Skip to content
Credential Leaks Surge Amidst Expanding GitHub Activity

Credential Leaks Surge Amidst Expanding GitHub Activity

First seen 5 Oct 2026, 18:08 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 5, 2026 at 18:09 UTC
  • •28.65 million hardcoded secrets detected in 2025, a 34% increase from 2024.
  • •80% of corporate leaks traced back to personal developer repositories.
  • •GitHub commits surged from 1 billion in 2025 to an expected 14 billion in 2026.

In 2025, GitGuardian detected 28.65 million new hardcoded secrets in public GitHub commits, marking a 34% increase from the previous year. Nearly 80% of corporate credential leaks were traced back to developers' personal repositories, highlighting the risks of credential exposure beyond company walls. The rapid growth in software production, with GitHub reporting a jump from 1 billion commits in 2025 to an anticipated 14 billion in 2026, exacerbates the issue. Security teams are urged to enhance visibility into their credential layers as leaked credentials associated with AI services rose by 81%. GitGuardian's updated Public Monitoring capabilities aim to help organizations identify and manage these exposures effectively.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-01-01
GitGuardian reports credential leaks
GitGuardian detected 28.65 million new hardcoded secrets in public GitHub commits, a 34% increase from the previous year.
Blog.Gitguardian
2026-05-01
CISA leak reported
A significant credential leak was reported by CISA, echoing concerns about developer exposure.
Blog.Gitguardian
2026-10-01
GitGuardian updates Public Monitoring
GitGuardian launched an updated Public Monitoring feature to help organizations manage credential exposure effectively.
Blog.Gitguardian

More articles in this cluster (4)

Following this threat?

Track S1ingularity and AWS in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What are hardcoded secrets?
Hardcoded secrets are sensitive credentials like API keys or passwords embedded directly in source code.
How can we prevent credential leaks?
Organizations should implement strict access controls, use secret management tools, and regularly audit their code repositories.
What should we do if we find leaked credentials?
Immediately revoke the exposed credentials, investigate the source of the leak, and update security policies to prevent future incidents.