Skip to content
Over 543,000 Valid Credentials Exposed on GitHub Despite Security Measures

Over 543,000 Valid Credentials Exposed on GitHub Despite Security Measures

First seen 30 Sep 2026, 19:28 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 30, 2026 at 20:30 UTC
  • •Over 543,000 valid credentials were found in public GitHub repositories.
  • •The oldest credential exposed dates back to 2009, with a median exposure time of 784 days.
  • •Push Protection has not effectively prevented the exposure of many credential types.

Truffle Security reported that over 543,000 valid credentials were found in public GitHub repositories, still active as of July 2026. The analysis covered 224 million repositories and 58 billion files, revealing that the median credential had been publicly accessible for 784 days, with the oldest dating back to 2009. Despite GitHub's Push Protection feature aimed at preventing accidental leaks, 36.8% of the exposed credentials were uploaded after this feature was enabled by default in February 2024. The study highlighted that 51.8% of the active credentials fell into categories not recognized by Push Protection. Truffle's findings indicate a significant increase in credential exposure, with the number of working credentials more than doubling since a previous scan in August 2025. The report emphasizes the need for immediate action to rotate exposed credentials and clean up repositories.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2025-08-07
Crawl of GitHub repositories closed
Truffle Security's dataset for analysis was finalized, covering 224 million repositories.
Truffle Security
2026-07-27
Credential testing conducted
Truffle Security tested the credentials found in the repositories, confirming 543,699 were still valid.
Truffle Security
2026-09-30
Research findings published
Truffle Security published their findings on the exposure of credentials in GitHub repositories.
BleepingComputer

More articles in this cluster (2)

Common questions

What types of credentials were exposed?
The exposed credentials included API keys, access tokens, and database connection strings.
How long were the credentials publicly accessible?
The median time for credentials to remain publicly accessible was 784 days, with some dating back to 2009.
What should developers do about exposed credentials?
Developers should rotate any exposed credentials immediately and clean up their repositories to remove sensitive information.