500,000 Active Credentials Left Exposed on GitHub
Truffle Security discovered over 500,000 active credentials exposed in public GitHub repositories, with many remaining active years after exposure. Despite GitHub's push protections and secret scanning programs, a large number of credentials remain active because providers do not always revoke leaked tokens. The exposed credentials include Google Cloud service account keys, MongoDB connection strings, and Google API keys. Nearly half of these credentials were pushed after GitHub enabled default push protections, highlighting that prevention alone does not eliminate risk without proper secret revocation.
AI Analysis
Technical Summary
In August 2025, Truffle Security scanned 224 million public GitHub repositories and found over 1.1 million exposed credentials. By July 2026, 543,699 of these credentials were still active. The exposure window has a median of 784 days, with some credentials dating back to 2009. Despite GitHub's default push protections and secret scanning alerts, many credentials remain active because providers do not mandate revocation upon detection. The exposed secrets include 69,041 Google Cloud service account credentials, 51,067 MongoDB connection strings, and 33,343 Google API keys. The issue stems from the lack of automated revocation pipelines rather than the absence of detection controls.
Potential Impact
The exposure of over half a million active credentials publicly on GitHub poses a significant risk of unauthorized access to cloud services, databases, and APIs. The persistence of these active credentials increases the attack surface for potential misuse. However, the impact is mitigated by GitHub's push protections and secret scanning alerts, which help prevent new exposures. The main risk remains from credentials already exposed and not revoked by their providers.
Mitigation Recommendations
GitHub's push protection and secret scanning features are effective at preventing new exposures and alerting users. However, credential providers must implement automated revocation pipelines to promptly disable leaked secrets. Organizations should ensure that exposed credentials are rotated and revoked immediately upon detection. Users should enable and monitor GitHub's secret scanning alerts and act on them by rotating keys. No urgent remediation is required for GitHub itself, as the platform's controls are in place; the focus should be on credential lifecycle management by providers and users.
500,000 Active Credentials Left Exposed on GitHub
Description
Truffle Security discovered over 500,000 active credentials exposed in public GitHub repositories, with many remaining active years after exposure. Despite GitHub's push protections and secret scanning programs, a large number of credentials remain active because providers do not always revoke leaked tokens. The exposed credentials include Google Cloud service account keys, MongoDB connection strings, and Google API keys. Nearly half of these credentials were pushed after GitHub enabled default push protections, highlighting that prevention alone does not eliminate risk without proper secret revocation.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
In August 2025, Truffle Security scanned 224 million public GitHub repositories and found over 1.1 million exposed credentials. By July 2026, 543,699 of these credentials were still active. The exposure window has a median of 784 days, with some credentials dating back to 2009. Despite GitHub's default push protections and secret scanning alerts, many credentials remain active because providers do not mandate revocation upon detection. The exposed secrets include 69,041 Google Cloud service account credentials, 51,067 MongoDB connection strings, and 33,343 Google API keys. The issue stems from the lack of automated revocation pipelines rather than the absence of detection controls.
Potential Impact
The exposure of over half a million active credentials publicly on GitHub poses a significant risk of unauthorized access to cloud services, databases, and APIs. The persistence of these active credentials increases the attack surface for potential misuse. However, the impact is mitigated by GitHub's push protections and secret scanning alerts, which help prevent new exposures. The main risk remains from credentials already exposed and not revoked by their providers.
Defensive Guidance
GitHub's push protection and secret scanning features are effective at preventing new exposures and alerting users. However, credential providers must implement automated revocation pipelines to promptly disable leaked secrets. Organizations should ensure that exposed credentials are rotated and revoked immediately upon detection. Users should enable and monitor GitHub's secret scanning alerts and act on them by rotating keys. No urgent remediation is required for GitHub itself, as the platform's controls are in place; the focus should be on credential lifecycle management by providers and users.
Technical Details
- Classification
- {"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/","fetched":true,"fetchedAt":"2026-10-01T14:43:11.235Z","wordCount":1018}
Threat ID: 6abe717fb45efb4220452614
Added to database: 10/01/2026, 14:43:11 UTC
Last enriched: 10/01/2026, 14:44:14 UTC
Last updated: 10/01/2026, 14:47:40 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.