r.nguyen@acme-corp.com pushed a commit to github.com/acme-corp/data-pipeline (public repo) at 10:52 containing a live AWS IAM access key (AKIA…) in a .env file. GitHub Advanced Security detected the secret within 4 seconds via pattern match (AKIA[0-9A-Z]{16}) with checksum validation — 97% confidence. The key was immediately revoked via the AWS IAM API before any external actor could use it. CloudTrail shows 0 API calls against the key between push and revocation (4-second window). Riley's commit was blocked from the remote and a new pre-commit hook has been deployed.