Researchers uncover leaked API keys on nearly 10,000 websites

Researchers analyzing 10 million web pages have identified 1,748 active API credentials from 14 major providers exposed across nearly 10,000 websites, including those run by banks and healthcare providers. These leaks could enable attackers to access sensitive data or gain control over digital infrastructure. Nurullah Demir of Stanford University described the issue as very significant, affecting even major companies.

A team led by Nurullah Demir at Stanford University in California scanned 10 million web pages and found 1,748 verified, active API credentials from services such as Amazon Web Services, Stripe, GitHub, and OpenAI. These were scattered across nearly 10,000 websites, with affected organizations including a global systematically important financial institution, a firmware developer, and a major hosting platform, alongside banks and healthcare providers. The exposed credentials, such as those potentially revealing RSA private keys, could allow attackers to impersonate servers, decrypt communications, or seize administrative control of company infrastructure. 84% of the leaks appeared in JavaScript environments, likely due to bundler tools used by developers, while 16% came from third-party resources like plugins. The credentials had been publicly accessible for an average of 12 months, with some online for up to five years. Researchers notified the affected companies, and about 50% removed the keys within two weeks, though some did not respond. Katie Paxton-Fear at Manchester Metropolitan University noted that many developers did not intend to be insecure, attributing exposures to programming quirks in development pipelines. Nick Nikiforakis at Stony Brook University highlighted that leaked API keys enable attackers to act as authorized users, posing risks in modern software development. Demir emphasized shared responsibility: developers must configure environments properly, tool creators should hide keys by default, and hosts should scan and deactivate leaks promptly. The findings are detailed in a paper on arXiv (DOI: 10.48550/arXiv.2603.12498).

Mga Kaugnay na Artikulo

A TechRadar report states that over 29 million secrets were leaked on GitHub in 2025. The article suggests that AI is not helping and may be making the situation worse.

Iniulat ng AI

Security specialists have raised alarms over the vulnerability of online accounts, stating that almost half of all passwords in use today can be broken within minutes.

Microsoft has alerted users that hackers are targeting password reset processes to breach accounts. The activity is attributed to the group Storm-2949.

Iniulat ng AI

Daniel Stenberg, creator of the widely used curl program, draws parallels between his project and a cyberattack that nearly succeeded two years ago. In an interview in Huddinge, he stresses the importance of trust in open-source software underpinning the internet. An expert warns he could theoretically shut down half the internet.

Gumagamit ng cookies ang website na ito

Gumagamit kami ng cookies para sa analytics upang mapabuti ang aming site. Basahin ang aming patakaran sa privacy para sa higit pang impormasyon.
Tanggihan