Lawmakers Demand Answers as CISA Tries to Contain Data Leak

2026-05-24T07:26:50Z490b71a380fa7184b8457fbdbb6be7c02230891b567a6c36f4b268e0d648634f
AWS GovCloudBlueHammerCISACanvasDDoSGandCrabGitHub leakIoT botnetKimwolfMicrosoft Office tokensREvilRussian state-backed actorsSharePointarrestcongressional inquirycredential exposuredata extortiondata leakeducation sectorincident responselaw enforcementpatch tuesdayransomwarerouter exploitzero-day

What happened

Multiple high-impact incidents reported: a CISA contractor publicly published AWS GovCloud credentials and extensive internal CISA secrets on a GitHub repository, triggering an ongoing containment effort and bipartisan congressional inquiries. A 23-year-old Ottawa man alleged to be the Kimwolf botnet operator (“Dort”) was arrested and charged in Canada and the U.S.; the botnet is linked to massive IoT-based DDoS activity. The Canvas education platform suffered a data extortion attack threatening the personal data of ~275 million students and faculty across ~9,000 institutions, causing wide-dis

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
490b71a380fa7184b8457fbdbb6be7c02230891b567a6c36f4b268e0d648634f
Enrichment time
2026-05-24T07:26:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Lawmakers Demand Answers as CISA Tries to Contain Data Leak · Baitaphish