Do you have no process ready to rotate a user's exposed credentials? It's what I would expect from any service provider once they become aware of an exposure.
E.g. I remember reading that Amazon even scans Github for AWS credentials proactively now, since this happened all the time.