CISA Credential Leak Exposes AWS Govcloud Keys in Public GitHub Repository
Postmortem reveals contractor accidentally published internal credentials for nearly six months before external discovery

Key Takeaways
- A CISA contractor accidentally published internal credentials, including AWS Govcloud keys, to a public GitHub repository.
- The repository remained accessible for approximately six months before external discovery.
- KrebsOnSecurity notified CISA of the leak in July 2026.
- CISA's postmortem identifies gaps in secret management and access control practices.
- The incident underscores the need for enhanced credential rotation, secret scanning, and access review policies.
Quick answers
- What happened?
- A contractor for the Cybersecurity and Infrastructure Security Agency inadvertently published dozens of internal CISA credentials, including AWS Govcloud keys, in a public GitHub repository. The exposure remained undetected for approximately six months until KrebsOnSecurity notified CISA in July 2026. The agency's subsequent postmortem identifies significant gaps in secret management and access controls.
- Which products are affected?
- CISA internal systems, AWS Govcloud environment
- What should defenders do?
- CISA postmortem recommendations likely include credential rotation, implementation of Git secret scanning tools, access control reviews, and enhanced internal policies for managing sensitive credentials. Specific remediation steps require verification from official CISA statements.
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem analysis regarding a significant credential leak involving internal agency keys. According to reporting by KrebsOnSecurity, a contractor for CISA accidentally published dozens of internal credentials, including AWS Govcloud keys, to a public GitHub repository. The repository remained publicly accessible for nearly six months before being discovered by external researchers.
KrebsOnSecurity reported that the leak was identified in July 2026, prompting CISA to publish a detailed postmortem examining the incident. The exposure included sensitive cloud credentials that could potentially grant access to government AWS Govcloud environments. The length of exposure -- approximately six months -- has raised concerns among security experts about the agency's secret management practices and internal access controls.
The postmortem, issued on July 13, 2026, outlines the circumstances that led to the credentials being published and identifies gaps in CISA's initial response. Security analysts note that the incident provides broader lessons for security teams regarding the detection and prevention of accidental credential exposure in code repositories.
As of the postmortem publication, CISA had not confirmed whether the exposed credentials had been actively exploited, though the six-month exposure window presents a potential risk of misuse by threat actors who may have discovered the keys during that period.
Security Details
Exposure of internal CISA credentials and AWS Govcloud keys in a public GitHub repository for approximately six months. Potential unauthorized access to government cloud resources.
Affected products
CISA internal systems, AWS Govcloud environment
Mitigation
CISA postmortem recommendations likely include credential rotation, implementation of Git secret scanning tools, access control reviews, and enhanced internal policies for managing sensitive credentials. Specific remediation steps require verification from official CISA statements.
Sources
Krebs on Security
Lessons Learned from CISA’s Recent GitHub Leak
Jul 13, 2026 · 15:03
Original link
Related Security News
CISA Adds Two Citrix NetScaler Vulnerabilities to Known Exploited Catalog
The Cybersecurity and Infrastructure Security Agency (CISA) has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation. CVE-2026-88771 involves improper input validation and CVE-2026-88772 involves improper restriction of operations within the bounds of a memory buffer, both affecting Citrix NetScaler products. The additions trigger remediation requirements under Binding Operational Directive 26-04 for Federal Civilian Executive Branch agencies.



_Dzmitry_Skazau_Alamy.jpg?width=720&quality=80&disable=upscale)