CISA contractor GitHub repository exposed internal credentials
Data Leak
Summary
Hide ▲
Show ▼
A CISA contractor left a public GitHub repository exposing AWS GovCloud credentials, plaintext passwords, and other internal access material tied to CISA and DHS systems. The repository, Private-CISA, held 844 MB of sensitive data, including files such as importantAWStokens and AWS-Workspace-Firefox-Passwords.csv, and the exposure remained public for nearly six months before being reported through KrebsOnSecurity. CISA said it rotated the leaked secrets, revoked contractor access, and found no customer or mission data was exposed or used outside its environments.
Related Happenings
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive Guidance
H score26
First: 13.07.2026 18:03
Last: 13.07.2026 18:03
Sources 1
How related:
The report’s authors also emphasized the importance of continuously scanning public code repositories like GitHub for exposed secrets, and said CISA has since rotated all secrets and created an action plan to improve management of developer secrets and to better monitor for them going forward.
About this happening:
CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
CISA recommends continuous secrets scanning and stronger key management after GitHub leak
Defensive GuidanceHow related: The report’s authors also emphasized the importance of continuously scanning public code repositories like GitHub for exposed secrets, and said CISA has since rotated all secrets and created an action plan to improve management of developer secrets and to better monitor for them going forward.
About this happening: CISA now recommends continuous secrets scanning and stronger key management after a contractor left internal credentials in a public GitHub repository for nearly *...
Single organization's private GitHub repository cloned after confirmed access
Data Leak
H score12
First: 09.07.2026 21:38
Last: 09.07.2026 21:38
Sources 1
About this happening:
Confirmed access to a private GitHub repository belonging to one organization marks a concrete data exposure and raises the risk of source-code or internal-content...
Single organization's private GitHub repository cloned after confirmed access
Data LeakAbout this happening: Confirmed access to a private GitHub repository belonging to one organization marks a concrete data exposure and raises the risk of source-code or internal-content...
AWS environment hit by data theft breach
Incident
H score26
First: 08.07.2026 15:30
Last: 08.07.2026 15:30
Sources 1
About this happening:
An AWS environment was compromised in an AI-assisted intrusion that enabled extortion, creating immediate risk of data theft and operational disruption. The actor...
AWS environment hit by data theft breach
IncidentAbout this happening: An AWS environment was compromised in an AI-assisted intrusion that enabled extortion, creating immediate risk of data theft and operational disruption. The actor...
FortiBleed Fortinet/FortiGate VPN credential leak
Data Leak
H score80
First: 17.06.2026 18:12
Last: 17.06.2026 18:12
Sources 1
About this happening:
FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
FortiBleed Fortinet/FortiGate VPN credential leak
Data LeakAbout this happening: FortiBleed is a data leak of Fortinet/FortiGate VPN credentials that now includes a verified database of 86,644 confirmed working credentials collected from inte...
Latest development: 19.06.2026 09:47
CISA urged Fortinet customers to secure FortiGate appliances after nearly 74,000 firewall and VPN credentials were exposed in the FortiBleed leak. The agency advised affected owners to terminate SSL VPN and administrative sessions, reset VPN and administrative passwords, enable phishing-resistant multifactor authentication, review logs for unauthorized access or lateral movement, store admin credentials with PBKDF2, restrict firewall management interfaces from public internet access, and remove unauthorized accounts.
Congress demands CISA answers on GitHub credential leak
Public Sector Action
H score19
First: 22.05.2026 19:34
Last: 22.05.2026 19:34
Sources 1
How related:
Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account.
About this happening:
Lawmakers in both houses of Congress demanded answers from CISA after a contractor exposed AWS GovCloud keys and other secrets on public GitHub. The letters presse...
Congress demands CISA answers on GitHub credential leak
Public Sector ActionHow related: Lawmakers in both houses of Congress are demanding answers from the U.S. Cybersecurity & Infrastructure Security Agency (CISA) after KrebsOnSecurity reported this week that a CISA contractor intentionally published AWS GovCloud keys and a vast trove of other agency secrets on a public GitHub account.
About this happening: Lawmakers in both houses of Congress demanded answers from CISA after a contractor exposed AWS GovCloud keys and other secrets on public GitHub. The letters presse...
Timeline
-
10.07.2026 19:00 1 articles · 5d ago
CISA details mitigation for exposed AWS GovCloud keys
Mitigation Patch UpdateCISA said that within moments of receiving information about internal AWS GovCloud keys and other material in a public GitHub repository owned by a contractor, its Office of the Chief Information Officer took swift and comprehensive action to mitigate exposure to CISA cloud resources and code repositories. The agency said internal incident response began on May 15, no customer or mission data was exposed, and the leaked credentials were not used outside CISA's environments.
Show sources
- CISA Details Incident Response to Exposed AWS GovCloud Keys — www.infosecurity-magazine.com — 10.07.2026 19:00
-
22.05.2026 19:34 1 articles · 1mo ago
Lawmakers demand answers over CISA Private-CISA leak
Legal Policy Action UpdateOn May 19, Sen. Maggie Hassan and Rep. Bennie Thompson, with Rep. Delia Ramirez co-signing Thompson’s letter, sent separate letters to CISA demanding answers about the Private-CISA GitHub leak and warning that the credential exposure raised serious concerns about CISA’s internal policies, contract support, and security culture.
Show sources
- Lawmakers Demand Answers as CISA Tries to Contain Data Leak — krebsonsecurity.com — 22.05.2026 19:34
-
18.05.2026 23:48 2 articles · 1mo ago
Private-CISA repository exposes CISA and DHS credentials
Initial DisclosureA contractor-maintained public GitHub repository named Private-CISA was created and exposed CISA and DHS secrets, including AWS GovCloud administrative credentials, cloud keys, tokens, plaintext passwords, logs, and files showing how CISA builds, tests, and deploys software internally.
Show sources
- CISA Admin Leaked AWS GovCloud Keys on Github — krebsonsecurity.com — 18.05.2026 23:48
- CISA Admin Leaked AWS GovCloud Keys on Github — krebsonsecurity.com — 18.05.2026 23:48
-
18.05.2026 23:48 2 articles · 1mo ago
Researchers validate Private-CISA credentials and CISA investigates
Technical Analysis UpdateResearchers from GitGuardian and Seralys validated that the leaked AWS keys could authenticate to three AWS GovCloud accounts at a high privilege level, found plaintext credentials for CISA's internal artifactory and other systems, and CISA said it was investigating with no indication that sensitive data had been compromised. The repository was taken offline after notification, but the exposed AWS keys reportedly remained valid for another 48 hours.
Show sources
- CISA Admin Leaked AWS GovCloud Keys on Github — krebsonsecurity.com — 18.05.2026 23:48
- Lessons Learned from CISA’s Recent GitHub Leak — krebsonsecurity.com — 13.07.2026 18:03