databreaches.net 3 Oct 2026, 13:40 UTC

Over 543,000 Credentials Lingered in Public GitHub Repositories

CyberSIXT Evidence Panel Source marked as original reporting

MORE than 543,000 valid credentials were exposed in public GitHub repositories, according to research cited by Dissent and Bill Toulas. The study, conducted by Truffle Security, analysed data pulled from scanning 224 million repositories and more than 58 billion files. It found that despite GitHub’s security measures intended to prevent inadvertent leaks, a substantial number of credentials remained publicly accessible for long periods. The median time a unique credential stayed exposed was 784 days, highlighting how long such data can linger even on a platform designed to curb exposure.

The findings indicate that the exposed credentials are widely distributed, appearing across more than 1.1 million files and repositories, including copies in forks. Of the credentials identified, about 10% were older than 6.3 years, with the oldest dating back to 2009. The report emphasises the potential risk posed by long-lived credentials that may be reused in various environments, alongside the challenge of fully eliminating exposures that persist across large code ecosystems.

The article cites BleepingComputer for fuller detail on the investigation, and presents the figures as evidence of ongoing leakage despite platform safeguards. Practically, the report underscores the importance of credential hygiene and repository scanning, though the article itself does not prescribe specific mitigations.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline