Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GitHub reported a phishing campaign in which attackers impersonated CircleCI and used counterfeit GitHub-style login pages to steal credentials. The pages could relay a victim’s time-based one-time password (TOTP) code to GitHub in real time, so TOTP alone did not stop this attack. GitHub’s alert is historical: the company said its Security team learned of the campaign on September 16. That notice does not establish that the campaign is active today.

How the phishing campaign worked

In its security alert, GitHub described attackers posing as CircleCI and directing users to a counterfeit login page designed to resemble GitHub’s sign-in flow. When users entered their GitHub credentials, the site captured them. If a user also entered a TOTP code, the phishing site relayed it to GitHub immediately, allowing the attacker to use the password and current code to authenticate.

This is a real-time phishing relay, not simply a fake page that saves a password for later. A TOTP code changes over time, but a live relay can pass a freshly entered code to the genuine service while it is valid. GitHub said accounts protected by hardware security keys were not vulnerable to this particular attack.

GitHub also warned that an attacker who gained access might establish ways to return later: creating personal access tokens (PATs), authorizing OAuth applications, or adding SSH keys. As a result, changing a password by itself may not remove access that was established through one of those mechanisms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
FEITIAN K9 USB A NFC - Two Factor Authenticator (2FA) - Multi-Factor Authentication (MFA) - Device Security Key + FIDO2 - Achieve Advanced Account Protection
  • FIDO2 + FIDO U2F certified and supported USB security key
  • Secured by NXP semiconductors
  • Works in every browser and application without installing any drivers
  • Supports desktops, laptops, tablets via USB-A and/or NFC, and supports iOS/Android Phones via NFC
  • Helps protect your accounts from phishing and other cyber-attacks. Prevents your devices from unauthorized use.

What to do if you entered your GitHub credentials

If you think you entered your password or 2FA code on a suspicious page, secure the account and check for access that may persist independently of your password.

  1. Reset your password and 2FA recovery codes. GitHub’s incident notice recommends resetting both if you believe you were phished.
  2. Review personal access tokens. In GitHub account settings, inspect your PATs and revoke any that are unexpected or no longer used.
  3. Review keys and authorizations. GitHub’s unauthorized-access guidance advises checking SSH keys, deploy keys, authorized OAuth apps, and GitHub Apps. Revoke unfamiliar access.
  4. Strengthen sign-in protection. Enable 2FA if it is not already enabled, and add a passkey. GitHub’s current setup recommendations are in its 2FA configuration documentation.

GitHub’s incident notice said that users who had not received an email notice had no evidence at that time that GitHub or an organization account had been accessed by the threat actor. That was a statement about the evidence available then, not a guarantee that an account is safe now.

Rank #2
Faraday Key Fob Jacket | RFID Signal Blocking & Water Resistant | Anti-Hacking | Ultimate Car Anti-Theft Protection Shielding Bag for Key Fobs and Key Cards | Magnetic Closure | Three Layers
  • ❌ CYBER BLOCKING: Specialized metal plated fabric containing nickel and copper shielding elements. Dissipates signals from both exterior and interior sources. Effectively blocking communication of signals to and from your device(s). -90dB attenuation 400Mhz-40Ghz.
  • ❌ DURABLE DESIGN: Water-resistant TPU outer layer, high quality exterior construction, double fold magnetic enclosure ensures 100% seal everytime.
  • ❌ SIZE: Interior dimensions is 4.75″ x 2.75″. Designed to accomadate any size keyfob, Tesla keycard and RFID badges
  • ❌ FEATURES: Heavy duty black TPU exterior designed for daily use, durable magnetic double fold for complete device isolation, and three interior layers of high performance CYBER nickel copper Faraday Fabric.
  • ❌ USE: Stop car theft via relay theft, great for rental/TURO owners.

How GitHub’s sign-in factors compare for phishing resistance

GitHub’s current guidance distinguishes between a primary 2FA method and a backup. Its mandatory-2FA documentation recommends TOTP as a primary method and a passkey or security key as backup. The incident shows why the setup role matters: a TOTP code can be relayed during a live phishing session, while phishing-resistant methods bind authentication to the legitimate site.

Method Phishing resistance relevant to this incident Role in GitHub’s current guidance Source
TOTP authenticator app A code can be captured and relayed in real time, as in the campaign GitHub described. Recommended as a primary method in GitHub’s mandatory-2FA guidance; a passkey or security key is recommended as backup. Incident alert; 2FA setup guidance
SMS GitHub says SMS-based 2FA is vulnerable to phishing and does not provide the same protection as passkeys and security keys. The cited guidance does not establish SMS as the recommended primary method in the TOTP-plus-backup configuration. Account-security best practices
Hardware security key / WebAuthn GitHub said hardware-key-protected accounts were not vulnerable to the described campaign and recommends security keys or WebAuthn against attacks that collect 2FA codes. Recommended as a backup option alongside a passkey in GitHub’s mandatory-2FA guidance. Incident alert; Account-security best practices; 2FA setup guidance
Passkey GitHub describes passkeys as phishing-resistant. Recommended as a backup option alongside a security key in GitHub’s mandatory-2FA guidance. Unauthorized-access guidance; 2FA setup guidance

GitHub’s documentation can change, so consult its current setup pages when configuring an account. This comparison is limited to the phishing resistance and setup roles supported by those sources; it does not rank methods by convenience, price, or device compatibility.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Thales - SafeNet eToken FIDO - FIDO2 Certified Security Key - Passwordless Phishing-Resistant Authentication for Web Apps, Devices & Desktops - USB-C - Pack of 1
  • FIDO2 SECURITY KEY: A versatile, tamper-evident USB-C authentication device with sensitive presence detection for online security. FIDO 2.0 level 1 and U2F certified
  • PASSWORDLESS CONVENIENCE: Replace frustrating passwords with a simple 4-digit PIN for accessing apps and sites. Seamlessly login to web apps and Windows sessions
  • BROAD COMPATIBILITY: Works with Windows, Mac, Linux, Apple, iOS, iPhone, Android and USB-C devices. Seamlessly integrates with Identity Providers or Credential Management Systems supporting FIDO2, including Thales, Microsoft, AWS, and Google
  • ENHANCED USER ADOPTION: Features a sensitive presence detector on the USB key, providing ease of use and superior security. Certified for U2F and FIDO2, ideal for individuals who want to secure access to their personal online accounts - Microsoft, Google, Twitter, Facebook, GitHub
  • THALES: We offer a wide range of FIDO authenticators, providing robust, phishing-resistant MFA that comply with stringent regulations. With almost three decades of experience, Thales is a pioneer in passwordless authentication devices, supported globally by the FIDO Alliance and industry analysts
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the alert does—and does not—say about current risk

The notice establishes what GitHub reported about a campaign its Security team learned of on September 16. It does not provide a victim count or success rate, and its historical discovery date is not evidence that the same campaign is operating now. Treat an unexpected CircleCI-branded message or GitHub sign-in link cautiously, and navigate to GitHub directly rather than signing in through a link you did not expect.

Best Value
Thetis BIOFP Plus FIDO2 Fingerprint Security Key Hardware Passkey with USB Type C/Biometric/FIDO Certified, 2FA / MFA Authenticator App Device, Works for Window, macOS, Linux, Gmail, Github
  • FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
  • Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
  • Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
  • USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
  • Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.
Rank #4
Swissbit iShield Key 2 FIDO2 USB-C Security Key with NFC – FIDO Certified, Passwordless Authentication, Passkey & U2F, Phishing-Resistant Security for Enterprise
  • SECURITY KEY FOR ENTERPRISE ACCESS: Supports FIDO2 passkeys and U2F for secure authentication across enterprise IT systems.
  • PHISHING-RESISTANT AUTHENTICATION: Enables passwordless login with secure on-device credential storage and PIN-based user verification.
  • COMPATIBLE WITH ENTERPRISE SYSTEMS: Works with FIDO2, WebAuthn, and U2F across enterprise, cloud, and modern IT environments.
  • DRIVERLESS FIDO2 AUTHENTICATION: FIDO2 works natively with modern browsers and platforms. No drivers required.
  • USB AND NFC CONNECTIVITY: Supports authentication via USB-C and NFC. No batteries required.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.