The Home Depot
Disclosed Dec 12, 20259 months agoUnverified
Leaked GitHub token exposed Home Depot internal systems for a year
A researcher found a Home Depot employee's GitHub access token published online since early 2024 that granted access to hundreds of private source code repositories and cloud systems; it was revoked after TechCrunch contacted the company.
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Dec 12, 2025 |
| Attack | Exposed data |
| Data exposed | Source code, API keys |
| Sector | Retail · US |
| Status | Unverified: not yet confirmed by an official notice, a filing or the organization |
Sources
| Source | |
|---|---|
| Home Depot exposed access to internal systems for a year, says researchertechcrunch.com · News | News |
Notices filed
| Where | Filed | People |
|---|---|---|
| Researchtotal | Dec 12, 2025 |
Other breaches at The Home Depot
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Custom malware at Home Depot registers exposes 56 million payment cardsSep 2, 201412 years agoHacking | Sep 2, 201412 years ago | Hacking | Retail | Settled | 56M |
History of this record
- 2026-09-25 · added · seed source
First seen 2026-09-25 (Research). Record counts are as reported. Not legal advice.