More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says a recent report from Bleeping Computer. Truffle Security has watched this happen for four years. They found that 817 exposed keys were tied to companies, and 526 of those were AWS root keys.

Researchers found that 242 keys belonged to IAM users who had the Administrator Access policy, which allows complete access to AWS services. The company found 431,875 AWS secrets in different code repositories and got 64,024 unique AWS keys. Out of the 10,616 keys with valid credentials, 88% were still active as of August 10.
Hugging Face is a platform for AI models and had the most leaked keys, with 8,482 cases. Most of these keys were old, averaging around five years, and were probably never changed. If attackers gained full control of an AWS account, they could steal data, control applications, or install cryptominers.
Truffle Security suggests removing root access keys, checking IAM credentials, changing exposed keys, and setting up budget alerts.

“Anytime AWS is aware of exposed keys, we notify the affected customers. We also thoroughly investigate all reports of exposed keys and quickly take any necessary actions, such as applying quarantine policies to minimize risks for customers without disrupting their IT environment. To report any security concern to AWS, including exposed customer credentials, please email [email protected] (PGP key).”

“AWS helps customers secure their cloud resources through a shared responsibility model. We encourage all customers to follow security, identity, and compliance best practices. In the event a customer suspects they may have exposed their credentials, they can start by following the steps listed in this post. As always, customers can contact AWS Support with any questions or concerns about the security of their account.” – AWS spokesperson said.
Related News:
InfoSecBulletin Cybersecurity for mankind
