Last updated 1 month ago
The United States Cybersecurity and Infrastructure Security Agency (CISA), a government agency, suffered a data leak when a contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account. The breach was publicly disclosed in May 2026, though the exact discovery date is not specified. The full scope of exposed data and number of affected records remains undisclosed.
The attack vector was an insider threat: a CISA contractor deliberately leaked sensitive credentials and secrets to a public GitHub repository. The exposed data includes AWS GovCloud keys and other unspecified agency secrets, which could enable unauthorized access to critical government cloud infrastructure. No specific threat actor group or individual has been named, and no CVEs are referenced.
Lawmakers in both houses of Congress are demanding answers from CISA as the agency struggles to contain the breach and invalidate the leaked credentials. No further details on regulatory actions, litigation, or remediation milestones have been reported.
Contractor intentionally published AWS GovCloud keys and other secrets on a public GitHub account
This breach underscores the critical need for strict access controls and monitoring of contractor activities, especially for privileged credentials like AWS GovCloud keys. CISA's failure to prevent an insider from exfiltrating and publishing secrets on a public repository highlights gaps in data loss prevention (DLP) and user behavior analytics (UBA) for privileged users. Organizations should enforce least-privilege access, implement robust DLP for code repositories, and conduct regular audits of contractor access to sensitive systems.
Sign in to join the discussion.
Company
Industry
Location
Disclosed
Records Affected
Attack Vector
Continent
Country
Industry
Attack Vector
MITRE ATT&CK