The lack of credentials grows: 28.65 million secrets detected in 2025 and higher risk IA

Author: Published 5 min de lectura 5 reading

The images in this article were generated with artificial intelligence. How we publish

The security of credentials - keys, tokens and secrets that connect users, services and now IA agents - has become the most exposed failure point of most organizations. Specific data collected by suppliers and public reports show that leaks not only grow in number, but expand within the scope of the environment where these credentials reside: public and internal repositories, collaborative systems and development teams themselves. To understand the real risk it is essential to start by detection: without a reliable inventory of what credentials exist, where they are and what permits they grant, any mitigation attempt will be partial and late.

Relevant confirmed facts: GitGuardian reported 28.65 million new hardcodeated secrets detected in GitHub public commitments during 2025, an increase of 34% per year, and noted an 81% increase in filtered credentials related to IA services. This research also points to the fact that internal repositories are approximately six times more likely than the public to contain at least one secret, and that about 28% of secret incidents originate outside the control of the source code, in systems of collaboration and productivity. In addition, Verizon's 2026 report identifies that the committed credentials represented 22% of the initial access vector in the gaps studied. These sources draw a coherent image: the attack surface linked to credentials is extended by managed and unmanaged environments alike. For the above reports, see the analysis of GitGuardian and the Verizon DBIR: GitGuardian and Verizon DBIR.

The lack of credentials grows: 28.65 million secrets detected in 2025 and higher risk IA
Image generated with IA.

Technically, the problem has several layers. First, credentials appear in different places: within Git's history (not only in the latest version), in branches or forks, in tickets and chats, and on the developer's disk. Secondly, the validity of these credentials often lasts: revalidation tests show that confirmed credentials valid in 2022 were still active in 64 per cent of cases as of January 2026. Third, the arrival of IA agents integrated into development flows has created new bodies that can read files, run commands and connect services: these agents have authentication contexts that multiply exposure points. Finally, the new infostealers families (for example, public campaigns at the end of 2025 that affected endpoints) have made development teams a priority; an analysis of an incident showed 33,185 unique secrets on 6,943 machines engaged, with almost half of these machines containing more than 10 secrets, illustrating the density and value of local telemetry.

Who's it to? To any organization that produces software or consumes cloud services: development equipment, operations, security, and any "citizen developed" using automation tools or IA agents. It also impacts the supply chain: a filtered credential in a personal project, an internal repository or an endpoint can be the entry key to achieving productive environments or external suppliers. The problem is not theoretical: the average time the attackers achieve lateral movement and exploitation has been drastically reduced; studies of the cybersecurity ecosystem point out that criminal gaps can climb in a matter of minutes, making it impossible to rely only on slow human responses (see, for example, CrowdStrike analysis and others on eCrime rupture times).

Practical implications: a disclosed credential can allow direct access to critical infrastructure (cloud, repositories, databases), silent persistence through insufficient rotation, and lateral climbing within the network. In addition, automatic malware playback looking for secrets in endpoints turns any machine with access to multiple services into a risk multiplier. To complicate the picture, many organizations do not know what fraction of the inventory of credentials is linked to a owner, an expiry policy or a productive workload, making it difficult to prioritize remediations without interrupting critical systems.

The lack of credentials grows: 28.65 million secrets detected in 2025 and higher risk IA
Image generated with IA.

Specific and prioritized actions to be taken by the reader (organizations and technical officials): first, establish a continuous detection that combines repository scans (including histories), public monitoring of commitments and discovery in endpoints. This means integrating detection tools into CI / CD and EDR / MDM to reveal secrets that do not reach central control. Second, enrich each finding with context: check the validity of the secret, identify the owner of the use, map associated permissions and list units or workloads that use it, so that the response can be selective and secure. Third, prioritise the rotation or revocation of credentials based on validity and scope of permits, not only on how many times the secret appeared. Fourth, apply temporary and less privileged authentication mechanisms: move credentials to vaults with short-lived secrets, adopt limited-life roles and tokens, and enable MFA where to apply. Fifth, limit what IA agents and external integrations can read or execute: define minimum permissions for models and agents, segregate implementation environments and use contextual data control policies (e.g., restrict access to sensitive files from agents). Finally, implement post-exposure detection: automatic alerts to the abnormal use of keys and playbooks that revoke and replace credentials throughout the chain.

Limitations and points still uncertain: some published metrics come from scans in public repositories and from specific data sets; therefore, the total magnitude of the problem in private environments may vary and is likely to remain underestimated. The effectiveness of certain measures (e.g. blocking IA agents in certain contexts) depends on the architecture and how these agents are integrated. In addition, the rapid evolution of malware specialized in stealing secrets implies that defensive tactics should be continuously reviewed; there are no unique solutions, but a combination of inventory, control and automation that reduces the exposure window.

In summary: the first priority is to detect with full scope and rich context. Without that inventory, there is no reliable way to remedy and prevent. Detection should cover repositories (including historical ones), public space, and development endpoints; mediation should be guided by validity and permissions; and prevention should focus on ephemeral credentials, least privilege and stricter controls over development agents and environments. To deepen the nature and evolution of the problem, readers can review research reports from suppliers and sectoral analyses such as those of GitGuardian and Verizon DBIR: GitGuardian - State of Secrets Sprawl 2026 and Verizon DRIR 2026.

Coverage

Related

More news on the same subject.