Found that the key is suspected to be leaked
Server Integration And Keys: Found that the key is suspected to be leaked
Identify signs of suspected leaks
Common signs include:
- Server-side API call with unknown IP appears.
- The request volume suddenly increases or exceeds the normal business peak.
- Application or data access behavior that does not belong to the organization occurs.
- The key appears in the code repository, build artifacts, chat logs, or public logs.
- The server-side API returns an abnormal Region or permission error.
Don’t wait to confirm all the details before taking protective measures. Wherever there is reasonable suspicion, the risk should be limited first.
Rotate immediately
Follow the "Rotate Server Keys" process to immediately rotate the keys of the affected Region and prioritize updating the production service. Old compromised keys should not be used even within the 48-hour grace period.
If the Public API Key is leaked, please check the source/signature verification, abnormal usage and rate limits of the endpoint, and contact Geelab to confirm the deactivation or regeneration plan.
Check the call log
Post-rotation inspection:
- Abnormal IP and request time.
- Accessed applications and Regions.
- Number of requests and error types.
- Whether there are data query or export risks.
- Are there still services using the old key.
Keep necessary audit records and handle them according to the organization's security event process.
Tighten IP whitelist
If the service plan supports IP whitelisting:
- List all legal server exit IPs.
- Delete unknown or no longer used addresses.
- Verify in the test environment first.
- Update the production whitelist.
- Observe authentication failures and business errors.
Do not directly clear the blank list when the exit address cannot be confirmed, so as not to interrupt normal services.
Contact Geelab Support
When contacting support, please provide desensitized information:
- Organization and Region.
- The time frame in which the anomaly was discovered.
- Affected applications.
- Abnormal IP or log summary.
- Request ID or error code.
- Completed rotation and whitelisting operations.
Do not send full server keys or passwords in tickets, emails, or chats.