MongoDB, GitHub and Google: Over 543,000 Live Credentials Found Exposed Across Public GitHub Repositories

MongoDB, GitHub and Google: Over 543,000 Live Credentials Found Exposed Across Public GitHub Repositories

Over Half a Million Exposed Credentials Remain Active on GitHub, Highlighting Persistent Security Gaps

In July 2026, researchers from Truffle Security identified 543,699 unique, still-valid credentials exposed in public GitHub repositories, revealing a critical disconnect between detecting leaked secrets and revoking them. The findings, based on an analysis of The Stack v3 a dataset containing 58.4 billion files from 224.5 million repositories collected up to August 7, 2025 showed that many credentials had remained publicly accessible for years, with some active for over 16 years.

The study found 1,103,438 separate exposures of these credentials, including duplicates across forks. The median exposure time was 784 days, while 10% of credentials had been leaked for at least 6.3 years. The oldest verified credential, linked to a file last modified in June 2009, was still operational in 2026.

Despite GitHub’s efforts to mitigate leaks such as free secret scanning alerts (February 2023) and default push protection (February 2024) 36.8% of the exposed credentials (199,843) were leaked after push protection was enabled. The issue was partly due to coverage limitations: 51.8% of live credentials belonged to categories not blocked by default, including database connection strings, private keys, and Google API keys.

Notable findings included:

  • 69,041 live Google Cloud service account credentials
  • 51,067 MongoDB connection strings
  • 33,343 Google API keys (31,374 of which were Gemini API keys)

GitHub does not enforce push protection for Google API keys by default due to false-positive risks, as the same key format can be used for both sensitive and public-facing services.

While push protection reduced new leaks by 53% for protected credential types, it did not address previously committed secrets. The effectiveness of automated revocation varied significantly:

  • npm tokens had a 0.001% survival rate
  • GitHub tokens had a 0.36% survival rate
  • Postgres (88%) and MySQL (75%) connection strings remained largely active due to the lack of provider-side revocation mechanisms.

The report underscores that secret scanning alone is insufficient organizations must treat all exposed credentials as compromised, rotate them immediately, and adopt short-lived credentials to mitigate risks.

Source: https://cyberpress.org/over-543000-live-credentials/

Google cybersecurity rating report: https://www.rankiteo.com/company/google

MongoDB cybersecurity rating report: https://www.rankiteo.com/company/mongodbinc

GitHub cybersecurity rating report: https://www.rankiteo.com/company/github

"id": "GOOMONGIT1790850492",
"linkid": "google, mongodbinc, github",
"type": "Breach",
"date": "8/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Organizations and individuals '
                                              'with exposed credentials',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'GitHub',
                        'size': 'Large',
                        'type': 'Platform'},
                       {'customers_affected': '69,041 accounts with exposed '
                                              'credentials',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'Google Cloud',
                        'size': 'Large',
                        'type': 'Cloud Service Provider'},
                       {'customers_affected': '51,067 accounts with exposed '
                                              'connection strings',
                        'industry': 'Technology',
                        'location': 'Global',
                        'name': 'MongoDB',
                        'size': 'Large',
                        'type': 'Database Service Provider'}],
 'attack_vector': 'Publicly accessible repositories',
 'data_breach': {'file_types_exposed': 'Configuration files, source code',
                 'number_of_records_exposed': '543,699 unique credentials, '
                                              '1,103,438 exposures',
                 'sensitivity_of_data': 'High (service account credentials, '
                                        'database access, API keys)',
                 'type_of_data_compromised': 'Credentials, API keys, database '
                                             'connection strings'},
 'date_detected': '2026-07',
 'date_publicly_disclosed': '2026-07',
 'description': 'In July 2026, researchers from Truffle Security identified '
                '543,699 unique, still-valid credentials exposed in public '
                'GitHub repositories, revealing a critical disconnect between '
                'detecting leaked secrets and revoking them. The findings were '
                'based on an analysis of The Stack v3, a dataset containing '
                '58.4 billion files from 224.5 million repositories collected '
                'up to August 7, 2025. Many credentials had remained publicly '
                'accessible for years, with some active for over 16 years. The '
                'study found 1,103,438 separate exposures of these '
                'credentials, including duplicates across forks. The median '
                'exposure time was 784 days, while 10% of credentials had been '
                'leaked for at least 6.3 years. The oldest verified '
                'credential, linked to a file last modified in June 2009, was '
                'still operational in 2026.',
 'impact': {'brand_reputation_impact': 'Negative impact on GitHub and affected '
                                       "organizations' reputations",
            'data_compromised': '543,699 unique credentials',
            'identity_theft_risk': 'High',
            'operational_impact': 'Potential unauthorized access to systems '
                                  'and data',
            'systems_affected': 'Public GitHub repositories, cloud services, '
                                'databases'},
 'investigation_status': 'Completed (research findings published)',
 'lessons_learned': 'Secret scanning alone is insufficient; organizations must '
                    'treat all exposed credentials as compromised, rotate them '
                    'immediately, and adopt short-lived credentials to '
                    'mitigate risks.',
 'post_incident_analysis': {'corrective_actions': ['Expand push protection to '
                                                   'cover more credential '
                                                   'types',
                                                   'Improve automated '
                                                   'revocation processes',
                                                   'Encourage adoption of '
                                                   'short-lived credentials'],
                            'root_causes': ['Persistent exposure of '
                                            'credentials in public '
                                            'repositories',
                                            "Limited coverage of GitHub's push "
                                            'protection for certain credential '
                                            'types',
                                            'Lack of automated revocation '
                                            'mechanisms for database '
                                            'connection strings and private '
                                            'keys']},
 'recommendations': ['Rotate all exposed credentials immediately',
                     'Adopt short-lived credentials',
                     'Enhance push protection coverage for all credential '
                     'types',
                     'Improve automated revocation mechanisms for database '
                     'connection strings and private keys'],
 'references': [{'date_accessed': '2026-07',
                 'source': 'Truffle Security Report'},
                {'date_accessed': '2026-07', 'source': 'The Stack v3 Dataset'}],
 'response': {'containment_measures': "GitHub's secret scanning alerts and "
                                      'push protection',
              'remediation_measures': 'Credential rotation, adoption of '
                                      'short-lived credentials',
              'third_party_assistance': 'Truffle Security (researchers)'},
 'title': 'Over Half a Million Exposed Credentials Remain Active on GitHub, '
          'Highlighting Persistent Security Gaps',
 'type': 'Data Exposure',
 'vulnerability_exploited': 'Exposed credentials in public GitHub repositories'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.