In May 2020, Swiss software engineer Till Kottmann downloaded more than 580 Git repositories from a GitLab server belonging to Daimler AG, the parent company of Mercedes-Benz, and published them online. He did not need to break in. The server let anyone register an account, and according to iThome and CPO Magazine it accepted a Daimler email address that did not exist without verifying it. The repositories held source code for the onboard logic unit (OLU), a component in Mercedes-Benz vans that connects them to the cloud. Reports that followed said the code also contained passwords and API tokens for Daimler's internal systems. Kottmann uploaded the repositories to MEGA, the Internet Archive and his own GitLab server. Daimler took its GitLab server offline after ZDNet contacted it but made no public statement. The leak became public by name on 18 May 2020, and no misuse of the exposed credentials has been reported.
Key takeaways
- A Daimler GitLab server allowed open self-registration, so an outsider could create an account and download more than 580 internal repositories, according to SiliconANGLE and iThome.
- The repositories contained source code for the onboard logic unit used in Mercedes-Benz vans, and reportedly passwords and API tokens for Daimler's internal systems.
- Kottmann republished the code on MEGA, the Internet Archive and his own GitLab server, so every secret inside it became public.
- Daimler shut the server down after ZDNet's inquiry but did not comment; no misuse of the exposed credentials has been reported.
- The identity lesson: secrets committed to code inherit the weakest control on the repository, and an open sign-up page made Daimler's machine credentials as public as its source code.
At a glance
| Organisation | Daimler AG, parent company of Mercedes-Benz |
|---|---|
| When | Repositories downloaded and posted online in May 2020; reported by name from 18 May 2020 |
| Attacker | No criminal attacker known. Software engineer Till Kottmann downloaded and published the code |
| Entry point | Open account registration on Daimler's self-hosted GitLab server, which accepted an unverified Daimler email address |
| Identities abused | Passwords and API tokens for Daimler internal systems, reported to be embedded in the leaked repositories |
| Impact | More than 580 repositories of van onboard logic unit source code published online; no confirmed misuse of the exposed credentials, and no statement from Daimler |
| Category | NHI. Incident class: exposure, no confirmed misuse (passwords and API tokens published with leaked source code) |
What happened
Till Kottmann, a software engineer based in Switzerland, regularly searched the internet for interesting GitLab instances. Using Google search queries, often called Google dorks, he found a GitLab server run by Daimler AG. According to iThome and CPO Magazine, the server did not verify new accounts and accepted registration with a Daimler corporate email address that did not belong to any real employee. Once signed in, he could see and clone the company's internal projects.
He downloaded more than 580 Git repositories containing source code for the onboard logic unit (OLU), a component installed in Mercedes-Benz vans. CPO Magazine reported that the OLU handles functions such as vehicle tracking, status checks, remotely freezing a van after theft, cloud connectivity and support for third-party apps, and that the repositories also held Raspberry Pi images, server images, internal documentation and code samples. In a tweet on 15 May 2020, shown by GIGAZINE, Kottmann described a leak of around 550 repositories from one of Germany's largest corporations, without naming it. He then uploaded the code to MEGA, the Internet Archive and his own GitLab server, iThome reported.
The code was not the only thing exposed. SiliconANGLE reported on 18 May that further analysis had found passwords and API tokens for Daimler's internal systems in the repositories. CPO Magazine attributed the finding to the security firm Under the Breach and said the credentials could grant access to the automaker's cloud platform, while iThome linked the analysis to Rapid7 commentary gathered by SiliconANGLE. Whoever found them first, the credentials were now in a public archive. Chris DeRamus of Rapid7 told CPO Magazine: "Misconfigured security settings is the top culprit behind many major data leaks and breaches."
Daimler took the GitLab server offline after ZDNet contacted the company, but it did not answer requests for comment, according to iThome and GIGAZINE. CPO Magazine reported that Kottmann said he would remove the code only if Daimler contacted him, and that there was no sign of legal action. No source reports that the exposed passwords or tokens were used by anyone, and Daimler has not said whether it rotated them.
Timeline
| Date | Event |
|---|---|
| May 2020 | Till Kottmann finds Daimler's GitLab server, registers an account and downloads more than 580 repositories. |
| 15 May 2020 | Kottmann tweets about a leak of around 550 repositories from a large German corporation, without naming it. |
| 18 May 2020 | The leak is reported by name, citing ZDNet; SiliconANGLE reports that passwords and API tokens were found in the code. |
| 19 May 2020 | iThome and GIGAZINE report that Daimler took the GitLab server offline after ZDNet contacted it, without comment. |
| 29 May 2020 | CPO Magazine reports that Under the Breach found passwords and API tokens for internal smart car components. |
How it happened: the identity attack path
- Server found by search. Daimler's self-hosted GitLab server was indexed and discoverable with ordinary search queries.
- Account self-registered. The server allowed open sign-up and accepted an unverified Daimler email address, so an outsider gained a valid user account.
- Repositories cloned. That account could read more than 580 internal repositories, which were downloaded in full.
- Secrets inside the code. The repositories reportedly contained passwords and API tokens for Daimler internal systems.
- Published online. The repositories, and the credentials inside them, were uploaded to MEGA, the Internet Archive and a personal GitLab server.
Impact
- Confirmed: more than 580 internal repositories, including onboard logic unit source code for Mercedes-Benz vans, were downloaded and published online.
- Reported: passwords and API tokens for Daimler internal systems were in the leaked code, according to SiliconANGLE, iThome and CPO Magazine. Daimler has not confirmed this.
- Not reported: any use of those credentials, any customer data exposure or any statement from Daimler.
- Potential: live tokens and passwords for internal and cloud systems could be used to plan and carry out intrusions, and security experts quoted by iThome said the code itself could give competitors valuable information.
What this means for NHI governance
This is on an NHI list because of what rode along with the code. Passwords and API tokens used by systems, not people, were stored in repositories, and the repositories were protected only by a sign-up page with no verification. Once a stranger could register, every machine credential in those projects was effectively published. Removing the server afterwards did not help: the copies were already on public file hosts.
The incident also shows how secrets outlive the code that holds them. Taking a server offline does nothing for credentials that have already been cloned; only revoking and rotating them does. Source code platforms should be treated as credential stores: secrets kept out of the code, repositories scanned, and access to the server limited to verified staff. Our Secrets Management Guide and Leaked Credential Response Playbook cover these steps, and Mercedes-Benz faced a similar lesson again with an exposed GitHub token in 2024.
Recommendations
- Revoke and rotate every credential in leaked repositories. Treat all secrets in an exposed project as compromised, including those in Git history, and confirm rotation rather than relying on the server being taken down. See our Leaked Credential Response Playbook.
- Keep secrets out of source code. Store passwords and API tokens in a secrets manager and inject them at runtime. See the Secrets Management Guide.
- Disable open registration on internal code platforms. Self-hosted GitLab and similar tools should require single sign-on or administrator approval, and should verify email domains before granting any access.
- Scan repositories for secrets continuously. Automated scanning of code and history finds embedded credentials before an outsider does. See the CI/CD Pipeline Identity Security Guide.
- Limit what a new account can see. Default new users to no project access, so one stray account cannot read hundreds of repositories.
- Check what search engines can see. Search for your own code hosting, build and dashboard hosts the way a researcher would, and remove anything that should not be public.
Frequently asked questions
How did the Mercedes-Benz source code leak happen in 2020?
Software engineer Till Kottmann found a Daimler AG GitLab server through search queries, registered an account with an unverified Daimler email address and downloaded more than 580 repositories of source code for Mercedes-Benz vans' onboard logic units. He then published them on MEGA, the Internet Archive and his own GitLab server.
Were credentials exposed in the Daimler GitLab leak?
Yes, according to reports at the time. SiliconANGLE, iThome and CPO Magazine reported that the leaked repositories contained passwords and API tokens for Daimler's internal systems. Daimler did not comment, and no misuse of those credentials has been reported.
Is this the same as the 2024 Mercedes-Benz GitHub token exposure?
No. The 2020 leak came from open registration on Daimler's own GitLab server. The 2024 case involved an exposed GitHub token and is a separate incident, covered on its own page.
Related NHI Mgmt Group resources
Mercedes-Benz GitHub Token Exposure 2024 · Nissan Source Code Leak 2021 · Twitter Source Code Leak 2023 · Secrets Management Guide · Leaked Credential Response Playbook
How NHI Mgmt Group can help
Source code platforms quietly accumulate machine credentials. We help teams find the secrets sitting in their repositories, move them into managed stores and build a response plan for the day a repository leaks. See our NHI and AI agent security training.
References
- SiliconANGLE: Mercedes-Benz source code exposed via misconfigured Git registration system (18 May 2020)
- iThome: Mercedes-Benz GitLab server misconfigured, researcher downloads more than 580 Git repositories (in Chinese) (19 May 2020)
- GIGAZINE: Mercedes-Benz on-vehicle processing unit (OLU) source code leaked (19 May 2020)
- CPO Magazine: Smart Car Source Code Leak May Compromise Customer Safety (29 May 2020)