A public GitHub repository containing 844 MB of sensitive data, including AWS GovCloud administrative keys and plaintext passwords for dozens of internal systems, remained exposed for half a year.
The Critical Failure: Despite receiving nine automated alerts prior to external notification, the exposure went unaddressed. Fragmented reporting channels and a lack of continuous cloud monitoring delayed the invalidation of critical keys by over 48 hours.
When the organization responsible for defending national infrastructure can leave plaintext credentials in public repositories and ignore automated warnings, it proves that developer secret mismanagement is a systemic, catastrophic risk that no entity is immune to.