Keys Leak Faster Than You Think
Protect .env files, API keys, GitHub tokens, SSH keys, cloud credentials and debug logs.
Illustrative scenario
How It Looks in Real Life
A developer commits a .env file to a public repo, notices, and deletes it in the next commit. The cloud key remains in history and is used within hours.
Understand it
How the Attack Works
Automated scanners search public code, logs and paste sites for credentials. Deleting a file does not remove it from history or from copies already taken.
Red flags
Warning Signs
- .env files or credential files not covered by .gitignore.
- Tokens printed in debug logs, screenshots or support tickets.
- Long-lived tokens with broad permissions.
Safer habits
What to Do Instead
- 1Keep secrets in a secret manager or CI secret store, never in code.
- 2Enable secret scanning and push protection on repositories.
- 3Use short-lived, least-privilege tokens and rotate them regularly.
Response playbook
Already Interacted?
For work accounts and devices, report promptly through your organisation’s IT or security process first. Never share passwords, codes or tokens in a report.
If you: exposed a token, key or secret
- 1Revoke or rotate the exposed secret at the provider first; deleting the commit or message is not enough.
- 2Report it to the security team with where and when it was exposed. Never paste the secret itself into the report.
- 3Review provider logs for use of the key after the exposure time.
Knowledge Check
What Would You Do?
You pushed an API key to a public repo ten minutes ago. What comes first?
Fictional example for learning. Not a test score or certification.
Sources
Content reviewed by WazuGuardix on 5 October 2026. Summaries are in our own words.
Make Safe Habits Part of Your Culture
Plain-language awareness sessions for everyday staff, developers and business teams.