Skip to main content

500,000 Active Credentials Left Exposed on GitHub

0
High
News
Published: 10/01/2026 (10/01/2026, 09:43:56 UTC)
Source: SecurityWeek

Description

Truffle Security discovered over 500,000 active credentials exposed in public GitHub repositories, with many remaining active years after exposure. Despite GitHub's push protections and secret scanning programs, a large number of credentials remain active because providers do not always revoke leaked tokens. The exposed credentials include Google Cloud service account keys, MongoDB connection strings, and Google API keys. Nearly half of these credentials were pushed after GitHub enabled default push protections, highlighting that prevention alone does not eliminate risk without proper secret revocation.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 10/01/2026, 14:44:14 UTC

Technical Analysis

In August 2025, Truffle Security scanned 224 million public GitHub repositories and found over 1.1 million exposed credentials. By July 2026, 543,699 of these credentials were still active. The exposure window has a median of 784 days, with some credentials dating back to 2009. Despite GitHub's default push protections and secret scanning alerts, many credentials remain active because providers do not mandate revocation upon detection. The exposed secrets include 69,041 Google Cloud service account credentials, 51,067 MongoDB connection strings, and 33,343 Google API keys. The issue stems from the lack of automated revocation pipelines rather than the absence of detection controls.

Potential Impact

The exposure of over half a million active credentials publicly on GitHub poses a significant risk of unauthorized access to cloud services, databases, and APIs. The persistence of these active credentials increases the attack surface for potential misuse. However, the impact is mitigated by GitHub's push protections and secret scanning alerts, which help prevent new exposures. The main risk remains from credentials already exposed and not revoked by their providers.

Defensive Guidance

GitHub's push protection and secret scanning features are effective at preventing new exposures and alerting users. However, credential providers must implement automated revocation pipelines to promptly disable leaked secrets. Organizations should ensure that exposed credentials are rotated and revoked immediately upon detection. Users should enable and monitor GitHub's secret scanning alerts and act on them by rotating keys. No urgent remediation is required for GitHub itself, as the platform's controls are in place; the focus should be on credential lifecycle management by providers and users.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.3,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/","fetched":true,"fetchedAt":"2026-10-01T14:43:11.235Z","wordCount":1018}

Threat ID: 6abe717fb45efb4220452614

Added to database: 10/01/2026, 14:43:11 UTC

Last enriched: 10/01/2026, 14:44:14 UTC

Last updated: 10/01/2026, 14:47:40 UTC

Views: 5

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses