Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Mercedes-Benz GitHub Token Exposure 2024: How One Employee’s…
Breach analysis Incident: 26 Jan 2024

Mercedes-Benz GitHub Token Exposure 2024: How One Employee’s Public Repository Opened Internal Source Code

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Category: NHI
Attack route: Leaked secret Identities: Source control token
On this page

On 26 January 2024, TechCrunch reported that a Mercedes-Benz employee had left a GitHub access token in a public GitHub repository, where it sat from late September 2023 until January 2024. The token was found by RedHunt Labs, a London-based security firm, during a routine scan on 11 January 2024. RedHunt says it gave "unrestricted" and "unmonitored" access to the source code on Mercedes-Benz's internal GitHub Enterprise Server, and that the repositories held further secrets such as cloud access keys, database connection strings and API keys. Mercedes-Benz revoked the token and removed the public repository on 24 January 2024, two days after being told. The company said the token gave access to "a certain number of repositories", not the whole server, and that customer data was not affected according to its analysis. Mercedes declined to say whether anyone else had used the token, so misuse is neither confirmed nor ruled out.

Key takeaways

  • A GitHub token belonging to a Mercedes-Benz employee was exposed in a public repository from 29 September 2023, according to RedHunt Labs, and stayed valid until 24 January 2024, a window of 117 days.
  • RedHunt says the token reached Mercedes-Benz's internal GitHub Enterprise Server, whose repositories contained database connection strings, cloud access keys, design documents, SSO passwords and API keys. BleepingComputer notes RedHunt had not verified the contents of those files.
  • Mercedes-Benz confirmed that "source code containing an internal access token was published on a public GitHub repository", revoked the token two days after notification and said customer data was not affected.
  • This is an exposure with no confirmed misuse. Mercedes did not say whether its logs showed access by anyone other than the researchers.
  • The identity lesson: a personal access token carries its owner's permissions wherever it goes, so one token in a personal repository can expose an entire corporate code estate and the secrets inside it.

At a glance

OrganisationMercedes-Benz
WhenToken exposed from 29 September 2023; found 11 January 2024; reported to Mercedes 22 January 2024; revoked 24 January 2024; made public 26 January 2024
AttackerNone known. Found by RedHunt Labs during a routine scan of GitHub
Entry pointA GitHub token committed to an employee's public GitHub repository
Identities abusedA GitHub token with access to Mercedes-Benz's GitHub Enterprise Server; secrets stored in the internal repositories, including cloud keys and database credentials, according to RedHunt
ImpactInternal source code and embedded secrets reachable for about four months; no confirmed misuse; Mercedes says customer data was not affected
CategoryNHI. Incident class: exposure, no confirmed misuse (source control token published in a public repository)

What happened

RedHunt Labs scans the internet for leaked data as part of its attack surface management work. On 11 January 2024 its scan of GitHub found a token in a public repository belonging to a Mercedes-Benz employee. RedHunt gives the date of the exposure as 29 September 2023. "The GitHub token gave 'unrestricted' and 'unmonitored' access to the entire source code" on the company's internal GitHub Enterprise Server, Shubham Mittal, RedHunt's co-founder and chief technology officer, told TechCrunch. "The repositories include a large amount of intellectual property," he said.

According to RedHunt, the repositories also held database connection strings, cloud access keys, blueprints, design documents, SSO passwords and API keys. TechCrunch, which coordinated the disclosure, reported that the repositories contained Microsoft Azure and Amazon Web Services keys and a Postgres database. BleepingComputer noted that RedHunt had not verified the contents of the exposed files, and that evidence of any malicious use would depend on whether audit logging was enabled on the GitHub Enterprise server.

RedHunt began coordinating with TechCrunch on 15 January, and the issue was reported to Mercedes-Benz on 22 January. On 24 January Mercedes revoked the token, and RedHunt verified it no longer worked. Mercedes spokesperson Katja Liesenfeld told TechCrunch that "internal source code was published on a public GitHub repository by human error," and that the company "revoked the respective API token and removed the public repository immediately." In a statement to BleepingComputer, Mercedes said: "We can confirm that source code containing an internal access token was published on a public GitHub repository," that the token gave access to a certain number of repositories rather than the whole server, and that "Customer data was not affected as our current analysis shows." Mercedes declined to tell TechCrunch whether it had seen any third-party access or had logs to check.

Timeline

DateEvent
29 September 2023The GitHub token is exposed in an employee's public repository, according to RedHunt Labs.
11 January 2024RedHunt Labs finds the token during a routine scan of GitHub.
15 January 2024RedHunt begins coordinating disclosure with TechCrunch.
22 January 2024Mercedes-Benz is notified.
24 January 2024Mercedes revokes the token and removes the repository; RedHunt confirms the token no longer works.
26 January 2024TechCrunch publishes the story.
29 January 2024RedHunt Labs publishes its own write-up.

How it happened: the identity attack path

  1. Broad token issued. An employee held a GitHub token able to read repositories on Mercedes-Benz's GitHub Enterprise Server.
  2. Token committed to a public repository. The token ended up in the employee's public GitHub repository, visible to anyone, by human error according to Mercedes.
  3. No detection for four months. The token remained valid and public from late September 2023 until a third party reported it in January 2024.
  4. Secrets behind the token. The internal repositories it could reach held further credentials, including cloud keys and database connection strings, according to RedHunt, so one leak could lead to many systems.
  5. Revocation after disclosure. Mercedes revoked the token two days after notification. Whether anyone used it in the meantime has not been disclosed.

Impact

  • Confirmed by Mercedes: source code containing an internal access token was published publicly; the token gave access to a number of internal repositories and was revoked.
  • Reported by RedHunt: access to internal source code and repositories containing cloud access keys, database connection strings, SSO passwords and API keys. Mercedes disputes that the whole server was reachable.
  • Customer data: not affected, according to Mercedes' analysis at the time.
  • Misuse: none confirmed, and none ruled out publicly. Mercedes did not say whether logs showed other access.

What this means for NHI governance

GitHub personal access tokens are often thought of as belonging to a person, but they behave as non-human identities. They are long-lived strings that authenticate scripts and tools without any sign-in, MFA prompt or device check, and they carry every permission their owner has. Here, a token tied to one employee reached a corporate GitHub Enterprise Server. Once it was in a public repository, anyone who found it had the same reach.

The exposure was made worse by what sat behind the token. Source code repositories that contain cloud keys and database connection strings turn a source control leak into a cloud and data leak. That pattern appears again and again in our database, from The New York Times in 2024 to Home Depot in 2025. Short-lived, narrowly scoped tokens, secret scanning on personal as well as corporate repositories, and secrets kept out of code are covered in our Secrets Management Guide and NHI Authentication Guide.

Recommendations

  • Revoke leaked tokens at once and rotate everything they could reach. Treat secrets stored in the exposed repositories as compromised too, and review audit logs for the token's use. See the Leaked Credential Response Playbook.
  • Use fine-grained, expiring tokens. Limit each token to the repositories and actions it needs and give it a short lifetime, so a leak has a small blast radius. See our NHI Authentication Guide.
  • Monitor public code for your organisation's secrets. Scan public GitHub, including employees' personal repositories, for tokens and keys that work against your systems.
  • Keep secrets out of source code. Move cloud keys, database credentials and API keys from repositories into a secrets manager. See our Secrets Management Guide.
  • Turn on and retain audit logs for source control. Without GitHub Enterprise audit logs, you cannot tell whether an exposed token was used.
  • Restrict enterprise access to managed identities. Use SSO-enforced tokens and IP allow lists for GitHub Enterprise so a token found on the internet does not work from anywhere. See our CI/CD Pipeline Identity Security Guide.

Frequently asked questions

What happened in the Mercedes-Benz GitHub token leak?

A Mercedes-Benz employee exposed a GitHub token in a public repository from late September 2023. RedHunt Labs found it in January 2024 and says it gave access to the company's internal GitHub Enterprise Server. Mercedes revoked it on 24 January 2024.

Was Mercedes-Benz source code stolen?

No theft has been confirmed. The token could reach internal source code for about four months, but Mercedes has not said whether anyone other than the researchers used it. It said customer data was not affected.

What secrets were in the Mercedes-Benz repositories?

According to RedHunt Labs, the repositories contained database connection strings, cloud access keys, blueprints, design documents, SSO passwords and API keys. TechCrunch reported Azure and AWS keys. RedHunt had not verified the files' contents, BleepingComputer noted.

New York Times GitHub Breach 2024 · Home Depot Token Exposure 2025 · Football Australia AWS Keys Exposure 2024 · Secrets Management Guide · Leaked Credential Response Playbook

How NHI Mgmt Group can help

Developer tokens are among the most widely leaked credentials and among the least governed. We help organisations inventory them, scope them down and catch them when they leak. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org