500,000 Active Credentials Left Exposed on GitHub

500,000 Active Credentials Left Exposed on GitHub
Truffle Security found more than 1.1 million exposed credentials in public GitHub repositories, with 543,699 still active when retested in July 2026. The leaks include long-lived AWS keys, Google Cloud service accounts, MongoDB connection strings, and Google API keys, showing that many secrets were exposed but never revoked. #GitHub #TruffleSecurity #AWS #GoogleCloud #MongoDB

Keypoints

  • Truffle Security scanned 224 million public GitHub repositories.
  • It found 1,103,438 exposed credentials in August 2025.
  • 543,699 credentials were still active when tested in July 2026.
  • The oldest exposed secret was an AWS key committed in 2009.
  • Google Cloud service accounts, MongoDB strings, and Google API keys were the most common leaks.

Read More: https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/