Identity security firm SailPoint discloses GitHub repository breach

SailPoint disclosed a GitHub repository breach on April 20. The company contained the incident and said no customer data was affected.
SailPoint is a cybersecurity company that provides identity security and identity governance solutions for enterprises. Its products help organizations manage and control user access to systems, applications, and sensitive data.
SailPoint revealed a cybersecurity incident involving its GitHub repositories that occurred on April 20. The identity management firm said it quickly contained the breach with the help of a third-party cybersecurity firm. The company confirmed the attack did not impact customer data or its production and staging environments.
“On April 20, 2026, we detected unauthorized access to a subset of our GitHub repositories. Our incident response team quickly terminated the unauthorized activity and resolved the issue. The root cause was a vulnerability in a third-party application, which has been remediated.” reads the FORM 8-K filed with the U.S. Securities and Exchange Commission (SEC)..
“Based on our investigation, supported by a third-party cybersecurity response firm, we found no evidence that customer data in our production or staging environments were accessed or that our services were interrupted.”
SailPoint did not disclose further details about the security breach or the type of data that may have been compromised.
SailPoint said it directly notified affected customers and currently sees no need for further customer action.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, SailPoint)


