You can use tools like Talisman which registers a Git hook to check if you are checking in anything that looks like secret.
I am thinking now would be a good time to port it to working with webhooks as well.
The tool would have blocked the aws credentials from being checked in: https://github.com/opnfv/releng-anteater/blob/master/master_...