Home Depot reportedly left internal systems at risk for over a year
- Home Depot exposed a GitHub token for a year, granting access to critical internal systems
- Researcher warnings were ignored until media intervened, after which the token was revoked
- Similar leaks across GitHub/GitLab show widespread risks from hardcoded secrets and misconfigured repos
Home Depot kept access to its internal systems open for more than a year, to anyone who knew where to look, experts have warned.
Security researcher Ben Zimmermann recently found a published GitHub access token which belonged to a Home Depot employee.
The token was exposed, most likely by mistake, in early 2024, and granted access to “hundreds of private Home Depot source code repositories” hosted on GitHub. Zimmermann said the token allowed him to modify the contents of those repositories.
A common problem
The tokens granted the researcher access to the company’s cloud infrastructure, order fulfillment and inventory management systems, as well as code development pipelines.
Zimmermann also said he tried reaching out to Home Depot on multiple occasions and through different channels, but was met with silence.
Only after reporting his findings to TechCrunch was the hole plugged, when the publication reached out to the company, which confirmed the token was removed in early December, and access was revoked.
GitHub access tokens often get left behind during software development, and as such present a unique opportunity for hackers looking for an easy way into corporate infrastructure.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
A security researcher recently found thousands of secrets in public GitLab Cloud repositories, demonstrating how software developers are inadvertently putting their own projects at risk of cyberattacks. Luke Marshall has revealed how he scanned GitLab Cloud, Bitbucket, and Common Crawl, for things like API keys, passwords, or tokens – and unfortunately uncovered quite a lot.
And in April 2025, security researchers GreyNoise warned that Singaporean threat actors were on the hunt for organizations in the country that can be broken into and exploited. At that time, cybercriminals were increasingly scanning for exposed Git configuration files.

The best antivirus for all budgets
Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds. Make sure to click the Follow button!
And of course you can also follow TechRadar on TikTok for news, reviews, unboxings in video form, and get regular updates from us on WhatsApp too.
Home Depot exposed a GitHub token for a year, granting access to critical internal systems Researcher warnings were ignored until media intervened, after which the token was revoked Similar leaks across GitHub/GitLab show widespread risks from hardcoded secrets and misconfigured repos Home Depot kept access to its internal systems open…
Recent Posts
- I’m an outdoors expert — here are 9 easy-pitch tents I’d recommend for a fuss-free camping trip
- Samsung’s updated Health app unsurprisingly comes with new AI-powered features
- Amazon develops a warehouse robot workers can speak to
- This App Makes Google TV Actually Usable
- Google Wallet ID passes will be available in select EU states this summer
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023