logo

768 Leaked AWS Keys Still Active With Full Admin Access to Corporate Accounts

ID: 4c145b41-7531-5409-9269-1d98994fa382

STIX ID: report--4c145b41-7531-5409-9269-1d98994fa382

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-08-22

Date Updated: 2026-08-22

Author: Eswar

...
...

Truffle Security analyzed publicly exposed AWS credentials (Aug 2022–Aug 2026) and found 64,024 unique key pairs, including 10,625 root keys; researchers revalidated 10,616 keys and observed 88% still authenticated. The investigation identified 768 active keys with full administrative privileges (526 root, 242 IAM AdministratorAccess), many hosted in public Git histories, Hugging Face datasets, container images and CI logs; keys were often years old with poor rotation, creating widespread account takeover and data-theft risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.