CSIDB logo
Incident

Flood.io

Incident posture

Attack window
Jul 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2025-10-30 00:00

Linked entities

Victim
Flood.io
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Hackers exploited a blind SQL injection vulnerability in a Git analytics platform to steal GitHub and GitLab OAuth tokens from its internal database, subsequently using these tokens to infiltrate external customer code repositories. The compromised credentials facilitated unauthorized access to source code projects at multiple companies, including Flood.io, leading to breaches disclosed shortly after the incident. The affected platform promptly addressed the vulnerability, invalidated stolen tokens through collaboration with Git service providers, and implemented enhanced security controls such as activity monitoring and token resets while sharing threat indicators to support customer investigations.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 3, 2020, hackers exploited a blind SQL injection vulnerability in Waydev, a Git analytics platform, to infiltrate its internal database and steal GitHub and GitLab OAuth tokens. These tokens, used by Waydev customers to integrate their code repositories with the analytics service, allowed attackers to pivot to external systems. GitHub’s security team detected anomalous activity linked to a customer’s Waydev token, prompting an investigation that revealed the breach. Waydev immediately patched the vulnerability upon discovery and collaborated with GitHub and GitLab to revoke compromised tokens, delist original OAuth applications, and issue replacements to invalidate attacker access. The company confirmed hackers accessed only a limited subset of customer codebases but did not disclose the exact number of affected organizations.

The stolen tokens facilitated subsequent breaches at multiple companies, including financial service provider Dave.com and software testing platform Flood.io, both of which publicly attributed their July 2020 security incidents to the Waydev compromise. Waydev notified U.S. authorities and shared attacker indicators—such as IP addresses, email addresses, and user-agent strings—to assist customers in log reviews. Post-incident, Waydev implemented stricter security controls, including manual account approvals, continuous activity monitoring, and periodic token resets. The company directed users to its support portal for additional guidance but did not specify whether customer data beyond code repositories was exposed. No further details regarding Flood.io’s specific compromise scope or operational disruptions were disclosed in the available reporting.

Sources

Sources available to members: 1 source.

CSIDB