CISA Admin Leaked AWS GovCloud Keys on Github
2026-05-21T07:23:25Z•3329c841cb7b5890da896fa26aaee37d9f75cb277ff4c52633f08ef28dd61327
AWSCISAGitHubGovCloudcloud-credentialscontractordata-leakdeployment-pipelineexposed-credentialsincident-responsesecret-leaksupply-chain-riskunauthorized-access
What happened
A CISA contractor publicly hosted a GitHub repository that exposed credentials for multiple highly privileged AWS GovCloud accounts and numerous internal CISA systems, along with build/test/deploy documentation. The leak enables potential unauthorized access to sensitive government cloud resources, supply-chain and deployment pipelines, and broad lateral movement within CISA environments. This represents a severe operational and national-security risk and likely requires immediate credential revocation, access reviews, and secret-management remediation.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 3329c841cb7b5890da896fa26aaee37d9f75cb277ff4c52633f08ef28dd61327
- Enrichment time
- 2026-05-21T07:23:25Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.