logo

GCP Incident report: Spotting an attacker in Google Cloud

ID: e144858f-8549-520f-9c80-fd0d274c7c4f

STIX ID: report--e144858f-8549-520f-9c80-fd0d274c7c4f

Feed Name: Expel Blog

Threat Score
45/100

Date Published: 2022-06-09

Date Updated: 2026-04-27

Author: Oscar De La Rosa; Girish Mukhi; David Blanton

...
...

TL;DR: Publicly exposed Google Cloud service account credentials in a public GitHub repository allowed an attacker (observed from a TOR exit node) to attempt creating a new service account key via the Google SDK; the attempt failed because the compromised service account lacked required IAM permissions and no further malicious activity was observed. Key takeaways: enforce least privilege, rotate keys regularly, and avoid storing credentials in code or repositories.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.