Vulnerabilities

Leaked AWS Keys Expose Corporate Accounts

August 22, 2026 12:05 · 12 min read
Leaked AWS Keys Expose Corporate Accounts

Massive Leak of AWS Keys Puts Corporate Accounts at Risk

A recent discovery by Truffle Security has revealed that more than 9,300 Amazon Web Services (AWS) access keys have been publicly exposed between August 2022 and August 2026, with 817 of these keys linked to companies. This includes 526 AWS root keys, which have full permissions to create, modify, delete, and view virtually all AWS services and resources within an account.

Truffle Security has been tracking this exposure for the past four years and found that 242 of the keys are associated with Identity and Access Management (IAM) users with the AdministratorAccess policy, giving attackers full control over a company's AWS account. This could allow an attacker to access, exfiltrate, or wipe cloud-hosted data, take control of servers and applications, and create rogue admin accounts for persistent access.

Consequences of Leaked AWS Keys

The exposure of these keys could have severe consequences, including the deployment of cryptominers, which could generate substantial charges for the company. Furthermore, threat actors could use their access to deploy malware, compromise sensitive data, or disrupt business operations.

According to Truffle Security, only 262 of 2,754 readable accounts had a budget alert set up, leaving many companies vulnerable to potential abuse. The largest single source of leaked AWS keys was Hugging Face, a popular online platform where developers share AI models, datasets, and applications, accounting for 8,482 unique key exposures.

Age and Rotation of Exposed AWS Keys

Truffle Security found that, for the 2,903 keys with available creation dates, the median age was 1,831 days (about five years), while the oldest had existed for 17.4 years. Only 398 (13.7%) of those entries had a newer access key associated with the same user, suggesting that most had never been rotated.

This highlights the importance of regularly rotating and revoking access keys to prevent unauthorized access. Companies should also configure budget alerts to detect and respond to potential abuse.

Recommendations and Response

To defend against potential abuse, Truffle Security recommends deleting all root access keys, reviewing IAM credentials by age, rotating or revoking exposed keys, and configuring budget alerts. Any credential committed to a public source should be treated as compromised.

Amazon Web Services (AWS) has stated that it notifies affected customers when it becomes aware of exposed keys and thoroughly investigates all reports of exposed keys. AWS encourages customers to follow security, identity, and compliance best practices and provides resources to help customers secure their cloud resources.

Anytime AWS is aware of exposed keys, we notify the affected customers. We also thoroughly investigate all reports of exposed keys and quickly take any necessary actions, such as applying quarantine policies to minimize risks for customers without disrupting their IT environment.

AWS spokesperson

Conclusion

The leak of AWS keys highlights the importance of cloud security and the need for companies to take proactive measures to protect their cloud resources. By following best practices, regularly rotating access keys, and monitoring for potential abuse, companies can reduce the risk of unauthorized access and protect their sensitive data.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free