Lawmakers Demand Answers as CISA Tries to Contain Data Leak

2026-05-24T13:23:27Z95713537d1362ab5e1fc47710be14ddb4fe6b87df1ea848bbfe8f0a1f447e17e
AWS GovCloudCISACanvasDDoSGitHubIoT-botnetKimwolfMicrosoft-Office-tokensScattered-Spidercongressional-inquirycontractor-securitycredential-leakdata-breachdata-extortioneducation-sectorinsider-threatpatch-tuesdayransomwarerouter-compromisevulnerabilitieszero-day

What happened

Multiple KrebsOnSecurity reports detail a major data-exposure incident in which a CISA contractor publicly posted highly privileged AWS GovCloud credentials and extensive internal agency secrets on a GitHub repository, forcing CISA to scramble to contain the leak, invalidate credentials and answer congressional inquiries. The feed also highlights related high-impact incidents: the arrest of an alleged Kimwolf IoT botnet operator tied to large-scale DDoS activity; a widespread Canvas education-platform data-extortion incident affecting millions of students and staff; and multiple large-scale/vw

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
95713537d1362ab5e1fc47710be14ddb4fe6b87df1ea848bbfe8f0a1f447e17e
Enrichment time
2026-05-24T13:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Lawmakers Demand Answers as CISA Tries to Contain Data Leak · Baitaphish