64% of Leaked Credentials From 2022 Still Valid in 2026, Report Finds
A report by GitGuardian's State of Secrets Sprawl 2026 highlights a growing problem of credential exposure persisting across security tools and environments. A single API key can travel from a developer's laptop to code repositories, pipeline logs, support tickets, and teammate configs, creating multiple copies with identical access privileges. Security tools such as repo scanners, endpoint agents, and vaults each guard their own territory but no single tool tracks a credential across all the environments it touches. The report found that 28% of secrets incidents occur entirely outside code repositories, in collaboration and productivity platforms where scanners never look. Most alarmingly, over 64% of credentials found exposed in public repositories in 2022 were still active when retested in January 2026.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in