CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

CISA Admin Leaked AWS GovCloud Keys on Github

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 138

As cited

Copy frozen at (site build).

breaches incidents

CISA Admin Leaked AWS GovCloud Keys on Github

A CISA contractor maintained a public GitHub repository that exposed privileged AWS GovCloud credentials, plaintext passwords, API tokens, and internal system details for several months until security researchers alerted the agency in May. The exposed files included administrative access to cloud infrastructure, credentials to CISA's secure code development environment, and access to internal software repositories, representing significant credential mismanagement and disabled security controls. Security experts characterized the incident as one of the most severe government data leaks in recent history due to the sensitivity of exposed assets and potential for lateral movement attacks.

Why it matters: Exposed GovCloud credentials and internal development system access create immediate risk of unauthorized access to critical infrastructure security tools and persistent backdoor opportunities in CISA's software supply chain.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

CISA Admin Leaked AWS GovCloud Keys on Github

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) publicly exposed highly privileged AWS GovCloud credentials, plaintext passwords, tokens, and internal deployment documentation on GitHub until May 15, 2026. The repository, named Private-CISA, contained credentials for multiple AWS GovCloud accounts and CISA systems including the Landing Zone DevSecOps environment, with evidence that the repository operator had manually disabled GitHub's built-in secret detection feature. Security researchers determined the exposed credentials retained valid access to critical infrastructure and internal code repositories, creating a significant pathway for attackers to establish persistence within CISA systems.

Why it matters: Federal agencies and contractors must audit their developers' GitHub accounts and enforce mandatory secret-scanning tools, as this exposure demonstrates how credential hygiene failures can compromise government infrastructure and create lasting backdoor opportunities for adversaries.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

breaches incidents

CISA Admin Leaked AWS GovCloud Keys on Github

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) publicly exposed highly privileged AWS GovCloud credentials, plaintext passwords, tokens, and internal deployment documentation on GitHub until May 15, 2026. The repository, named Private-CISA, contained credentials for multiple AWS GovCloud accounts and CISA systems including the Landing Zone DevSecOps environment, with evidence that the repository operator had manually disabled GitHub's built-in secret detection feature. Security researchers determined the exposed credentials retained valid access to critical infrastructure and internal code repositories, creating a significant pathway for attackers to establish persistence within CISA systems.

Why it matters: Federal agencies and contractors must audit their developers' GitHub accounts and enforce mandatory secret-scanning tools, as this exposure demonstrates how credential hygiene failures can compromise government infrastructure and create lasting backdoor opportunities for adversaries.

VendorsGoogleAmazon Web ServicesGitHub
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary