Mon, 13 Jul 2026
← BackThe Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb. On May 15, 2026, the security firm GitGuardian asked for help in notifying CISA about the existence of a public GitHub repository called “Private CISA” that included 844 MB of sensitive CISA-related data. One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers.
Another file — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. CISA quickly acknowledged our initial alert, but took more than 48 hours to invalidate the AWS keys and many other important secrets leaked in the GitHub repo. In its report on the data leak, CISA said the complexities of the agency’s systems and interconnections with federal and industry partners caused its key rotation to take longer than anticipated. “Drawing on this experience, CISA encourages others to maintain mature and well-tested key management capabilities,” the report notes.
CISA also admitted it can do better when it comes to responding to security incident notifications from...
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a recent data leak in which a contractor published dozens of internal CISA credentials — including AWS Govcloud keys — in a public GitHub repository for almost six months before being notified by KrebsOnSecurity. Experts say the gaps identified in the agency’s initial response provide important lessons that all security teams should absorb. On May 15, 2026, the security firm GitGuardian asked for help in notifying CISA about the existence of a public GitHub repository called “Private CISA” that included 844 MB of sensitive CISA-related data. One of the exposed files, titled “importantAWStokens,” included the administrative credentials to three Amazon AWS GovCloud servers.
Another file — “AWS-Workspace-Firefox-Passwords.csv” — listed plaintext usernames and passwords for dozens of internal CISA systems. CISA quickly acknowledged our initial alert, but took more than 48 hours to invalidate the AWS keys and many other important secrets leaked in the GitHub repo. In its report on the data leak, CISA said the complexities of the agency’s systems and interconnections with federal and industry partners caused its key rotation to take longer than anticipated. “Drawing on this experience, CISA encourages others to maintain mature and well-tested key management capabilities,” the report notes.
CISA also admitted it can do better when it comes to responding to security incident notifications from external parties. The postmortem stresses that clear and distinct reporting channels are essential to ensure that incidents affecting the organization itself are handled differently from those involving its products or customers. “In CISA’s case, these channels were not well defined, leading the security researcher to try multiple avenues – including emailing the contractor, submitting through CISA’s vulnerability disclosure platform (which is intended for vulnerabilities impacting the broader cybersecurity community), and ultimately involving a reporter,” reads the analysis written by Preston Werntz and Brad Libbey, the acting chief information officer and acting chief information security officer at CISA, respectively. CISA said it is refining its reporting channels to make them easier and faster for researchers.
“Additionally, while many researchers rely on the security.txt file, organizations can ensure clarity by publishing reporting instructions in multiple prominent locations,” the CISA authors wrote. Guillaume Valadon, the GitGuardian researcher who first contacted KrebsOnSecurity about the exposed CISA credentials, said CISA ignored nine automated alerts about the exposed credentials prior to our notification on May 15. Valadon’s company constantly scans public code repositories at GitHub and elsewhere for exposed secrets, automatically alerting the offending accounts of any apparent sensitive data exposures. “Letting nine notification emails go unanswered is how a one-day incident becomes a six-month exposure,” Valadon wrote in an analysis of CISA’s report.
“Make it trivial to report a leak about you, not just about your products. The person reporting a leak to you is not the threat. Publish a security.txt, but do not stop there. Put reporting instructions in several prominent places, and make sure a report about your own infrastructure does not land in a product-bug queue.” The report’s authors also emphasized the importance of continuously scanning public code repositories like GitHub for exposed secrets, and said CISA has since rotated all secrets and created an action plan to improve management of developer secrets and to better monitor for them going forward.
The report notes that while CISA had developed a playbook for responding to cybersecurity incidents, that playbook somehow didn’t include what to do in situations involving GitHub or other cloud services. Valadon said the report validates the need to scan continuously — not just quarterly — for exposed secrets. “The Private-CISA repository sat public for six months,” Valadon wrote. “Continuous monitoring of public GitHub surfaced it.
Comprehensive internal scanning could have caught the plaintext passwords and committed backups long before they left the building.” CISA gave itself passing grades on several areas of security preparedness that it said helped the agency gauge the scope and impact of the exposed secrets, including enhanced logging capabilities, and the adoption of zero-trust principles in both its production and development systems. CISA said those detailed logs allowed it to show that no customer or mission data was exposed, and that the leaked credentials were not used outside of CISA’s environments. The agency said the contractor who exposed the secrets had their system access revoked. Valadon reckons the biggest takeaway is the CISA postmortem itself, and praised the agency for being transparent about what worked and what didn’t.
“To my knowledge, it is also the first time a national cybersecurity agency has publicly advocated for secrets scanning and for simplifying relations with security researchers,” Valadon wrote. “That is exactly the incident communication we should expect from every organization.” This entry was posted on Monday 13th of July 2026 11:03 AM The government will always condone and positively critique its own behavior. Some bureaucrat(s) should at least lose their job and pensions as a result of this egregious fubar. Unfortunately, so many people have been culled at CISA and other agencies by the orange-faced buffoon there aren’t enough people left to do the job properly.
Firing those who are already overworked and underpaid isn’t the answer. Yes, this incident was preventable and should have been caught sooner, but when your bosses boss changes priorities to make sure that national security takes a back seat to them making money these things happen. I’m surprised we didn’t print out that importantAWStokens text file and kept it in a cardboard box in a Mar A Lago bathroom. What else can you expect from the current government?
I dunno about you, but I kind of don’t think it is a terrible idea to keep some printouts of keys offline in a safe place somewhere. Too many disk meltdowns and outages to not know how that can go. Thanks, Brian. There’s a reason I still read you daily, even though I retired from my sysadmin job in ’19.
The root cause is the overuse of contractors. A long time ago, contractors were hired as experts for short-term projects where the regular staff had knowledge gaps. More recently, contractors are hired to avoid having regular staff. Regular staff had low turnover rates.
Contractors have very high turnover rates. And now, many contractors are far from experts, they are closer to young and inexperienced. Whatever the staffing company can get. Young and inexperienced people should not be handling large files of sensitive data.
Managers used to be responsible for their staff. Do DOGE cuts have any impact on this event? Would this happen have happened in earlier times? I agree with you, john.
I think the recent DOGE cuts DID have something to do with it. I read morale was low and the people working there have had their workloads increased. wow If anybody out there in United States still think that any government agency in this country can keep any secrets about anything anymore. Let me dissuade you of that idea.
Anything you share with the government will always be hacked and shared with the rest of the world. There are no secrets. If anybody thinks the Russians, the Chinese the North Koreans don’t know everything that goes on in this country with all our companies and the government is living in delusion land. lol, You do understand that the Russians, Chinese, North Koreans and ALL others have the exact same issue that we have.
Too much information and no one to look at it. They may, occasionally, have a vague clue at what they are seeing. But mostly move past, if they ever see it. “Another file — ‘AWS-Workspace-Firefox-Passwords.csv’ — listed plaintext usernames and passwords for dozens of internal CISA systems.” The bar is in hell and we’re still faceplanting “security.txt” is referenced in this post as well as in a previous post to this blog (https://krebsonsecurity.com/2021/09/does-your-organization-have-a-security-txt-file/).
As a former implementer of websites with 100,000+ daily unique visitors, I find the idea very positive. A quick search shows that some leading tech companies indeed have a security.txt page–terrific! This website feels like it should be setting an example or practicing what it preaches. But I can’t find a security.txt page on the site.
What am I missing? [May I have a bug bounty, please 🙂 ] I think this incident shows that even organizations with strong security frameworks can be undermined by slow operational response. To me, the biggest lesson is that continuous monitoring and a clear reporting process are just as important as technical defenses. A mature security program should make it easy to detect, report, and remediate exposed secrets before they become long-term risks.
Very good to be informed of things like this. With the rapidly dwindling availability of trustworthy reporters to provide cogent reports on things of this nature, Mr. Krebs continues to shine a light in the darkened streets and alleys of the underbelly of the information parking lots of the world. Your email address will not be published.
Required fields are marked * Comment * Name * Email * Website Δ Mailing List Search KrebsOnSecurity Recent Posts Story Categories Why So Many Top Hackers Hail from Russia