Thousands of publicly exposed AWS access keys remained active, including hundreds with full control of company accounts

Researchers found that thousands of Amazon Web Services access keys exposed in public sources were still valid, including hundreds tied to companies and many with top-level privileges. Truffle Security says 9,300 AWS keys exposed between 2022 and 2026 were still active, with 526 root keys and 242 Identity and Access Management (IAM) administrator keys among the risky set; the leaks were found in code repositories, Git history, Docker images, registries, datasets, and CI logs.
Why it matters: Any organization with leaked AWS credentials could face data theft, server takeover, destructive changes, or costly cryptomining through valid logins that bypass many prevention controls. Affected teams should treat any publicly exposed key as compromised, revoke or rotate keys immediately, delete root keys, and review cloud accounts for abuse.

Sources

Hundreds of leaked AWS keys give full control over corporate accounts
Bill Toulas 2026.08.21 100% relevant
This article establishes a distinct security story about long-lived public exposure of active AWS credentials across many organizations, rather than a single company breach or a specific CVE.
← Back to all stories