Microsoft (VSCode) and GitHub - Levi & Korsinsky, LLP

Report a Violation

Thank you for your report. Our team will review and follow up.

Date of Breach Date of Breach
2026-06-02
Allegation Allegation
Data Breach
Institution Type Institution Type
IT / Cybersecurity
Number Impacted Number Impacted
Unknown
What Happened?

What Is This About?

If you recently received a letter or an email from Microsoft (VSCode) and GitHub informing you that your sensitive personal information was compromised in a data breach, we would like to speak with you about your rights and potential legal remedies. Microsoft (VSCode) and GitHub recently disclosed that it was the victim of a security vulnerability/incident that exposed individuals’ sensitive personal information.
What Happened?

What Happened?

On June 2, 2026, security researcher Ammar Askar publicly disclosed a critical vulnerability in Visual Studio Code’s webview implementation affecting both the browser-based github.dev environment and the desktop VSCode application. The disclosure described an attack in which a victim could have GitHub OAuth tokens exfiltrated after clicking a single malicious link, with the stolen tokens allegedly enabling full read/write access to victims’ private GitHub repositories globally. The described attack chain includes use of malicious Jupyter Notebook or VSCode extension files, potential silent installation of malicious extensions, and exploitation of unscoped OAuth tokens. The disclosure also stated the issue could potentially lead to Remote Code Execution (RCE). Based on the provided information, Microsoft/GitHub’s date of discovery, whether third-party forensic investigators were engaged, whether notice letters were sent to impacted individuals, and whether any Attorney General or other government filings were made have not been provided. The disclosure further stated there was no prior coordinated disclosure with Microsoft and that GitHub was notified approximately one hour before the public release.
What Happened?

What Information Was Impacted?

Upon information and belief, the following types of sensitive personal information may have been compromised:

  • "GitHub OAuth tokens (authentication/access tokens)";
  • "Access to private GitHub repositories (read/write access enabled by stolen tokens)" .

What Happened?

What Action Can You Take?

Levi & Korsinsky, LLP is investigating whether affected users are entitled to compensation. If you received a notice from Microsoft (VSCode) and GitHub, there is no cost or obligation to participate. Follow the link below to find out about your rights and potential legal remedies available.

About

Microsoft (VSCode) and GitHub

Microsoft (VSCode) and GitHub, headquartered in Redmond, Washington (Microsoft) and San Francisco, California (GitHub), are IT / Cybersecurity technology providers that specialize in developer tools and source-code hosting/collaboration platforms, including Visual Studio Code and GitHub.

About

Levi & Korsinsky

Levi & Korsinsky is a nationally recognized consumer advocacy law firm that has recovered hundreds of millions of dollars against large corporations. The firm is a 100% contingency firm – we don't get paid unless you get paid! Attorney Advertising. Prior results do not guarantee similar outcomes.  

UNDER THE RULES OF CERTAIN JURISDICTIONS, THIS WEBSITE MAY CONSTITUTE ATTORNEY ADVERTISING.

  • Step

    Preliminary Form

  • Step

    Review & Validation

  • Step

    Declaration & Retainer

  • Step

    Follow-up Form

Get Started

Step One Complete

We’ve got your info! We’re reviewing it now to check if you’re eligible.

Verification in Process

Almost Done

We’ve started your claim. Help us move faster and make your case even stronger by answering a few quick questions.

Follow-up Details Process

Sorry,

It looks like you do not qualify for this case. Please be sure to check our other featured cases to see if you qualify for another claim.

All Set!

You’re all done for now. Our team is reviewing your case and will be in touch soon.
Sit back and relax — we’ve got it from here.

Sorry,

It looks like you do not qualify for this case. Please be sure to check our other featured cases to see if you qualify for another claim.

Loader