Home Depot Credential Leak Exposes Internal Systems for a Year

Home Depot Credential Leak Exposes Internal Systems for a Year

First seen 13 Dec 2025, 01:50 UTC TechcrunchCsoonline 31.3

Article Content

Browse articles
ThreatCluster

A Home Depot employee inadvertently published a private GitHub access token in early 2024, granting access to internal systems for a year. Security researcher Ben Zimmermann discovered the exposed token and attempted to notify Home Depot, but received no response for several weeks. The issue was resolved after TechCrunch contacted the company representatives.