Cybersecurity

Hundreds of Leaked AWS Keys Grant Full Control Over Company Accounts

Truffle Security found that more than 9,300 AWS access keys remained active and usable after being publicly exposed, including root keys and accounts with full administrative privileges. This exposure could allow attackers to access data and servers, create hidden accounts, or run mining tools that increase companies’ costs.

2026-08-21
3 min read
10 views
فريق تحرير certi.news
Hundreds of Leaked AWS Keys Grant Full Control Over Company Accounts

More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 remained active and capable of authenticating, according to four years of tracking by Truffle Security. Among the exposed keys, 817 were associated with companies, including 526 root keys that grant the highest level of privileges within an AWS account.

Researchers said another 242 keys were associated with users in the Identity and Access Management (IAM) service who had the AdministratorAccess policy. This policy allows users to create, modify, delete, and view nearly most AWS services and resources. They also noted that every one of the 768 live keys in two examined groups granted “full control over a company’s AWS account.”

Scope of the Exposure and Sources of the Keys

Truffle Security found 431,875 AWS-related secrets in code repositories, Git history, datasets, Docker images, container logs, and continuous integration and delivery (CI) logs. After removing duplicates, the number fell to 64,024 unique keys belonging to 50,654 AWS accounts.

The group for which complete credentials were available for revalidation included 10,616 keys. Of these, 88% were still capable of authenticating as of August 10. Hugging Face, where developers share artificial intelligence models, datasets, and applications, was the single largest source of leaked keys, associated with 8,482 unique exposures. Root keys accounted for 17.9% of these cases.

What Changes in Practice?

Depending on the associated level of privileges, a valid key allows an attacker to access, extract, or delete cloud-hosted data; take control of servers and applications; and create hidden administrative accounts to maintain access. The accounts may also be used to deploy cryptocurrency-mining tools, which could result in high bills for the company. Of the 2,754 accounts whose data could be read, only 262 had a budget alert enabled.

The ages of the keys reveal an additional problem in credential management: among 2,903 keys for which creation dates were available, the median age was 1,831 days, or about five years, while the oldest key was 17.4 years old. Only 398 cases, or 13.7%, had a newer access key associated with the same user, indicating that most keys had not been rotated.

Risk-Mitigation Measures

Truffle Security recommends deleting all root keys, reviewing IAM credentials based on their age, rotating or revoking exposed keys, and enabling budget alerts. Any credentials committed to a public source should also be treated as compromised, even if there is no evidence that they were actually used.

The company said its testing was limited to reading metadata and that it notified all credential owners who could be identified. The significance of the findings is that a key remaining active after appearing publicly can turn an old leak in a repository or build log into a direct entry point to cloud infrastructure.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news