GCP Incident report: Spotting an attacker in Google Cloud
ID: e144858f-8549-520f-9c80-fd0d274c7c4f
STIX ID: report--e144858f-8549-520f-9c80-fd0d274c7c4f
Feed Name: Expel Blog
Date Published: 2022-06-09
Date Updated: 2026-04-27
Author: Oscar De La Rosa; Girish Mukhi; David Blanton
TL;DR: Publicly exposed Google Cloud service account credentials in a public GitHub repository allowed an attacker (observed from a TOR exit node) to attempt creating a new service account key via the Google SDK; the attempt failed because the compromised service account lacked required IAM permissions and no further malicious activity was observed. Key takeaways: enforce least privilege, rotate keys regularly, and avoid storing credentials in code or repositories.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
