securityonline.info 8/21/2026, 12:26:40 PM · external

Over 64,000 AWS keys leaked in public repositories

Over 64,000 AWS keys leaked in public repositories
CyberSIXT Evidence Panel
Primary Source trufflesecurity.com

SECURITY researchers have detected significant leaks of corporate AWS access keys and credentials, affecting over 9,900 AWS accounts, including 768 corporate environments. A total of 64,024 AWS access key pairs were identified, with 10,625 being root account keys. The exposure primarily occurred due to inadvertent commits to public repositories and datasets, particularly on machine learning platforms. Most leaked credentials had not been rotated, with 86% of them remaining unrevoked.

Consequences of the leaks could lead to substantial unauthorized cloud spending. Security teams are urged to review and delete compromised keys, set strict rotation policies, and configure alerts for unusual billing activities. Truffle Security has coordinated notifications to affected account owners.

View Primary Source Via securityonline.info

Article by CyberSIXT