BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Thousands of Passwords Exposed via Popular JSON Formatter Tools

Organizations Leak Sensitive Credentials Through Online Code Formatting Tools, Leading to Active Exploitation and Temporary Feature Disabling

  • Organizations across sensitive sectors are exposing credentials by pasting them into online code formatting tools.
  • A dataset of over 80,000 files on JSONformatter and CodeBeautify revealed thousands of leaked credentials and personal data.
  • The shareable link feature of these tools makes sensitive information accessible and easy to scrape by malicious actors.
  • Fake AWS keys uploaded to these platforms were tested by attackers within 48 hours, showing active exploitation of leaked data.
  • Both tools have temporarily disabled the save function, likely responding to security concerns raised by affected organizations.

New research reveals that organizations in critical sectors such as government, telecommunications, and infrastructure have been exposing sensitive credentials by pasting them into online code formatting and validation tools. The Cybersecurity firm watchTowr Labs collected a dataset of over 80,000 files from platforms including JSONformatter and CodeBeautify, uncovering a wide range of leaked data like usernames, passwords, repository keys, database access credentials, and API keys.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

This data spans five years of JSONformatter content and one year from CodeBeautify, totaling more than 5 gigabytes of annotated JSON files. Affected sectors include finance, healthcare, aerospace, education, retail, and cybersecurity, among others. Security researcher Jake Knott explained that these tools are popular and often ranked high in search engine results, leading many organizations and developers to use them for formatting code that sometimes contains sensitive information, as stated here.

Both services allow users to save formatted code as shareable links, which can be accessed by anyone with the URL. These links follow predictable patterns (e.g., https://jsonformatter.org/{id} or https://codebeautify.org/{formatter-type}/{id}), making it possible for malicious actors to scrape exposed data using automated crawlers. Examples of leaked information include Jenkins secrets, encrypted credentials, Know Your Customer (KYC) details from banks, AWS credentials linked to a financial exchange’s monitoring tools, and Active Directory credentials for banking institutions.

watchTowr Labs conducted tests by uploading fake AWS keys, observing that these were targeted by attackers within 48 hours of being posted. This demonstrated active scraping and exploitation of exposed credentials. Knott emphasized the severity, stating, “Mostly because someone is already exploiting it, and this is all really, really stupid.”

In response to these findings, both JSONformatter and CodeBeautify have temporarily disabled the save functionality, reporting they are working on improvements and enhanced content prevention measures. watchTowr Labs suspects this action followed September communications with impacted organizations, as detailed above.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

War Sparks Cash Rush, Gold & Bonds Dumped

Bitcoin is under pressure as investors flee to cash, with Bitcoin retesting $67,500 support...

Circle Shares Plummet 20%; Tether Audit, Yield Bill Weigh

Circle's stock (CRCL) plummeted 20% on Tuesday, erasing recent gains.Rival Tether announced a major...

Robinhood announces $1.5B buyback plan over three years

Robinhood announced a new share repurchase program for up to $1.5 billion.The firm's shares...

Nearly All Pump Fun Traders Made Under $500

Over 96% of wallets trading Pump Fun-launched tokens have netted less than $500 in...

Epic Games Lays Off 1,000+

Epic Games is laying off over 1,000 employees, citing a significant decline in Fortnite...

Must Read

What Is Bcrypt Password Hashing Function?

KEY TAKEAWAYSBcrypt is a password hashing function that transforms plain passwords into unique alphanumeric sequences.It is a one-way process, ensuring that passwords cannot be...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading