https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights

Truffle Security has published findings from four years of tracking publicly exposed Amazon Web Services access keys, revealing that more than 9,300 keys exposed between August 2022 and August 2026 remain active and valid. Across that period the firm identified 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries, and CI logs, extracting 64,024 unique AWS keys corresponding to 50,654 AWS accounts after deduplication. Of the 10,616 keys for which complete credentials were available for re-verification, 88 percent continued to authenticate as of 10 August 2026. Of the broader set of exposed keys, 817 were linked to companies, 526 of those being AWS root keys carrying the highest privilege level and unrestricted by IAM permissions policies. A further 242 keys were associated with IAM users holding the AdministratorAccess policy, a role granting full permissions to create, modify, delete, and view virtually all AWS services and resources within an account. Truffle Security assessed that each of the 768 live keys across these two categories provided full control of a company’s AWS account.

Amazon Web Services responded with a statement confirming that it notifies affected customers whenever it becomes aware of exposed keys, investigates all reports, and may apply quarantine policies to minimise risk without disrupting customer environments. AWS reiterated its shared responsibility model and directed customers who suspect credential exposure to follow published remediation steps and contact AWS Support.

Discover more from Edwin Kwan

Subscribe now to keep reading and get access to the full archive.

Continue reading