www.infosecurity-magazine.com 8/24/2026, 8:21:19 AM · external

Over 9,300 Active AWS Keys Leaked, Many With Full Admin Rights

Over 9,300 Active AWS Keys Leaked, Many With Full Admin Rights

SECURITY researchers at Truffle Security have identified over 9,300 leaked AWS keys still active, many of which include full admin rights. These keys were found across various public datasets and repositories, with a significant number remaining in use despite not being rotated or secured with alerts. The researchers found that almost 88% of the examined keys still authenticate, highlighting a major security risk as such keys could be exploited for actions like data theft or unauthorized installations.

Truffle Security has urged organizations to improve key management practices, including deleting root access keys, setting up budget alerts, and treating exposed keys as compromised. This situation underlines the importance of stringent security practices in cloud management.

View full article

Article by CyberSIXT