaque. It’s dated December 31, but the Internet Archives didn’t see it until Thursday, five days later. It’s clear Slack wasn’t in a hurry for the event to become widely known.

Like the CircleCI disclosure, the Slack alert also steers clear of concrete language and instead uses the passive phrase “were stolen and misused” without saying how. Adding to the lack of forthrightness: The company embedded the HTML tag in the post in an attempt to prevent search engines from indexing the alert.

After obtaining the Slack employee tokens, the threat actor misused them to gain access to the company’s external GitHub account. From there, the intruders downloaded private code repositories. The advisory stresses that its customers weren’t affected and that “the threat actor did not access other areas of Slack’s environment, including the production environment, and they did not access other Slack resources or customer data.”

Customers should take the statement with a generous helping of brine. Remember the LastPass advisory from August? It, too, used the opaque phrase “security incident” and said “no customer data was accessed,” only to reveal the true extent on the last major business day of 2022. It wouldn’t be surprising if Slack or CircleCI updated its advisories to disclose further access to customer data or more sensitive parts of their networks.

Hacking the supply chain

It’s possible, too, that some or all of these breaches are related. The Internet relies on a massive ecosystem of content delivery networks, authentication services, software development tool makers, and other companies. Threat actors frequently hack one company and use the data or access they obtain to breach that company’s customers or partners.

That was the case with the August breach of security provider Twilio that led to the compromise of Okta, Signal, DoorDash, and more than 130 other companies.

Something similar played out in the last days of 2020 when hackers compromised Solar Winds, gained control of its software build system, and used it to infect roughly 40 Solar Winds customers.

For now, people should brace themselves for additional disclosures from companies they rely on. Checking internal system logs for suspicious entries, turning on multifactor authentication, and patching network systems are always good ideas, but given the current events, those precautions should be expedited. It’s also worth checking logs for any contact with the IP address 54.145.167.181, which one security practitioner said was connected to the CircleCI breach.

People should also remember that despite companies’ assurances of transparency, their terse, carefully worded disclosures are designed to conceal more than they reveal.

Read More
Dan Goodin

Latest

Philippines SEC Signals Readiness for Real-World Asset Tokenization

You are here: Home / Cryptocurrency News / Philippines SEC Signals Readiness for Real-World Asset Tokenization The Philippines SEC has signalled the readiness of the country to tokenize its real-world assets (RWAs), with more and more trust being invested in the blockchain-powered financial tools. As per the opinion of the regulator, all the legal frameworks

FIFA president Infantino brushes off World Cup criticism as crypto ambitions linger in the background

Giovanni Infantino has never been accused of lacking confidence. At press conferences held between June 10-14, the FIFA president addressed a growing list of complaints about the 2026 World Cup by telling critics to “chill and relax.” The tournament, he insisted, would be a success. The critics have material to work with. Ticket prices for

Morocco’s World Cup win over Scotland sparks crypto prediction market frenzy

Morocco’s 1-0 victory over Scotland on June 19 wasn’t just a statement win for the Atlas Lions. It was also one of the most heavily traded sporting events in crypto prediction market history, with volumes exceeding $2 billion around the Group C opener alone. Ismael Saibari scored just 71 seconds into the match at Boston

Newsletter

Don't miss

Philippines SEC Signals Readiness for Real-World Asset Tokenization

You are here: Home / Cryptocurrency News / Philippines SEC Signals Readiness for Real-World Asset Tokenization The Philippines SEC has signalled the readiness of the country to tokenize its real-world assets (RWAs), with more and more trust being invested in the blockchain-powered financial tools. As per the opinion of the regulator, all the legal frameworks

FIFA president Infantino brushes off World Cup criticism as crypto ambitions linger in the background

Giovanni Infantino has never been accused of lacking confidence. At press conferences held between June 10-14, the FIFA president addressed a growing list of complaints about the 2026 World Cup by telling critics to “chill and relax.” The tournament, he insisted, would be a success. The critics have material to work with. Ticket prices for

Morocco’s World Cup win over Scotland sparks crypto prediction market frenzy

Morocco’s 1-0 victory over Scotland on June 19 wasn’t just a statement win for the Atlas Lions. It was also one of the most heavily traded sporting events in crypto prediction market history, with volumes exceeding $2 billion around the Group C opener alone. Ismael Saibari scored just 71 seconds into the match at Boston

5 Small Business Ideas for Retirees Who Don’t Want to Sit Still

Please enable JS and disable any ad blocker

Business delegation visits Kazakhstan to strengthen economic and trade cooperation

Astana, Kazakhstan, Jun 2, 2026 - (ACN Newswire) - A business delegation led by the Chief Executive of the Hong Kong Special Administrative Region (HKSAR), John Lee, and organised by the Hong Kong Trade Development Council (HKTDC), began its visit to Astana, the capital of Kazakhstan, on 1 June. During the visit, a total of 43

13 Real Business Trip Stories That Prove Work Travel Collects More Stories Than Miles

Real business trips almost never go the way the itinerary promised. They start with a confidently-packed suitcase and an eight-page agenda, and somewhere between the airport gate and the hotel breakfast they quietly turn into something nobody could have invented — equal parts comedy, chaos, and unscheduled adventure. These 13 real business trip moments are exactly that kind of work-trip plot

Your business texts could look like scam messages from July 1 if you don’t act now

From July 1, any branded SMS your business sends without a registered sender ID will be labelled “Unverified” and grouped with scam messages.  What’s happening: From 1 July 2026, any business or organisation that sends SMS using a branded name, such as “MyShop” or “AcmeServices”, instead of a phone number, must have that sender ID