The recent discovery of exposed credentials on popular code formatting sites shows how small mistakes can create serious security gaps. Publicly accessible JSON snippets stored on these platforms revealed keys and configuration data from banks, government agencies, and major tech firms. Researchers documented more than 80,000 pastes containing live secrets gathered over several years. Attackers have already attempted to use some of the leaked data, which confirms active exploitation attempts.
Relevant Source (watchTowr Labs): Stop Putting Your Passwords Into Random Websites (Yes, Seriously, You Are The Problem)
This research report from watchTowr Labs details how scraping JSONFormatter and CodeBeautify exposed over 80,000 saved JSON pastes with live credentials, keys, and configuration data from banks, governments, and tech companies, which is the exact incident summarized in this section.
Quick Facts
- Over 80,000 JSON pastes exposed across two online code tools
- Leaks include bank, government, healthcare, and tech sector credentials
- Secrets discovered: AD logins, API keys, private keys, SSH logs, PII
- Attackers attempted to use planted honeypot AWS keys
- URLs followed predictable patterns that made scraping simple
- Recent Links sections remain publicly accessible at the time of reporting
Hidden Data Risks
Accidental uploads on code formatting sites create a silent risk for companies in every industry. These tools store saved snippets under predictable URLs with no authentication layer, which allows anyone to view data uploaded by other users. Researchers found live production credentials, sensitive scripts, and personal data sitting in plain sight. The ease of access and the volume of exposed records amplify the risk for organizations that rely on these tools without understanding how their data is handled.
- Platforms stored saved snippets without access controls
- Secrets included private keys, database credentials, and cloud access tokens
- Some files came from banks, government bodies, and cybersecurity firms
The scale of the leak shows a pattern of developers using unsafe quick fixes when handling code. A simple copy and paste into a formatting tool can trigger a major breach if the tool stores the content publicly.
Relevant Source (GitGuardian): The State Of Secrets Sprawl 2025
This report analyzes tens of millions of exposed secrets in public and private code repositories, showing how developer mistakes and unchecked uploads leak API keys, database passwords, and cloud tokens at scale.
Relevant Source (TechRadar): Leading AI Companies Keep Leaking Their Own Information On GitHub
This article summarizes Wiz research that found 65% of top AI companies accidentally publishing credentials and sensitive configuration data on public GitHub, illustrating how routine developer workflows create hidden exposure.
Why Exposure Matters
Sensitive data in public code tools gives attackers a direct line into high-value systems. Scraping predictable URL patterns allows automated bots to harvest thousands of secrets with little work. Production AWS credentials, CI/CD tokens, and Docker repository logins can give attackers deep access to core infrastructure. Government scripts and configuration files can reveal internal architecture even without passwords present.
- Attackers can use exposed credentials to pivot through networks
- Cloud keys can compromise storage, compute, and automation systems
- PII leaks increase compliance liabilities across sectors
- Internal scripts help attackers map systems and identify weak points
- Secrets from third-party MSSPs create shared risk across clients
The long-term impact grows when organizations do not respond to disclosure emails. Failure to revoke keys or update configurations leaves the door open even after exposure becomes known.
Relevant Source (GitGuardian): How Cybercriminal Organizations Weaponize Exposed Secrets
This article explains how attackers turn leaked credentials, cloud keys, and tokens into full infrastructure compromise, including lateral movement through networks and customer environments.
Relevant Source (MITRE ATT&CK): Valid Accounts (T1078)
This MITRE ATT&CK technique page describes how adversaries use stolen or exposed credentials to gain persistent access, move laterally, and reach high-value systems across an organization.
What You Should Do Now
Companies and developers can reduce risk with a few direct steps. Start by disabling or restricting the use of online code beautifiers for any content that contains credentials or internal details. Audit internal code bases for saved tokens and rotate anything that might have been exposed. Train developers to avoid uploading configuration files, scripts, or logs to public web tools.
Steps to act now:
- Revoke and rotate any exposed keys
- Disable use of public code-formatting tools for sensitive content
- Add automated secrets scanning to CI pipelines
- Use internal or self-hosted formatting tools
- Enforce developer training on safe handling of configuration files
Closing these small gaps strengthens internal security practices and prevents repeated exposure.
Relevant Source (GitGuardian): What to do if you expose a secret: How to stay calm and respond to an incident
This article walks through concrete steps for responding to leaked secrets, including revoking and rotating credentials, assessing impact, and improving future handling practices.
Relevant Source (GitGuardian): How to Avoid Secrets Sprawl: Best practices
This guidance covers preventing and managing secrets sprawl with automated scanning, safer tooling choices, and developer education, which aligns directly with reducing reliance on public code tools and tightening internal workflows.
The Big Picture
The incident highlights a common pattern in security failures. Convenience tools tempt developers to take shortcuts when dealing with complex JSON files or configuration data. Without understanding how these sites store information, users assume their pastes remain private and temporary. In reality, the platforms create permanent, publicly accessible records unless removed manually.
Attackers do not need to break into systems when credentials are posted online. Automated scraping tools can harvest thousands of secrets in minutes. Large organizations that rely on managed service providers gain additional exposure when third-party teams leak client data through unsafe workflows. Each leak expands attack surfaces across several organizations, not just the uploader.
Relevant Source (Checkmarx): The Dangers of Exposed Secrets – and How to Prevent Them
This article explains how exposed credentials in public-facing tools and repositories enable automated harvesting, lateral movement, and long-lived attack paths across organizations.
Relevant Source (CISA): Protecting Against Cyber Threats to Managed Service Providers and Their Customers
This joint advisory details how compromises and poor security practices at MSPs and other third-party providers can propagate risk to many client environments at once, mirroring the shared exposure described in this section.
Final Thoughts
Data leaks caused by online code tools show how simple habits can undermine strong security systems. Treat every credential, configuration file, and script as sensitive even if it seems harmless. The safest approach is to keep formatting and debugging tools inside controlled environments and stop relying on public platforms for quick fixes.
Common Questions
Are code formatting sites safe for sensitive files?
No. Public formatting tools often store content and make it accessible through predictable URLs.
What kinds of data were exposed?
Researchers found API keys, private keys, cloud credentials, internal scripts, and personal data.
Were attackers actively using the leaked keys?
Yes. Honeypot credentials planted by researchers were tested by unknown actors.
Can companies remove their exposed data from these platforms?
Some platforms allow removal, but prior scraping means copies may still exist elsewhere.
How can developers avoid this risk?
Use local formatting tools, rotate exposed keys, and train teams to avoid uploading internal files.
How JENI Helps Strengthen Your Security Posture
JENI supports organizations that want tighter control over their systems without adding complexity. The platform helps teams reduce risk linked to careless storage, weak configurations, and unmonitored system behavior. It improves visibility across devices so administrators catch issues before they evolve into full incidents.
What JENI Delivers
- Automated system health and configuration monitoring
- Local optimization that avoids risky reliance on external tools
- Clear reporting that highlights suspicious trends and performance shifts
JENI fits naturally into environments that value disciplined security habits. It reinforces safe workflows by keeping analysis and diagnostics on trusted local machines rather than public services. It gives organizations a way to reduce unnecessary exposure while improving performance and stability. It supports teams that want tighter operational control and helps them maintain a cleaner, safer system footprint without changing how they work.

