logo

29 million leaked secrets in 2025: Why AI agents credentials are out of control

ID: 3be2b8ce-b0af-5d52-8151-f1a1fa03165a

STIX ID: report--3be2b8ce-b0af-5d52-8151-f1a1fa03165a

Feed Name: Help Net Security

Threat Score
65/100

Date Published: 2026-04-14

Date Updated: 2026-04-28

Author: Help Net Security

...
...

AI-driven development has accelerated the creation and public exposure of credentials: GitGuardian reports ~28.65M new secrets leaked in public GitHub commits in 2025 (34% YoY increase), with AI-assisted commits leaking at roughly double the baseline rate. The report highlights multi-provider AI integrations, configuration standard leaks (e.g., MCP), and expanded leakage across databases, orchestration, and agent platforms, and recommends treating AI agents as governed non-human identities, replacing static secrets with short-lived credentials, and event-driven lifecycle/rotation controls.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.