according to new research from cloud security firm Wiz. Wiz found confirmed leaks at 65% of companies on the Forbes AI 50 list, representing a combined valuation of more than $400 billion.
See also: New attack allows Git Credentials to be exported to ArgoCD

Despite the severity of the issue, nearly half of Wiz’s outreach efforts either failed to reach the affected companies or received no response, suggesting limited preparedness to address security reports. The leaks included credentials that could expose private AI models, training data, and internal organizational details, suggesting how the pressures for speed to market continue to outweigh secure development practices in the AI sector.
“Think API keys, tokens, and sensitive credentials, often buried deep in deleted forks, gists, and developer repositories that most scanners never touch,” Wiz wrote in a blog post. “Some of these leaks could have exposed organizational structures, training data, or even private models.” Some of the leaked credentials belonged to large AI platforms like Hugging Face, Weights & Biases , and LangChain, which could have granted access to private models or sensitive training datasets, according to Wiz.
Analysts have said that cloud storage misconfiguration has been a recurring problem for more than a decade, citing past incidents like the AWS S3 leaks. But while the pattern is familiar, the potential damage has increased as the exposed assets now include AI models, training data, and complex pipelines.
See also: Kimsuky exploits GitHub to distribute malware

The scale of the report points to “a glaring DevSecOps gap” between AI startups and more mature SaaS or cloud companies, according to Chandrasekhar Bilugu, CTO of SureShield. “In AI, where training data is a valuable commodity, a single leaked token provides access to thousands of private models with subsequent intellectual property theft or model poisoning.”
The findings suggest that as AI adoption accelerates, developers and CISOs should strengthen oversight of development pipelines and secret storage practices. Wiz’s findings highlight how exposed API keys can escalate into full-scale breaches across entire AI ecosystems, according to Sakshi Grover, senior research director for Cybersecurity Services at IDC Asia Pacific.
“Stolen credentials can be used to manipulate model behavior or extract training data, undermining trust in deployed systems.” Grover noted that such exposures are often tied to how AI development environments operate. “AI projects often operate in loosely governed, experimental environments where notebooks, pretrained models, and repositories are frequently shared, leaving secrets unscanned or refreshed,” Grover added.
See also: PureHVNC RAT leverages GitHub for source code hosting

She pointed to data from IDC’s Asia Pacific Security Study, which showed that 50% of enterprises in APAC plan to invest in API security when selecting CNAPP vendors, reflecting how exposed APIs have become a significant attack vector. With regulators increasing their focus on AI security and data protection, secrets management and API governance are likely to become auditable elements of emerging AI compliance frameworks, Grover said.
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
