CISA Admin Leaked AWS GovCloud Keys on Github
A contractor working for CISA left highly privileged AWS GovCloud credentials and internal system details exposed in a public GitHub repository until this past weekend. Security experts described the leaked archive, which included details about how the agency builds and deploys its own software, as one of the most serious government data exposures in recent memory.
Why this matters: CISA is the federal agency responsible for protecting critical infrastructure and government systems from exactly this kind of mistake. A contractor left the keys to privileged government cloud accounts sitting in a public repository. Anyone who found it first could have had broad access to internal systems before anyone noticed. That is not a minor slip. It is a fundamental failure of basic credential hygiene at the agency whose job is to set the standard. The bigger problem is accountability: when a contractor causes a breach this serious, it is rarely clear who actually answers for it.
Who should care: Cybersecurity · Privacy officers · Administrators
This summary is AI-assisted and may contain errors. It is an original briefing to help you gauge significance quickly — not a reproduction of the source. Always read the linked original before relying on it. See our methodology.