• News/
  • https://www.bleepingcomputer.com/news/security/over-12-million-auth-secrets-and-keys-leaked-on-github-in-2023/

Over 12 million auth secrets and keys leaked on GitHub in 2023

BleepingComputer
·
Bill Toulas
·
Published Mar 12, 2024
·
Updated

GitHub users accidentally exposed 12.8 million authentication and sensitive secrets in over 3 million public repositories during 2023, with the vast majority remaining valid after five days. This is according to cybersecurity experts at GitGuardian, who sent out 1.8 million complimentary email alerts to those who exposed secrets, seeing only a tiny 1.8% of those contacted taking quick action to correct the error. The exposed secrets include account passwords, API keys, TLS/SSL certificates, encryption keys, cloud service credentials, OAuth tokens, and other sensitive data that could give external actors unlimited access to various private resources and services, leading to data breaches and financial damage. A 2023 Sophos report highlighted that compromised credentials accounted for 50% of the root cause for all attacks recorded in the first half of the year, followed by vulnerability exploitation, which was the attack method in 23% of the cases. GitGuardian says the secret exposure on GitHub, the world's most popular code hosting and collaboration platform, has followed a negative trend since 2020. The "leakiest" countries for 2023 were India, the United States, Brazil, China, France, Canada, Vietnam, Indonesia, South Korea, and Germany. In terms of which sectors leaked the most secrets, IT tops the list with the lion's share of 65.9%, followed by education with a notable 20.1%, and all others combined (science, retail, manufacturing, finance, public administration, healthc...

Read full article

Affected Software

4 affected components
Google API and Google Cloud keys
OpenWeatherMap bot tokens
Telegram bot tokens
OpenAI API keys

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the accidental exposure of over 12 million authentication secrets and keys on GitHub in 2023.

2

What security implications are discussed?

The article highlights the risks associated with exposed authentication secrets, including potential unauthorized access to sensitive data and services.

3

What products or software are affected?

Affected products include Google API and Google Cloud keys, OpenWeatherMap bot tokens, Telegram bot tokens, and OpenAI API keys.

4

How many repositories were involved in the leak?

The leak involved over 3 million public repositories on GitHub.

5

What percentage of the exposed keys remained valid after a week?

The majority of the exposed authentication keys remained valid after five days.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203