Avatier

Service-account or non-human identity abuse

Secrets sprawl

Also called: API key leak

Secrets sprawl is the spread of passwords, API keys, tokens and private keys into places they should not live, such as source code, public repositories, chat messages, tickets and config files. Each copy is another chance for an attacker to find a working credential, and copies are hard to track.

How it works

Developers hard-code a key to make something work, commit it, then copy the project or paste the key into a ticket. Attackers scan public code-sharing sites and stolen repositories for strings that look like keys, then test them against cloud and SaaS services. A single leaked key can reach whatever its service account can.

A real example

In an April 2018 announcement of a revised complaint, the FTC alleged that Uber learned in November 2016 that intruders had accessed consumer data on a third-party cloud provider's servers using an access key an Uber engineer had posted on a code-sharing website.

Source: Uber Agrees to Expanded Settlement with FTC Related to Privacy, Security Claims — Federal Trade Commission (FTC), 2018-04-12

How to stop it

Keep secrets in a managed vault, scan code and repositories for leaked keys before and after commit, and revoke and rotate any secret that has been exposed.

Related terms

Sources

  1. Uber Agrees to Expanded Settlement with FTC Related to Privacy, Security Claims — Federal Trade Commission (FTC), 2018-04-12

Last reviewed Oct 2, 2026