Skip to main content
Back to overview
Medium

CISA Contractor Leaks AWS GovCloud Keys and Internal Credentials on Public GitHub

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal…

Key points

  • CISA contractor exposed credentials on a public GitHub repository.
  • Exposed data included AWS GovCloud keys and internal CISA system credentials.
  • Repository contained plaintext passwords, cloud keys, tokens, and internal files.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

03

Potential impact

Data Exposure

Confidentiality

Published
May 15, 2026
Updated
Jun 29, 2026
Confidence
Medium
Evidence
2 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Error activity

Watch process controls, misconfiguration and accidental disclosure paths.

  • Source type: possible insider or internal misuse

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

CisaData DisclosureCISA Contractor Leaks AWS GovCloudKeys and Internal CredentialsPublic GitHub ACybersecurityCISAGitHubAWS GovCloudGitGuardian

Quick context

Questions about this signal

What happened in this signal?

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public GitHub repository that exposed credentials to several highly privileged AWS GovCloud accounts and a large number of internal CISA systems. The exposure was flagged by GitGuardian on May 15, 2026, and reported to KrebsOnSecurity. The repository, named 'Private-CISA,' contained plaintext credentials, cloud keys, tokens, and internal CISA files, exposed since November 2025. CISA acknowledged the leak and took the repository offline.

When was this signal reported?

Shadow Tier lists May 15, 2026 as the signal date.

Which organization is connected to this signal?

Cisa is the organization connected to this public signal.

Explore Cisa
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence