Skip to content

Breaches that exposed api keys

39 breaches, most recently disclosed first. The list grows as new ones are disclosed.

OrganizationAffected
Hugging FaceAutonomous OpenAI agent breached Hugging Face and stole internal datasets and credentialsJul 172 months agoAI or modelUnknown
AccentureAccenture confirms breach after hacker sells 35 GB of source code and keysJul 72 months agoHackingUnverifiedUnknown
KlueKlue legacy credential breach leads to OAuth token theft and Salesforce raidsJun 193 months agoSupply chainUnknown
JetBrains15 malicious AI assistant plugins stole developers' AI API keysJun 163 months agoSupply chainUnverifiedUnknown
GitHubGitHub says 3,800 internal repositories stolen via poisoned Nx Console extensionMay 204 months agoSupply chainUnknown
BraintrustAI evaluation startup's AWS account breach exposed stored customer AI API keysMay 44 months agoHackingUnknown
SAPOfficial SAP npm packages trojanized to steal developer credentialsApr 294 months agoSupply chainUnverifiedUnknown
CheckmarxCheckmarx confirms LAPSUS$ leak of GitHub data after Trivy-linked compromiseApr 265 months agoSupply chainUnknown
BitwardenBitwarden CLI npm release trojanized to steal developer credentialsApr 235 months agoSupply chainUnverifiedUnknown
VercelBreach at AI app maker Context AI led to theft of Vercel customer credentialsApr 195 months agoSupply chainUnknown
CiscoCisco source code reportedly stolen using Trivy supply-chain credentialsMar 315 months agoSupply chainUnverifiedUnknown
LiteLLMMalware slipped into popular LiteLLM AI gateway package stole developer credentialsMar 246 months agoSupply chainUnverifiedUnknown
Aqua SecurityTrivy scanner releases and GitHub Actions hijacked to push credential stealerMar 216 months agoSupply chainUnverifiedUnknown
LexisNexis Legal & ProfessionalLexisNexis confirms breach via React2Shell flaw as FulcrumSec leaks filesMar 36 months agoHackingUnverifiedUnknown
OpenClawMore than 135,000 OpenClaw AI agent instances found exposed to the internetFeb 97 months agoExposed dataUnverifiedUnknown
ClawHubOver 230 malicious OpenClaw skills pushed info-stealing malware to AI agent usersFeb 27 months agoSupply chainUnverifiedUnknown
MoltbookVibe-coded AI agent social network exposed 1.5M API tokens and 35,000 emailsFeb 27 months agoExposed dataUnverifiedUnknown
The Home DepotLeaked GitHub token exposed Home Depot internal systems for a yearDec 12, 20259 months agoExposed dataUnverifiedUnknown
Tata MotorsExposed AWS keys in Tata Motors portal left customer data openOct 28, 202511 months agoExposed dataUnverifiedUnknown
Smithery.aiPath traversal in MCP hosting registry exposed admin token to 3,000+ hosted AI serversOct 22, 202511 months agoExposed dataUnverifiedUnknown
CloudflareCloudflare Salesforce data stolen via Salesloft Drift OAuth tokensSep 2, 20251 year agoSupply chainUnknown
Nxs1ngularity: malicious Nx npm releases used AI CLIs to hunt and leak developer secretsAug 26, 20251 year agoSupply chainUnknown
SalesloftStolen Drift AI chatbot OAuth tokens used to raid customer Salesforce instancesAug 26, 20251 year agoSupply chainUnverifiedUnknown
xAIxAI employee leaked API key on GitHub giving access to private Grok modelsMay 1, 20251 year agoExposed dataUnverifiedUnknown
Common CrawlNearly 12,000 live API keys and passwords found in AI training datasetFeb 28, 20251 year agoExposed dataUnverifiedUnknown
MicrosoftStorm-2139 used stolen customer credentials to hijack Azure OpenAI accountsFeb 26, 20251 year agoCredential stuffingUnknown
OmniGPTHacker leaked 34M lines of OmniGPT AI chat logs and 30,000 user contactsFeb 12, 20251 year agoHackingUnverifiedUnknown
DeepSeekUnauthenticated ClickHouse database exposed chat history and API secretsJan 29, 20251 year agoExposed dataUnverifiedUnknown
OpenAIArtists leaked early access to OpenAI's Sora video model on Hugging FaceNov 26, 20241 year agoInsiderUnverifiedUnknown
SAPSAPwned: SAP AI Core flaws gave researchers access to customer cloud keys and AI artifactsJul 17, 20242 years agoExposed dataUnverifiedUnknown
RabbitHardcoded API keys in Rabbit R1 code exposed users' AI assistant responsesJun 26, 20242 years agoExposed dataUnverifiedUnknown
Hugging FaceUnauthorized access to Spaces platform exposed a subset of user secretsMay 31, 20242 years agoHackingUnknown
Dropbox SignThreat actor accesses Dropbox Sign production environment and all user dataMay 1, 20242 years agoHackingUnknown
SisenseSisense compromise prompts CISA to urge customers to reset credentialsApr 11, 20242 years agoHackingUnverifiedUnknown
BMWMisconfigured BMW Azure storage bucket exposes private keys and internal dataFeb 14, 20242 years agoExposed dataUnverifiedUnknown
Mercedes-BenzExposed GitHub token gave unrestricted access to Mercedes-Benz source codeJan 26, 20242 years agoExposed dataUnverifiedUnknown
Hugging Face1,681 exposed Hugging Face API tokens gave write access to Meta Llama and other reposDec 4, 20232 years agoExposed dataUnverifiedUnknown
JumpCloudNorth Korean hackers breach JumpCloud to target its cryptocurrency customersJul 12, 20233 years agoHackingUnknown
DropboxPhishing attack lets hacker steal 130 Dropbox GitHub repositoriesNov 1, 20223 years agoPhishingUnverifiedUnknown

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.