TL;DR: High-profile 2022 breaches at Toyota, Cash App, and Cloudflare all stemmed from credential exposure, third-party access, or phishing, with the Toyota issue persisting nearly five years before detection, according to Axiad’s security bulletin. The lesson is that identity governance fails when access outlives oversight, especially across contractors, former employees, and password-based workflows.
At a glance
What this is: This bulletin reviews three 2022 breaches and shows that exposed credentials, former-employee access and phishing all convert ordinary identity workflows into breach paths.
Why it matters: IAM and PAM teams need to treat credential lifecycle, third-party access and phishing resistance as one governance problem, because any weak link can outlive its intended controls.
Context
Credential sprawl is the accumulation of usernames, passwords, keys and access paths across employees, contractors, repositories and SaaS systems. In the article’s examples, the problem is not a single control failure but the way access persists after ownership, employment or publishing decisions change.
For identity programmes, the governance gap is lifecycle discipline: who received the credential, who can still use it, and whether the access was ever removed when the business relationship changed. The article shows how breach exposure can come from public code, stale post-employment access and phishing, which are different entry points but the same control failure at the identity layer.
Key questions
Q: What breaks when third-party credentials are published in source code?
A: A public code leak becomes an access event when secrets remain valid after exposure. The breach risk is not limited to the repository. It extends to whatever server, cloud account, or API the secret unlocks. Teams need secret scanning, rapid revocation, and separate handling for third-party code contributions.
Q: What happens when ex-employees still have access to company data?
A: When former employees retain access, organisations keep an unnecessary path to confidential information open long after the employment relationship ends. That creates avoidable exposure, especially if accounts, permissions, or shared credentials are not revoked promptly. The practical consequence is continued data risk, delayed incident containment, and weaker accountability over who can still reach internal systems.
Q: How can organisations reduce phishing risk in passwordless environments?
A: They should extend identity assurance beyond login by signing email and documents with certificates. That way, the organisation can validate not just who authenticated, but whether downstream communications and approvals came from a trusted identity. This matters because phishing often targets workflow trust rather than the initial sign-in.
A: Start with a rapid scope check. Hunt for indicators of compromise, identify where the exposed credentials were stored or forwarded, and determine which accounts, systems, and third parties may have been affected. Then rotate the compromised secrets immediately, prioritize privileged accounts, and verify that MFA is enabled. The goal is to cut off reuse before attackers can turn leaked credentials into broader access.
Technical breakdown
How exposed credentials become a breach path
When credentials appear in public code repositories or other shared systems, the initial exposure may remain dormant until an attacker discovers and reuses it. The technical issue is not just disclosure, but the lack of binding between the secret and its intended scope, so a leaked credential can still authenticate to a server or data store long after it should have lost value. In Toyota’s case, a subcontractor’s source code exposure created a long-lived access path because the credential remained usable until discovery. That is a classic secret lifecycle failure: the token or password outlives the trust decision that created it.
Practical implication: treat every exposed secret as already active and revoke it before investigating scope.
Why post-employment access persists
Former employees often keep access because the identity governance process is tied to payroll status or manual offboarding, not to actual data entitlements. If reports, portals or export paths remain reachable after employment ends, the account may still be authorised even though the relationship has changed. Cash App’s case shows that the breach surface is not limited to credentials in the wild; it also includes legitimate accounts whose access was never fully withdrawn. The deeper issue is stale entitlement persistence, where access reviews lag behind the real-world change in identity status.
Practical implication: tie leaver processes to entitlement removal and not just account disablement.
Why phishing still succeeds against strong logins
Phishing works when the attacker can capture valid credentials before the authentication stack enforces stronger factors or device-based checks. Cloudflare’s incident shows that usernames and passwords remain a valuable target even when a hardware key blocks the final sign-in. In practice, phishing is successful at the point of user interaction, not necessarily at the point of account compromise. That means the technical control is not simply adding more authentication steps, but ensuring the credential captured in the first place cannot be replayed into a usable session. Hardware-bound authentication reduced impact because the stolen password alone was insufficient.
Practical implication: pair phishing-resistant authentication with rapid session revocation for any credential capture event.
Threat narrative
Attacker objective: The objective was to turn exposed or residual identity access into customer data exposure and downstream account abuse.
- Entry occurred when a third-party contractor exposed source code credentials on GitHub, when a former employee retained access to customer reports after departure, and when employees were lured to a fake login page by SMS phishing.
- Credential access followed through reusable passwords or report access that remained valid beyond the intended trust boundary, allowing the attackers or the unauthorised user to reach internal systems or data.
- Impact differed by case but followed the same pattern: Toyota exposed customer data, Cash App exposed account information, and Cloudflare saw credential theft attempts blocked before deeper compromise.
Breaches seen in the wild
- Co-op cyber attack 2025: Attackers linked to Scattered Spider tricked their way into a Co-op employee account and stole personal data of all 6.5 million members.
- Sisense breach 2024: A credential in Sisense's GitLab reportedly opened S3 buckets of customer tokens, passwords and certificates; CISA urged a full reset.
Read and download The State of NHI & AI Agent Breach Report 2026, covering 150+ breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
Credential sprawl is a lifecycle problem before it is a breach problem: The article’s three cases show that exposure begins when identity ownership, access scope and revocation are not aligned. A leaked secret, a departed employee and a phished password are different symptoms of the same governance failure. The implication is that IAM and NHI teams must measure access by lifecycle state, not by whether an account still exists.
Long-lived credentials create a standing trust debt: Toyota’s nearly five-year exposure window shows what happens when credentials remain valid long after the business event that created them. That is not just poor hygiene, it is a broken assumption that secrets will be discovered before reuse. NHI governance has to treat every persistent credential as residual risk until it is explicitly retired.
Post-employment access exposes the limits of account-based offboarding: Cash App demonstrates that disabling an account is not the same as removing meaningful access to data. If reports, exports or privileged interfaces remain reachable through other paths, the leaver process has failed in substance even if the directory record changes. Practitioners should view offboarding as entitlement closure, not account closure.
Phishing-resistant authentication only works when credential replay is blocked: Cloudflare’s experience shows that stolen passwords remain a live threat even when stronger factors stop final access. The important lesson is that the attack still succeeds at the credential capture stage, so the control objective shifts from preventing all theft to making the stolen secret unusable. Teams that measure success only by blocked logins miss the broader exposure window.
Credential sprawl is the modern identity blast radius: Public code, former employees and SMS phishing all widened the same blast radius across different trust zones. That pattern is exactly what OWASP-NHI and zero-trust identity models are meant to constrain, because the identity boundary now extends beyond formal employees into contractors, repositories and consumer-grade messaging channels. The practical conclusion is that every extra credential expands the organisation’s attack surface unless ownership, scope and revocation are continuously governed.
What this signals
Credential sprawl widens identity blast radius: When credentials live in code repositories, contractor workflows and human inboxes at the same time, the organisation no longer has one access perimeter. The practical shift is to govern issuance, reuse and revocation as one lifecycle rather than three separate operational tasks.
Access review is not enough when access is residual: Reviews assume the identity still has a stable permission set long enough to certify. In these cases, the more useful control point is revocation at the moment a repository goes public, a contractor relationship changes or a phishing attempt succeeds.
Leaver governance now extends beyond people: The same offboarding logic that removes employee access has to apply to third-party credentials and shared secrets. If not, the attack surface persists after the business relationship ends, which is exactly how stale access becomes exploitable.
For practitioners
- Audit third-party credential publishing paths Inventory where contractors, developers and service providers can expose secrets in public repositories, paste sites or shared code systems, then block those routes with review and scanning controls.
- Bind leaver offboarding to entitlement removal Remove report access, export rights and downstream system permissions as part of the same workflow that ends employment or contractor engagement, rather than treating account disablement as sufficient.
- Replace password replay with phishing-resistant authentication Require hardware-bound or device-bound sign-in for sensitive workflows so a stolen username and password cannot be reused as a valid session by an attacker.
- Revoke exposed secrets immediately Treat any credential found in a public repository, support artifact or shared file as compromised and rotate or revoke it before remediation analysis continues.
- Monitor for residual post-employment access Run periodic checks for former employees or contractors who can still reach customer data, reports or administrative functions through alternate permissions or stale group membership.
Key takeaways
- The article shows that breach exposure often starts with ordinary identity handling mistakes, not only with sophisticated malware or exploit chains.
- Toyota, Cash App and Cloudflare illustrate three different identity failure modes: exposed secrets, residual post-employment access and password phishing.
- The control that matters most is lifecycle discipline, because access that is not revoked, scoped or hardened will eventually be reused against the organisation.
Key terms
- Credential Sprawl: Credential sprawl is the uncontrolled accumulation of machine secrets, keys, and tokens across systems, teams, and environments. It usually starts with a single use case and ends with overlapping permissions, unclear ownership, and a larger attack surface than the organisation expected.
- Residual Access: Residual access is any permission, token, account, or data path that continues to work after a user should no longer have access. It is a common failure mode in SaaS-heavy environments because deprovisioning one system does not automatically shut down all downstream connections.
- Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
- Secret revocation: Secret revocation is the process of invalidating exposed credentials so they can no longer be used. In practice, it must include every system that trusts the secret, because a credential that remains valid after disclosure is still an active attack path.
Deepen your knowledge
NHI governance, identity lifecycle management, and machine identity security are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
Published by the NHIMG editorial team on June 8, 2026.
Updated on October 7, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org