During 2023, 12.8 million authentication credentials and other sensitive data were accidentally exposed across three million public GitHub.

GitGuardian researchers sent over 1.8 million email notifications to those who accidentally exposed these secrets. However, only 1.8% of those notified of these leaks took immediate action to remove the exposed data.
The exposed data on GitHub includes account passwords, API keys, TLS/SSL certificates, encryption keys, cloud service credentials, OAuth tokens, and other sensitive data that a malicious user could use to gain full access to accounts and services.
Exposing this sensitive data can also lead to financial losses. Attackers can use the data to commit fraud, such as identity theft or credit card fraud.
Additionally, exposing sensitive data can have legal implications. If users have exposed third-party data, they may face legal penalties.
See also: ChatGPT: Thousands of credentials for sale on the dark web
A Sophos report for 2023 highlighted that compromised credentials were the root cause (in 50% of cases) for all attacks recorded in the first half of the year.
According to GitGuardian, the countries that had the most data leaks on GitHub in 2023 were India, the United States, Brazil, China, France, Canada, Vietnam, Indonesia, South Korea, and Germany.
See also: Roblox: 34 million credentials have been found on the dark web since 2021
When it comes to the sectors most affected by these leaks, IT tops the list. It is followed by education, and then several other sectors, such as science, retail, construction, finance, public administration, healthcare, entertainment, and transportation.

GitGuardian's detectors caught about 45% of all exposed secrets on GitHub that the company detected in 2023 and concluded that they mainly contained Google API and Google Cloud keys, MongoDB credentials, OpenWeatherMap and Telegram bot tokens, MySQL and PostgreSQL credentials, and GitHub OAuth keys.
See also: GitHub: Secret Scanning Push Protection now available by default
2.6% of exposed secrets are revoked within the first hour, but a whopping 91.6% remain valid even after five days, according to GitGuardian.
Generative AI tools continued their explosive growth in 2023, also reflected in the number of related secrets exposed on GitHub last year (e.g. OpenAI API keys). Other AI services, such as Cohere, Claude, Clarifai, Google Bard, Pinecone, and Replicate, were also affected, but to a lesser extent.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: www.bleepingcomputer.com
