Found large Australian news corp API & SSO Keys

I’m new to the world of pen testing & bug bounty so don’t mind my noob questions.

I was doing a lil experimental check on some large news corps in Australia and I came across a News Corp’s API & SSO key.

I’m just wondering how much of a security risk is this for that News Corp?

Should I report it to them or is there different types/layers of API & SSO keys?

Apologies again for the noobness.

