Breaches involving API keys, tokens, service accounts, signing keys and other non-human identities, 2016–2026
can you tell me how many breaches that involved secretes API keys and other non human identities happend in the last 10 years
This review recovered 132 distinct, named, publicly documented incidents between September 2016 and September 2026 in which a non-human identity or machine credential — an API key, OAuth token, service account, cloud or signing key, certificate, or other secret — was confirmed exposed, stolen or abused. It draws on 82 source pages across 15 hosts. No global registry tags breaches this way, so 132 is what documentation supports, not the true worldwide total.
| Year | Incident | Credential | Confirmed role | Impact | Pages | Source |
|---|
Method: 132 named, publicly documented incidents (Sep 2016–Sep 2026) in which a source explicitly tied a non-human identity or machine credential to confirmed exposure, theft, abuse or access; generic risks, unexploited vulnerabilities and raw leak counts excluded. Evidence: 82 URLs across 15 hosts; the most-used URL supports 23 rows (17.4%). Counting is per normalized incident, not per key, victim or mention; dates are often year-level. Impact left blank where unresolved. Count is a documented lower bound.