Lawmakers Demand Answers as CISA Tries to Contain Data Leak

2026-05-23T13:23:26Zf668d4c68be25569905a793bd11719f6804122fe9140abbfb9902a74e704550c
anti-ddos abuseaws govcloudbluehammercanvaschrome zero-daycisacongressional inquirycredentials exposuredata breachdata extortionddosdoxingeducation breachgithub leakincident responseiot botnetkimwolflaw enforcementmicrosoft office tokenspatch tuesdayransomware gangs','revil','gandcrabrouter exploitscattered spiderswattingzero-day

What happened

KrebsOnSecurity reports a string of high-impact incidents: a CISA contractor intentionally published highly privileged AWS GovCloud credentials and extensive internal documentation to a public GitHub repository, triggering an ongoing containment effort, credential invalidation challenges and bipartisan Congressional inquiries. Related coverage in the feed includes the arrest of the alleged Kimwolf botmaster (IoT botnet used for massive DDoS, doxing and swatting), a large-scale Canvas data-extortion/defacement incident threatening ~275 million student and faculty records, a Russian campaign hij

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
krebs_on_security
Record identifier
f668d4c68be25569905a793bd11719f6804122fe9140abbfb9902a74e704550c
Enrichment time
2026-05-23T13:23:26Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Lawmakers Demand Answers as CISA Tries to Contain Data Leak · Baitaphish