Lawmakers Demand Answers as CISA Tries to Contain Data Leak
2026-05-24T13:23:27Z•95713537d1362ab5e1fc47710be14ddb4fe6b87df1ea848bbfe8f0a1f447e17e
AWS GovCloudCISACanvasDDoSGitHubIoT-botnetKimwolfMicrosoft-Office-tokensScattered-Spidercongressional-inquirycontractor-securitycredential-leakdata-breachdata-extortioneducation-sectorinsider-threatpatch-tuesdayransomwarerouter-compromisevulnerabilitieszero-day
What happened
Multiple KrebsOnSecurity reports detail a major data-exposure incident in which a CISA contractor publicly posted highly privileged AWS GovCloud credentials and extensive internal agency secrets on a GitHub repository, forcing CISA to scramble to contain the leak, invalidate credentials and answer congressional inquiries. The feed also highlights related high-impact incidents: the arrest of an alleged Kimwolf IoT botnet operator tied to large-scale DDoS activity; a widespread Canvas education-platform data-extortion incident affecting millions of students and staff; and multiple large-scale/vw
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- krebs_on_security
- Record identifier
- 95713537d1362ab5e1fc47710be14ddb4fe6b87df1ea848bbfe8f0a1f447e17e
- Enrichment time
- 2026-05-24T13:23:27Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.