This seems implausibly high. Is it including stuff like putting password=replaceme in an example config file?
No surprise that they get leaked all the time now, though at least one can cancel them at any point... and then you have to spend an hour or two replacing the cached version everywhere.
GitGuardian can provide an automatic audit of your company-specific leaks we found on GitHub. Just ask: https://www.gitguardian.com/complimentary-audit-secrets-leak...
More details on how it works: https://blog.gitguardian.com/github-secrets-leak-free-audit/