ThreatPaper
Assessed, Not Confirmed

Codecov attackers breached hundreds of restricted customer networks

Assessment

The figure originates with Reuters, reporting on 19 April 2021 and citing investigators who spoke on condition of anonymity. It was repeated widely from there, and the underlying reporting also describes the attackers using automation to reuse harvested credentials at scale and directing particular effort at other software development tool makers and technology service providers. No named authority has confirmed a count. Codecov has published no figure for downstream network access. CISA's alert of 30 April 2021 does not quantify impact. The FBI's San Francisco field office investigated and, according to the same reporting, notified dozens of likely victims — a number an order of magnitude smaller than "hundreds," and describing notification rather than confirmed intrusion. The reporting is credible and consistent with what victims disclosed voluntarily. It is rated Assessed rather than Verified because its sole basis is unnamed sources, and because a figure repeated across hundreds of articles still rests on the same single unattributed origin.

Where this claim appeared

BleepingComputer · 2021-04-19

https://www.bleepingcomputer.com/news/security/hundreds-of-networks-reportedly-hacked-in-codecov-supply-chain-attack/

What “Assessed, Not Confirmed” means

A named source states this as its own assessment, at its own stated confidence, rather than as established fact. Attribution to a nation state usually sits here. The assessment is real and reportable; treating it as settled is the error.

4 of 5 · rating scale

Assessed in

Codecov Bash Uploader Compromise: 60 Days of Silent CI Credential Theft

Think this assessment is wrong? Report an error.