132 documented incidents found — a lower bound, not a global census

Breaches involving API keys, tokens, service accounts, signing keys and other non-human identities, 2016–2026

Asked:
can you tell me how many breaches that involved secretes API keys and other non human identities happend in the last 10 years

This review recovered 132 distinct, named, publicly documented incidents between September 2016 and September 2026 in which a non-human identity or machine credential — an API key, OAuth token, service account, cloud or signing key, certificate, or other secret — was confirmed exposed, stolen or abused. It draws on 82 source pages across 15 hosts. No global registry tags breaches this way, so 132 is what documentation supports, not the true worldwide total.

incidents with multiple corroborating pages  single-page incidents  — years 2017–2019 marked “none found”: no qualifying event was recovered, which is not a confirmed global zero
Documented incidents rise steeply after 2022 — from 8 that year to 50 in 2026 — though the 2026 jump may partly reflect better reporting, search recency and broader NHI terminology, not incidence alone. astrix.security
Stolen tokens repeatedly turned one compromise into many: Codecov’s stolen git tokens reached 17,000 companies’ private repositories in 2021. astrix.security
A single unrotated token and service-account credentials let attackers breach Cloudflare’s entire Atlassian suite in 2023 — one of the best-corroborated incidents, with 11 independent pages. astrix.security
Exposed keys can sit unnoticed for years: Toyota’s access key was public on GitHub for five years, exposing data on more than 290,000 customers. blog.gitguardian.com

Evidence: all 132 incidents

YearIncidentCredentialConfirmed roleImpactPagesSource

Method: 132 named, publicly documented incidents (Sep 2016–Sep 2026) in which a source explicitly tied a non-human identity or machine credential to confirmed exposure, theft, abuse or access; generic risks, unexploited vulnerabilities and raw leak counts excluded. Evidence: 82 URLs across 15 hosts; the most-used URL supports 23 rows (17.4%). Counting is per normalized incident, not per key, victim or mention; dates are often year-level. Impact left blank where unresolved. Count is a documented lower bound.

This report was generated automatically by Keenable SELECT at a user's request, from publicly available web sources linked herein. Keenable does not review, verify, or endorse its contents and makes no representation as to accuracy, completeness, or timeliness; AI-based extraction may contain errors. Nothing in this report is investment, legal, financial, or other professional advice. All trademarks and referenced content remain the property of their respective owners; no affiliation or endorsement is implied. To report an error, rights concern, or request removal: legal@keenable.ai.

Keenable SELECTAsk your own question
Made with Keenable SELECT