Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Home Depot Token Exposure 2025: How a Leaked…
Breach analysis Incident: 12 Dec 2025

Home Depot Token Exposure 2025: How a Leaked GitHub Token Left Internal Systems Open for More Than a Year

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 11 min read
Category: NHI
Attack route: Leaked secret Identities: Source control token
On this page

In December 2025, TechCrunch reported that a Home Depot employee had published a private GitHub access token online, probably by mistake, and that it had stayed exposed since sometime in early 2024. Security researcher Ben Zimmermann found the token in early November 2025 and, when he tested it, found it gave access to hundreds of private Home Depot source code repositories, with the ability to modify them, as well as to cloud infrastructure, order fulfilment and inventory management systems and code development pipelines. He emailed Home Depot several times and messaged its chief information security officer, but got no reply. The token was taken offline and its access revoked only after TechCrunch contacted the company on 5 December 2025. Home Depot has not said whether anyone else used the token while it was public. The case is a clear example of a single long-lived non-human credential with no visible owner, no expiry that worked in practice and no route for outsiders to report it.

Key takeaways

  • A Home Depot employee published a private GitHub access token online, which TechCrunch says was exposed "sometime in early 2024". Researcher Ben Zimmermann found it in early November 2025.
  • According to TechCrunch, the token gave access to hundreds of private repositories with the ability to modify their contents, and to cloud infrastructure, order fulfilment, inventory management and code development pipelines.
  • Home Depot did not respond to Zimmermann's emails or to a LinkedIn message to its CISO. It had no vulnerability disclosure or bug bounty programme, so he went to TechCrunch.
  • TechCrunch contacted Home Depot on 5 December 2025; the token was removed and its access revoked soon after. The story was published on 12 December 2025.
  • Lessons: developer tokens need owners, expiry, narrow scopes and secret scanning, and organisations need a working channel for outsiders to report exposed credentials.

At a glance

OrganisationThe Home Depot
WhenToken exposed from early 2024 (TechCrunch); found early November 2025; revoked after 5 December 2025; reported 12 December 2025
AttackerNone identified. The token was found by a security researcher; Home Depot has not said whether anyone else used it
Entry pointA private GitHub access token belonging to an employee, published online by mistake
Identities abusedOne GitHub access token with write access to private repositories and reach into cloud and development pipeline systems
ImpactPotential read and write access to hundreds of private repositories and to internal cloud, fulfilment and inventory systems for more than a year; no confirmed misuse reported
CategoryNHI (leaked developer token, secrets exposure)

What happened

TechCrunch's report, by Zack Whittaker, opens: "A security researcher said Home Depot exposed access to its internal systems for a year after one of its employees published a private access token online, likely by mistake." According to the report, the token was exposed sometime in early 2024.

Ben Zimmermann, the researcher, found the token in early November 2025 and tested it. TechCrunch says it "granted access to hundreds of private Home Depot source code repositories hosted on GitHub and allowed the ability to modify their contents." The same access reached "Home Depot's cloud infrastructure, including its order fulfillment and inventory management systems, and code development pipelines." CSO Online described the access as write permissions to private repositories plus access to the company's cloud infrastructure and its order fulfilment and inventory systems.

The published reports do not say where exactly the token was posted, what type of GitHub token it was, or how a token issued for source control led on to the cloud and fulfilment systems. They do make clear that one credential tied to one employee carried a wide set of privileges.

Zimmermann tried to report the problem. TechCrunch says he "sent several emails to Home Depot but didn't hear back", and he also contacted chief information security officer Chris Lanzilotta through LinkedIn, again without a reply. Zimmermann told TechCrunch he had disclosed similar exposures to other companies, and that "Home Depot is the only company that ignored me."

Home Depot did not have "a way to report security flaws, such as a vulnerability disclosure or bug bounty program," TechCrunch reported, so Zimmermann asked the publication for help. TechCrunch contacted Home Depot on 5 December 2025. A spokesperson, George Lane, acknowledged receipt of the email but did not answer follow-up questions. According to TechCrunch, "The exposed token is no longer online, and the researcher said the token's access was revoked soon after our outreach."

TechCrunch also asked whether Home Depot could tell if anyone else had used the token during the months it was online. It did not get an answer. TechCrunch published the story on 12 December 2025, and CSO Online, SC Media and TechRadar followed within days. SC Media summarised the ending plainly: the issue "was only resolved after TechCrunch intervened."

Timeline

DateEvent
Early 2024A Home Depot employee publishes a private GitHub access token online, likely by mistake (TechCrunch; exact date not published).
Early November 2025Ben Zimmermann finds the token and tests it, confirming access to private repositories and internal systems.
After discovery (dates not published)Zimmermann sends several emails to Home Depot and messages its CISO on LinkedIn; none are answered.
5 December 2025TechCrunch contacts Home Depot; a spokesperson acknowledges the email but does not answer follow-up questions.
Soon after 5 December 2025The token is removed from public view and its access revoked, according to the researcher.
12 December 2025TechCrunch publishes the story; CSO Online reports it the same day.
15 December 2025SC Media and TechRadar report the exposure.

How it happened: the identity attack path

  1. A token outlives its purpose. An employee created or held a GitHub access token with broad rights over company repositories. Nothing in the public reporting suggests it expired or was reviewed between early 2024 and December 2025.
  2. The token leaks. The employee published it online, probably by mistake. Once a credential is public, anyone who finds it holds the same access as its owner.
  3. Broad privileges travel with it. According to TechCrunch, the token could read and modify hundreds of private repositories and reach cloud infrastructure, order fulfilment and inventory systems, and development pipelines. Write access to code and pipelines is the kind of access supply chain attackers look for.
  4. Nobody notices. The exposure lasted well over a year without the token being revoked. The reports do not show any detection or monitoring that flagged its public exposure or unusual use.
  5. The report goes nowhere. With no disclosure programme and no reply to emails or a message to the CISO, the finder had no route to the people who could revoke the token.
  6. Revocation only after press contact. The token came down only after a journalist asked questions, roughly a month after the researcher first found it.

Impact

  • Exposure window: TechCrunch says the token was exposed from early 2024 until it was revoked after 5 December 2025, which is more than a year.
  • Scope of access: hundreds of private source code repositories with the ability to modify them, plus cloud infrastructure, order fulfilment and inventory management systems and code development pipelines, according to TechCrunch.
  • Misuse: none has been reported. Home Depot did not answer TechCrunch's question about whether it could tell if anyone else used the token, so the absence of reported misuse is not evidence that none took place.
  • Disclosure process: the company had no vulnerability disclosure or bug bounty programme at the time, according to TechCrunch.

What this means for NHI governance

The Home Depot case has no attacker in the public record, only a leaked credential and a slow response, which makes it a useful study of what governance looks like when it is missing. A GitHub access token is a non-human identity. It authenticates code, scripts and tools rather than a person at a login screen, and it carries whatever privileges were attached when it was created. Here, one token tied to one employee could change source code and reach cloud, fulfilment and pipeline systems. That is a production-grade privilege held in a developer credential.

Three governance gaps stand out. First, ownership: the token belonged to an employee, but there is no sign that anyone at the organisation knew it existed, what it could do, or that it had leaked. Our NHI Ownership and Accountability Guide covers why every credential needs a named, accountable owner. Second, lifetime: a token that still worked after more than a year in public had no effective expiry or rotation. Third, scope: access to hundreds of repositories plus infrastructure is far wider than most individual tasks need.

The response gap matters as much as the leak. Exposed secrets in public places are routinely found by researchers, and by attackers. In November 2025, researcher Luke Marshall reported scanning 5.6 million public GitLab repositories and finding 17,430 verified live secrets, as BleepingComputer reported, which we cover in our page on 17,000+ secrets exposed in public GitLab repositories. When an outsider does find one of your tokens, a working disclosure channel is what turns that finding into a revocation. Without one, the fastest route in this case was a journalist.

Recommendations

  • Inventory developer tokens and give each an owner. Know which GitHub tokens can reach your organisation's repositories, who holds them and what they are for. Follow the NHI Ownership and Accountability Guide.
  • Set short lifetimes and narrow scopes. Use tokens limited to the specific repositories and permissions a task needs, always with an expiry date, and require organisation approval for them. Prefer GitHub Apps or short-lived credentials for automation over personal tokens.
  • Keep secrets out of places they can leak. Store credentials in a secrets manager rather than code, config or notes. The Secrets Management Guide sets out how to centralise, restrict, shorten and remove them.
  • Scan for your own leaked secrets. Turn on secret scanning and push protection for your repositories, and monitor public sources for credentials that belong to you, not only your own estate.
  • Separate code access from production access. A token for source control should not also unlock cloud, fulfilment or inventory systems. Review what each pipeline credential can reach.
  • Publish a vulnerability disclosure route and staff it. A security.txt file, a disclosure policy or a bug bounty gives finders somewhere to go, and someone must triage what arrives.
  • Revoke first, then investigate. When a token is reported, revoke it at once, then review audit logs for the whole exposure window, as covered in the ITDR Guide.

Frequently asked questions

What happened in the Home Depot token exposure?

A Home Depot employee published a private GitHub access token online, likely by mistake, in early 2024. It gave access to hundreds of private repositories with write rights and to internal cloud, order fulfilment, inventory and pipeline systems. Researcher Ben Zimmermann found it in November 2025, and it was revoked only after TechCrunch contacted Home Depot on 5 December 2025.

Was Home Depot hacked through the exposed token?

No attack has been reported. However, Home Depot did not tell TechCrunch whether it could determine if anyone other than the researcher used the token while it was public, so misuse can neither be confirmed nor ruled out from public information.

Why did it take so long to revoke the Home Depot token?

According to TechCrunch, Home Depot had no vulnerability disclosure or bug bounty programme, and it did not answer the researcher's emails or his LinkedIn message to the CISO. The token was revoked soon after TechCrunch contacted the company.

CrewAI GitHub token leak · Leaked SpotBugs token · Red Hat Consulting GitLab breach 2025 · Secrets Management Guide · NHI breaches

How NHI Mgmt Group can help

Developer tokens like the one Home Depot exposed are non-human identities, and they need owners, expiry, scoping and a plan for when they leak. Our NHI Foundation Level Training Course shows teams how to discover, govern and respond to exposed secrets and tokens before someone else finds them.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

    Bonus 33% off our NHI Course when you subscribe.

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org