logo

CISA Admin Leaked AWS GovCloud Keys on Github

ID: ca3c45ae-b261-5f16-9fa8-ecad15d46d52

STIX ID: report--ca3c45ae-b261-5f16-9fa8-ecad15d46d52

Feed Name: Krebs on Security

Threat Score
78/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: BrianKrebs

...
...

A public GitHub repository maintained by a CISA contractor (the “Private-CISA” repo) accidentally exposed numerous sensitive assets — including administrative AWS GovCloud keys, plaintext internal passwords, tokens, and access to the agency’s artifactory — potentially enabling attackers to access, persist in, or backdoor CISA systems; the account was taken offline after disclosure but some credentials remained valid for 48 hours and CISA is investigating.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.