Lawmakers Demand Answers as CISA Tries to Contain Data Leak
2026-05-24T07:26:50Z•490b71a380fa7184b8457fbdbb6be7c02230891b567a6c36f4b268e0d648634f
AWS GovCloudBlueHammerCISACanvasDDoSGandCrabGitHub leakIoT botnetKimwolfMicrosoft Office tokensREvilRussian state-backed actorsSharePointarrestcongressional inquirycredential exposuredata extortiondata leakeducation sectorincident responselaw enforcementpatch tuesdayransomwarerouter exploitzero-day
What happened
Multiple high-impact incidents reported: a CISA contractor publicly published AWS GovCloud credentials and extensive internal CISA secrets on a GitHub repository, triggering an ongoing containment effort and bipartisan congressional inquiries. A 23-year-old Ottawa man alleged to be the Kimwolf botnet operator (“Dort”) was arrested and charged in Canada and the U.S.; the botnet is linked to massive IoT-based DDoS activity. The Canvas education platform suffered a data extortion attack threatening the personal data of ~275 million students and faculty across ~9,000 institutions, causing wide-dis
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 490b71a380fa7184b8457fbdbb6be7c02230891b567a6c36f4b268e0d648634f
- Enrichment time
- 2026-05-24T07:26:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.