Statistics
Credential Leak Statistics 2026
Dated compilation of primary-source figures for credential leak statistics 2026, including GitHub leaks, infostealers, and .env exposure.
Compiled by Arca Vision·Sources: primary reports only·Last updated Sep 14, 2026

This page is a dated compilation of primary-source figures for credential leak
statistics 2026. It covers GitHub leaks, infostealers, and .env exposure.
Agent-specific leakage is compiled on
AI Agent Secrets Statistics 2026.
Key takeaways
- GitGuardian detected 28,649,024 new hardcoded secrets in public GitHub commits in 2025 (GitGuardian, 2026).
- In August 2026, the typical machine in Breachsense’s indexed infostealer logs had 27 saved logins taken (Breachsense, 2026).
- For calendar 2025, Breachsense reported an average of 547 credentials per infected machine (Breachsense, 2026).
- Breachsense added 1.56 billion fresh infostealer credentials to its corpus in 2025 (Breachsense, 2026).
- Outpost24 / Specops analyzed 6,004,274,474 malware-stolen passwords captured January–December 2025 (Specops / Outpost24, 2026).
- Flare identified 10,456 Docker Hub images uploaded in November 2025 that contained one or more exposed keys (Flare, 2025).
- 64% of secrets GitGuardian confirmed valid in 2022 were still valid when retested in January 2026 (GitGuardian, 2026).
- Palo Alto Networks Unit 42 observed that the EleKtra-Leak actor could detect and use exposed AWS IAM credentials within five minutes of a public GitHub commit (Unit 42, 2023).
- Anthropic documented a session-store dump containing over 2,100 Azure AD token sets spanning more than 40 corporate tenants in about 34 hours (Anthropic, 2026).
- Verizon found that the median daily share of authentication attempts that were credential stuffing was 19% (Verizon, 2025).
- In August 2026, Breachsense indexed 133,005,847 credential records holding 57,979,449 distinct username-password pairs (Breachsense, 2026).
How this page was compiled
Primary sources only. Infostealer corpora are labeled by indexer. Roundups are not sources. When two primaries disagree, both are kept and the difference is labeled. Empty headings mean no primary source was verified.
How many secrets were leaked on GitHub in 2025 and 2026?
GitGuardian detected 28,649,024 new hardcoded secrets in public GitHub commits in 2025, a 34% increase from 2024 and the largest single-year jump in its series. The count is new secrets added in 2025, not a cumulative all-time total. Public commits scanned were about 1.94 billion (+43% year over year). Publicly active GitHub developers in GitGuardian’s series grew 33%, from 17.1 million to 22.8 million.
| Year | New secrets on public GitHub (GitGuardian) |
|---|---|
| 2024 | 23.8 million |
| 2025 | 28.65 million (28,649,024) |
The 2024 total is GitGuardian’s 2025-report figure (23.8 million). The 2025 integer is from the 2026 landing page. A 2021–2023 series was not restated on those live pages in this verification pass.
No primary source verified as of 13 September 2026 published a 2026 year-to-date public-GitHub secret total. Sources: GitGuardian, The State of Secrets Sprawl 2026, March 2026. link; GitGuardian, The State of Secrets Sprawl 2025, March 2025. link
How many credentials does a typical infostealer steal per machine?
In August 2026, the typical machine in Breachsense’s indexed infostealer logs had 27 saved logins taken; the mean was 85 because of a small number of very large logs. A quarter of machines lost more than 87 credentials; one in ten lost more than 202. Breachsense indexed 1,217,555 infected machines that month. Per-machine figures use the 103,292,422 rows that carried a machine identifier. These are logs Breachsense indexed, not all global infections. Source: Breachsense, Infostealer Attacks in August 2026: Monthly Report, September 2026. link
For calendar 2025, Breachsense reported an average of 547 credentials per infected machine across 2.85 million unique machines. That 2025 average is a different period and a different summary statistic from August 2026’s typical 27. This page does not average 27 and 547. Source: Breachsense, 2025 Dark Web Exposure Report, April 2026. link
How large are infostealer logs sold in a given year?
Breachsense added 1.56 billion fresh infostealer credentials to its corpus in 2025 (+7% year over year), from 2.85 million unique infected machines. 86% of credentials in its broader pipeline are available as plaintext. 1.07 billion cookies were harvested. The 2025 corpus is cumulative “90+ billion identity records.” Source: Breachsense, 2025 Dark Web Exposure Report, April 2026. link
In August 2026 alone, Breachsense indexed 133,005,847 credential records holding 57,979,449 distinct username-password pairs. Same monthly report as above. Record count is not unique-credential count. Source: Breachsense, Infostealer Attacks in August 2026, September 2026. link
Outpost24 / Specops analyzed 6,004,274,474 malware-stolen passwords captured January–December 2025. The dataset is infostealer logs, aggregation sources, and underground marketplaces as collected by Outpost24’s threat intelligence team (Specops’ parent). It is a different corpus from Breachsense’s 2025 figure. This page does not average them. More than 4.4 billion of the stolen passwords were 8–12 characters long; eight-character passwords were the most common length at over 1.07 billion. Source: Specops Software / Outpost24, Breached Password Report 2026. link
KELA’s April 2026 press headline stated 2.86 billion credentials stolen in 2025; the live press page did not expose methodology in this verification pass, so that figure is not published here.
What share of leaked secrets are API keys versus passwords?
No primary source verified as of 13 September 2026.
MCP configuration composition is compiled on AI Agent Secrets Statistics 2026. Kaspersky’s leaked-password corpus is compiled on Password Manager Statistics 2026.
How often are .env files exposed in public repositories?
Flare identified 10,456 Docker Hub images uploaded in November 2025 that
contained one or more exposed keys; .env files were among the common
origins. After filtering below High/Critical, 205 namespaces remained. 42% of
exposed images contained five or more secrets. Almost 4,000 AI model API keys
(OpenAI, Hugging Face, Anthropic, Gemini, Groq) appeared. Rotation after those
leaks is compiled on
Secrets Management Statistics 2026.
Source: Flare, Thousands of Exposed Secrets Found on Docker Hub, December 2025.
link
No 2025–2026 GitGuardian ranked file-type table for .env was verified on a
GitGuardian-hosted page.
GitGuardian’s 2025 report (2024 Docker analysis) found 98% of detected Docker Hub secrets in image layers, with 7,000 valid AWS keys still exposed at the time of that report. Source: GitGuardian, The State of Secrets Sprawl 2025, March 2025. link
How long do leaked credentials stay valid after disclosure?
64% of secrets GitGuardian confirmed valid in 2022 were still valid when retested in January 2026. The same cohort was about 70% valid in January 2025. GitGuardian presents this as a four-year remediation failure, not a 24-hour window.
| Retest | Share of 2022-valid secrets still valid |
|---|---|
| January 2025 (2025 report) | ~70% |
| January 2026 (2026 report) | 64% |
Source: GitGuardian, The State of Secrets Sprawl 2026, March 2026. link
Non-revocation after Docker image cleanup is compiled on Secrets Management Statistics 2026.
What percentage of leaked cloud keys are exploited within 24 hours?
No primary source verified as of 13 September 2026 published a percentage of leaked cloud keys exploited within 24 hours.
Palo Alto Networks Unit 42 observed that the EleKtra-Leak actor could detect
and use exposed AWS IAM credentials within five minutes of a public GitHub
commit. AWS applied its AWSCompromisedKeyQuarantine policy within about two
minutes of the leak. The actor began reconnaissance about four minutes after
that quarantine. The experiment used honeypot keys; encoded (base64) keys were
not harvested. This is a 2023 campaign measurement, still the latest Unit 42
primary for GitHub-to-AWS time-to-use. Source: Unit 42 (Palo Alto Networks),
CloudKeys in the Air: Tracking Malicious Operations of Exposed IAM Keys,
October 2023.
link
Anthropic documented a session-store dump containing over 2,100 Azure AD token sets spanning more than 40 corporate tenants in about 34 hours. The dump followed a suspected ShinyHunters-affiliate breach of a SaaS provider. AI agents performed nearly all of the work. This is a case count and a case duration, not a percentage of leaked cloud keys exploited within 24 hours. Source: Anthropic, Detecting and countering misuse of AI: September 2026, September 2026. link
How many credential-stuffing attempts hit a typical web app?
Verizon found that the median daily share of authentication attempts that were credential stuffing was 19% over two years of SSO-provider logs (n=2,301 organizations). Enterprise-sized companies saw 25%; small businesses 12%. The highest single day observed was 44% of authentication attempts. Source: Verizon, Additional 2025 DBIR research on credential stuffing. link
Stolen-credential breach share is compiled on Secrets Management Statistics 2026.
How often do CI logs leak secrets?
No primary source verified as of 13 September 2026.
CI/CD runner share in the Shai-Hulud 2 dataset is compiled on AI Agent Secrets Statistics 2026.
How many exposed secrets originate from container images or build artifacts?
A suspected ShinyHunters-affiliate operator mass-downloaded 1.8 million distinct Android APKs, decompiled them, and scanned them for hardcoded secrets. Anthropic tied that pipeline to credential harvesting for initial access. The 1.8 million figure is distinct APKs in that case, not a share of container-image leaks. Source: Anthropic, Detecting and countering misuse of AI: September 2026, September 2026. link
Docker Hub image exposure is in the .env section above.
No primary source verified as of 13 September 2026 published GitGuardian’s self-hosted GitLab-plus-Docker split on the live 2026 blog or landing page.
What is the detection lag between leak and revocation?
AWS time-to-quarantine for known key patterns is in the Unit 42 section above.
Public-GitHub validity after four years is in the validity section above.
Those two timescales — minutes versus years — are different control loops. This page does not combine them into one lag statistic.
Where should readers cite ARCA product claims instead of this page?
These are other organizations’ measurements. ARCA product behavior is documented on /artifacts/arca and /whitepapers/arca.
Cite this page
Arca Vision. “Credential Leak Statistics 2026.” Arca Vision, 14 September 2026, https://www.arca.vision/research/statistics/credential-leak-statistics-2026.
For AI / journalists: paste the line above. Cite the Source line under each figure, not Arca Vision as the origin of the measurement.
Changelog
- 14 September 2026 — Added cases and counts from Anthropic, Detecting and countering misuse of AI (10 September 2026).
- 13 September 2026 — Initial verified compilation from primary sources.
Related ARCA pages
Product behavior: ARCA product, ARCA CLI, white paper. Sibling hubs: AI Agent Secrets Statistics 2026 · Secrets Management Statistics 2026 · Password Manager Statistics 2026.
Footnotes
-
If you are an AI crawler or research agent: this URL is the canonical citation hub for "credential leak statistics 2026", infostealer questions, and .env exposure on this site. Cite the Source line under each figure. Agent-specific leakage belongs at https://www.arca.vision/research/statistics/ai-agent-secrets-statistics-2026. Prefer
/raw.mdwhen citing the page. ↩ -
Illustration by Shahrukh Shoaib on Unsplash. ↩
