CISA Administrator Exposed AWS GovCloud Credentials on Public GitHub
Key Takeaways Highly sensitive U.S. government cloud credentials, including AWS GovCloud access keys and plaintext passwords, were publicly exposed on GitHub. The exposure originated from a...
Key Takeaways
- Highly sensitive U.S. government cloud credentials, including AWS GovCloud access keys and plaintext passwords, were publicly exposed on GitHub.
- The exposure originated from a contractor working with CISA, who inadvertently published the data in a public repository named “Private-CISA.”
- The exposed data included administrative credentials for multiple AWS GovCloud environments and access to CISA’s internal systems, posing a significant supply chain risk.
- The repository was taken down, but some credentials remained valid for nearly 48 hours post-disclosure, and CISA is investigating with no evidence of active exploitation found yet.
CISA Contractor Exposes Critical AWS GovCloud Credentials on Public GitHub
In a significant cybersecurity incident, a contractor affiliated with the Cybersecurity and Infrastructure Security Agency (CISA) inadvertently uploaded highly sensitive U.S. government cloud credentials and other proprietary data to a public GitHub repository. This lapse has potentially exposed critical infrastructure details and internal system access.
Table Of Content
The repository, titled “Private-CISA,” contained a trove of confidential information, including AWS GovCloud credentials, unencrypted passwords, API tokens, and various internal system specifics. It remained accessible to the public until mid-May 2026, raising serious concerns among security experts.
Industry researchers are categorizing this event as one of the most severe government-related data exposures observed in recent years, highlighting the profound implications of such a breach.
Discovery and Initial Response
The exposure was initially detected by Guillaume Valadon, a researcher at GitGuardian, a firm specializing in scanning public repositories for leaked secrets. Valadon described the information within the repository as “extremely sensitive” and reported initial difficulties in alerting the owner about the vulnerability.
Following the initial discovery, the findings were escalated and subsequently shared with KrebsOnSecurity, which prompted a deeper investigation into the extent of the exposure.
Details of the Exposed Data
Analysis of the “Private-CISA” repository confirmed that it contained administrative credentials for at least three distinct AWS GovCloud environments. These environments are specifically designed to host and manage sensitive U.S. government workloads, underscoring the gravity of the exposure.
Further examination revealed a file named “AWS-Workspace-Firefox-Passwords.csv,” which contained dozens of plaintext usernames and passwords. These credentials were linked to various internal CISA systems, including a DevSecOps environment identified as “LZ-DSO.”
Philippe Caturegli, founder of the security consultancy Seralys, independently verified that some of the exposed AWS credentials remained active and provided high-level access at the time of their discovery. Caturegli also noted the presence of credentials for CISA’s internal “artifactory,” a central system used for managing and distributing software components. Compromise of such a system could enable threat actors to inject malicious code into software pipelines, potentially affecting numerous systems during deployment.
Researchers also pointed to significant security deficiencies within the repository. Sensitive data was stored without encryption, and crucially, GitHub’s native secret scanning protections had been intentionally disabled. Commit logs suggest the repository may have been used more as a personal file synchronization tool or a temporary workspace rather than a securely managed development project.
“The patterns indicate this was likely used to sync files between different machines, possibly a work and home environment,” Caturegli explained, adding that such usage “doesn’t reduce the severity it actually makes it worse.”
Contractor Link and CISA’s Response
Reports indicated that the exposed repository was associated with a contractor from Nightwing, a U.S.-based government services firm. The contractor’s GitHub account had been active since 2018, with the “Private-CISA” repository itself being created in November 2025.
Although the repository was promptly removed following public disclosure, the exposed AWS credentials reportedly remained valid for nearly 48 hours afterward, extending the window of potential risk.
CISA has acknowledged the incident and initiated an active investigation. The agency stated that, as of now, there is no evidence suggesting active exploitation of the exposed credentials. However, CISA emphasized that additional security measures are being implemented to mitigate any potential future risks.
This incident occurs amid reports of significant workforce reductions at CISA, attributed to budget cuts and restructuring. Security experts caution that such operational pressures can elevate the risk of human error and security misconfigurations.
The overall event serves as a stark reminder that even organizations at the forefront of national cybersecurity must maintain rigorous security practices, particularly concerning credential management and secure development workflows, to prevent basic errors from leading to critical compromises.
What You Should Do
- Implement Automated Secret Scanning: Ensure all code repositories, especially those handling sensitive data, are continuously scanned for exposed credentials and secrets using automated tools.
- Enforce Strong Access Controls: Regularly audit and enforce least privilege principles for all cloud and internal system access.
- Mandate Multi-Factor Authentication (MFA): Require MFA for all accounts, especially those with administrative privileges, to add an extra layer of security.
- Conduct Regular Security Training: Educate contractors and employees on secure coding practices, data handling, and the dangers of exposing sensitive information in public repositories.
- Rotate Credentials Frequently: Implement a policy for regular rotation of API keys, passwords, and other credentials, especially after any suspected exposure.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.