Breaches today are more frequently occurring due to stolen or leaked credentials. The facilitation of API development across teams with platforms such as Postman and SwaggerHub has unleashed new concerns and measures required to ensure the safekeeping of credentials, be it API tokens or passwords. While most research and tooling in this area has been focused towards GitHub, it has been shown that this habit has been brought over to other platforms.This talk will be focused on leaked credentials from an offensive security perspective, shining light on methodologies for searching for secrets across platforms such as Postman, SwaggerHub, cloud buckets, PyPI, GitHub, and other sources. Hear about how we disclosed secrets to some of Canada's largest organizations with our tool "Porch Pirate" and explore the state of leaking credentials in 2024.