Thousands of Leaked AWS Access Keys Grant Full Control Over Corporate Accounts, Exposing Sensitive Data and Operations to Malicious Actors

A staggering number of Amazon Web Services (AWS) access keys, totaling over 9,300, have been found to be publicly exposed and remain active and valid, posing a significant security risk to numerous organizations. Truffle Security, a cybersecurity firm specializing in cloud security, has been meticulously tracking this ongoing exposure over the past four years, revealing a disturbing trend of compromised credentials that grant attackers unfettered access to corporate cloud infrastructure. The firm’s latest analysis highlights that 817 of these exposed keys are linked to companies, with a particularly alarming 526 identified as AWS root keys, the most powerful access credentials within an AWS account. Further investigation by Truffle Security indicates that 242 of these compromised keys are associated with Identity and Access Management (IAM) users possessing the "AdministratorAccess" policy, a designation that bestows complete authority to manage virtually all AWS services and resources.

The implications of such widespread credential exposure are dire. Each of the 768 live keys identified within two specific datasets examined by researchers effectively grants "full control of a company’s AWS account." This level of access allows malicious actors to perform a wide range of destructive and exploitative actions, including the unauthorized access, exfiltration, or outright deletion of critical cloud-hosted data. They can seize control of servers and applications, establish persistent backdoors by creating rogue administrator accounts, and even leverage compromised resources for illicit activities such as cryptocurrency mining, which can incur substantial financial penalties for the affected organizations. Truffle Security’s findings underscore the severity of this vulnerability, noting that out of 2,754 readable accounts, a mere 262 had implemented budget alerts, leaving many organizations blind to the escalating costs associated with unauthorized resource usage.

The scope of the data leakage is extensive. Truffle Security’s comprehensive scan uncovered 431,875 AWS secrets scattered across various digital repositories, including code repositories, Git history, datasets, Docker images, registries, and continuous integration (CI) logs. From this vast pool of exposed information, the researchers successfully extracted 64,024 unique AWS keys, corresponding to an estimated 50,654 distinct AWS accounts after removing duplicates. While the total number of exposed keys is significant, the subset for which researchers possessed complete credentials allowing for re-verification stood at 10,616 keys. Disturbingly, 88% of these verified keys were still successfully authenticating as of August 10, indicating a persistent and unaddressed security gap.

Hundreds of leaked AWS keys give full control over corporate accounts

A Chronology of Compromise and Discovery

The issue of exposed AWS keys is not a recent phenomenon. Truffle Security’s continuous monitoring since August 2022 has illuminated the persistent nature of this threat. Their research, spanning a four-year period up to August 2026, reveals that a substantial portion of these critical credentials have remained vulnerable. The discovery process involved an extensive sweep of publicly accessible digital footprints where cloud credentials might inadvertently be disclosed. This included scanning code repositories, which are often used for collaboration and development, where sensitive keys can be accidentally committed. Git history, a record of changes made to code, also proved to be a significant source, as older, forgotten credentials might still reside in past commits. Furthermore, datasets, Docker images, and CI logs, which are integral to modern software development and deployment pipelines, were also scrutinized.

The sheer volume of identified secrets – over 431,000 – points to a systemic issue in how organizations manage and protect their cloud credentials. The extraction of over 64,000 unique AWS keys from this data highlights the direct link between these secrets and actual AWS accounts. The crucial verification phase, which narrowed down the focus to 10,616 keys, provided a more concrete picture of the active threats. The fact that a vast majority of these verified keys were still functional in August 2026 is a stark indicator that organizations are either unaware of the exposure or are failing to implement timely remediation measures.

The Gravity of Exposed Root and Administrator Keys

Hundreds of leaked AWS keys give full control over corporate accounts

The analysis by Truffle Security zeroes in on the most critical types of exposed credentials: root keys and keys with AdministratorAccess policies. AWS root keys are the ultimate credentials for an AWS account, granting absolute control over all services and resources. They are not subject to IAM policies, meaning there are no restrictions on their usage. The discovery of 526 exposed root keys is particularly alarming, as it signifies that attackers could potentially gain complete dominion over an entire AWS environment.

Equally concerning is the identification of 242 keys belonging to IAM users with the "AdministratorAccess" policy. While these keys operate within the framework of IAM, this specific policy grants them nearly identical privileges to root access. Such users can create, modify, delete, and view almost any AWS service and resource. This means attackers could escalate privileges, disable security controls, access sensitive data, and even lock out legitimate administrators. The researchers explicitly state that each of the 768 live keys in the two sets they analyzed offered "full control of a company’s AWS account." This highlights a critical vulnerability that could lead to catastrophic data breaches, service disruptions, and severe financial losses.

Hugging Face: A Significant Source of Leaked Credentials

Among the platforms where these credentials were found, Hugging Face, a prominent online hub for developers to share AI models, datasets, and applications, emerged as the largest single source of leaked AWS keys. The platform accounted for 8,482 unique key exposures. This finding is significant, given Hugging Face’s central role in the AI community and the sensitive nature of the data and models hosted there. The fact that a substantial portion of these keys (17.9%) were root keys further amplifies the security concerns associated with this specific source. The widespread use of Hugging Face by AI developers and organizations means that a compromise originating from this platform could have far-reaching implications across the rapidly evolving field of artificial intelligence.

Hundreds of leaked AWS keys give full control over corporate accounts

The Age and Persistence of Exposed Credentials

The longevity of these exposed credentials is another critical aspect of the security threat. Truffle Security’s analysis of 2,903 keys with available creation dates revealed a median age of 1,831 days, which translates to approximately five years. The oldest key identified had been active for an astonishing 17.4 years. This indicates a deeply entrenched problem of credential management, where keys are often created and then forgotten, remaining active and vulnerable for extended periods.

Compounding this issue is the lack of key rotation. Of the keys with available creation dates, only 398 (13.7%) had a newer access key associated with the same user. This strongly suggests that the vast majority of these exposed keys have never been rotated since their initial creation, leaving them perpetually vulnerable to exploitation. Regular credential rotation is a fundamental security practice designed to limit the window of opportunity for attackers who may have obtained compromised keys. The widespread failure to adhere to this practice significantly increases the risk of prolonged and undetected breaches.

The Broader Impact and Implications for Businesses

Hundreds of leaked AWS keys give full control over corporate accounts

The implications of these exposed AWS credentials extend far beyond mere data theft. Companies that rely on AWS for their core operations face a multitude of risks:

  • Data Exfiltration and Loss: Attackers can access, copy, or delete sensitive customer data, proprietary information, intellectual property, and financial records. This can lead to severe reputational damage, regulatory fines, and significant financial losses.
  • Service Disruption: Malicious actors can shut down critical services, rendering websites, applications, and business operations inaccessible to legitimate users. This can result in lost revenue, decreased productivity, and customer dissatisfaction.
  • Ransomware and Extortion: Attackers can encrypt data and demand a ransom for its restoration, or they can threaten to release stolen data publicly unless a payment is made.
  • Cryptojacking: As highlighted by Truffle Security, attackers can deploy cryptocurrency mining software on compromised infrastructure. This exploits the victim’s computing resources to generate cryptocurrency for the attacker, leading to unexpectedly high cloud bills and performance degradation.
  • Lateral Movement and Further Compromise: Once an attacker gains access to one AWS account, they can use it as a pivot point to launch further attacks against other internal systems or even external partners, creating a domino effect of breaches.
  • Reputational Damage: News of a data breach or significant security incident can severely damage a company’s brand reputation, eroding customer trust and potentially leading to a loss of business.
  • Regulatory Penalties: Depending on the nature of the data compromised and the industry sector, organizations may face significant fines from regulatory bodies for failing to protect sensitive information adequately.

The findings from the "Blue Report 2026" further underscore the critical nature of credential security. The report indicates that once attackers obtain valid credentials, their ability to evade defenses dramatically increases, with only 37% of their subsequent actions being blocked. This highlights a significant gap in security postures, where initial access can be relatively easy, but preventing further malicious activity becomes exceedingly difficult once an attacker is operating with legitimate credentials.

Recommendations and Mitigation Strategies

In light of these alarming findings, Truffle Security has put forth several critical recommendations for organizations to bolster their cloud security posture:

Hundreds of leaked AWS keys give full control over corporate accounts
  • Eliminate Root Access Keys: Root access keys should be deleted entirely and never used for routine operations. Their use should be restricted to very specific, infrequent administrative tasks, and even then, they should be managed with extreme caution.
  • Regularly Review IAM Credentials by Age: Implement a policy to regularly audit and review the age of all IAM credentials. Older credentials are more likely to be forgotten and compromised.
  • Rotate and Revoke Exposed Keys Promptly: Any AWS access key that is known or suspected to have been exposed must be immediately revoked and replaced with a new, securely generated key.
  • Configure Budget Alerts: Setting up comprehensive budget alerts is crucial for detecting anomalous resource usage that could indicate cryptojacking or other malicious activities.
  • Treat Publicly Committed Credentials as Compromised: Any credential found in a public repository, code commit, or any other publicly accessible location should be considered compromised and immediately rotated.
  • Implement Secrets Management Solutions: Organizations should leverage dedicated secrets management tools to securely store, manage, and distribute credentials, rather than embedding them directly in code or configuration files.
  • Conduct Regular Security Audits and Penetration Testing: Proactive security assessments, including penetration testing, can help identify vulnerabilities and exposed credentials before they can be exploited by malicious actors.
  • Educate Developers and Staff: Continuous training and awareness programs for developers and IT staff on secure coding practices and credential management are essential to prevent accidental exposure.

Truffle Security has confirmed that its testing was limited to read-only metadata to avoid any potential impact on live systems. Furthermore, the firm has taken the responsible step of notifying all identifiable owners of the exposed credentials, providing them with an opportunity to remediate the vulnerabilities. However, the onus remains on organizations to act swiftly and decisively to secure their AWS environments and prevent potentially catastrophic breaches. The persistent presence of thousands of active and valid leaked AWS keys serves as a stark reminder of the ongoing challenges in cloud security and the critical need for robust credential management practices.

Related Posts

Five Venezuelan Nationals Plead Guilty to ATM Jackpotting Conspiracy

Five Venezuelan nationals have entered guilty pleas for their involvement in a sophisticated conspiracy to defraud automated teller machines (ATMs) through the use of malware, a criminal tactic known as…

Microsoft Warns of TerminalFix Attacks Deploying Reverse Tunnels

A sophisticated new malware campaign, dubbed TerminalFix by Microsoft’s security researchers, is exploiting a novel attack vector that leverages deceptive Cloudflare CAPTCHA prompts to ensnare unsuspecting users and establish deep…

Leave a Reply

Your email address will not be published. Required fields are marked *

You Missed

A British Man’s Viral Walmart Experience Illuminates Transatlantic Consumer Culture Shock

A British Man’s Viral Walmart Experience Illuminates Transatlantic Consumer Culture Shock

Google Launches AI-Powered ‘Google Pics’ to Revolutionize Everyday Design within Workspace and Premium AI Subscriptions

Google Launches AI-Powered ‘Google Pics’ to Revolutionize Everyday Design within Workspace and Premium AI Subscriptions

The TV vs projector value debate isn’t close – here’s why

The TV vs projector value debate isn’t close – here’s why

Adobe Scales Generative Engine Optimization with Integration of Semrush Assets into New Brand Visibility Suite

Adobe Scales Generative Engine Optimization with Integration of Semrush Assets into New Brand Visibility Suite

Google Messages Integrates Live Checklists, Enhancing Collaborative Event and Trip Planning with September Android Drop

Google Messages Integrates Live Checklists, Enhancing Collaborative Event and Trip Planning with September Android Drop

Razer Unveils Prio: A Foldable Mobile Gaming Controller Redefining Portability for On-the-Go Play

Razer Unveils Prio: A Foldable Mobile Gaming Controller Redefining Portability for On-the-Go Play