Hundreds of leaked AWS keys give full control over corporate accounts

This title could be clearer and more informative.Try out Clickbait Shieldfor free (5 uses left this month).

Truffle Security found over 9,300 publicly exposed AWS access keys, spanning August 2022 to August 2026, that remain active and valid. Of those, 817 belong to companies, with 526 being root keys and 242 tied to AdministratorAccess IAM users, giving attackers full account control. The keys were scraped from code repos, Docker images, CI logs, and datasets, with Hugging Face being the single largest source at 8,482 unique exposures. Most keys were never rotated, median age around five years, and only a small fraction of accounts had budget alerts configured to catch abuse like cryptomining. Researchers recommend deleting root keys, rotating exposed credentials, and treating any publicly committed credential as compromised.

3m read timeFrom bleepingcomputer.com
Post cover image
Table of contents
Related Articles:

Questions this post answers

How many leaked AWS access keys are still active and giving full account control?

Security researchers tracking exposed AWS credentials over four years found more than 9,300 leaked keys still active and valid, with 817 tied to corporate accounts and 526 of those being root keys. Another 242 belonged to IAM users with AdministratorAccess, and 768 live keys across these sets granted full control of a company's AWS account. Teams auditing cloud credential exposure follow AWS security incidents like this on daily.dev.

Why was Hugging Face the largest source of leaked AWS keys?

Hugging Face accounted for 8,482 unique AWS key exposures, the single largest source found across code repositories, Git history, datasets, Docker images, registries, and CI logs, with 17.9% of those being root credentials that bypass IAM permission restrictions entirely. Developers sharing models and datasets track secrets-scanning findings like this on daily.dev.

How old are typical leaked AWS keys and are they ever rotated?

Among keys with known creation dates, the median age was about 1,831 days, roughly five years, and the oldest had existed for 17.4 years. Only 13.7% had a newer access key tied to the same user, indicating most exposed credentials were never rotated after being leaked. Engineers reviewing credential rotation policies keep tabs on findings like this on daily.dev.

452 Impressions