Passwords.txt
Update your Acceptable Use Policy (AUP). State clearly: "The creation, storage, or transmission of plaintext credential files (including but not limited to passwords.txt, credentials.xlsx, or keys.pem) on any company device or cloud service is grounds for immediate disciplinary action."
A prominent game developer suffered a ransomware attack. The attacker didn't exploit a software vulnerability. Instead, they found a file named dev_passwords.txt on a public-facing Jenkins server. Inside were the AWS root keys. The attacker deleted 80% of the company's production data in one command. passwords.txt
Every web scanner (Gobuster, Dirb, DirBuster) has a wordlist containing hundreds of variations of passwords.txt. When a hacker runs a scan against your domain (https://yourcompany.com), the first 100 requests include: Update your Acceptable Use Policy (AUP)