Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Thunderquakes can act like X-rays for the ground

    August 21, 2026

    American Oversight Presses N.C. Auditor’s Office Over Missing Woodhouse Records and Search of Boliek’s Device

    August 21, 2026

    How Oregon Hides the Details of Affordable Housing Spending — ProPublica

    August 21, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Thunderquakes can act like X-rays for the ground
    • American Oversight Presses N.C. Auditor’s Office Over Missing Woodhouse Records and Search of Boliek’s Device
    • How Oregon Hides the Details of Affordable Housing Spending — ProPublica
    • Arsenal sign Konsa from Villa as Premier League holders bolster defence | Football News
    • Germany investigates Russia links to weapons cache discovery, reports say
    • UK, France, Germany, Italy and Canada condemn Israel’s West Bank settlement project
    • Smithsonian’s New Latino Museum May Receive an Existing Building
    • Meta’s Big Reckoning Is Here
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, August 21
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Hundreds of leaked AWS keys give full control over corporate accounts

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 21, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.

    Truffle Security has been tracking this exposure for the past four years and says that 817 of the exposed keys were linked to companies, 526 of them being AWS root keys.

    According to the researchers, 242 of the keys are associated with Identity and Access Management (IAM) users with the AdministratorAccess policy. This role has full permissions to create, modify, delete, and view virtually all AWS services and resources within an account.

    image

    They note that each key of the 768 live keys in the two sets “full control of a company’s AWS account.”

    The company found 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries, and CI logs and extracted 64,024 unique AWS keys that corresponded to 50,654 AWS accounts after removing duplicates.

    Exposed AWS keys
    Unique verified exposed AWS keys
    Source: Truffle Security

    However, the subset for which the researchers had complete credentials that could be used for re-verification was 10,616 keys, and 88% of them continued to authenticate as of August 10.

    Amazon Web Services (AWS) is Amazon’s cloud-computing platform used by companies to host websites and applications, store data, run databases and servers, manage domains, and operate their online infrastructure.

    Full control of a company’s AWS account could allow an attacker to access, exfiltrate, or wipe cloud-hosted data, take control of servers and applications, and create rogue admin accounts for persistent access

    Threat actors could also use their access to deploy cryptominers, generating substantial charges for the company. Truffle Security says that only 262 of 2,754 readable accounts had a budget alert set up.

    Hugging Face, a popular online platform where developers share AI models, datasets, and applications, was the largest single source of leaked AWS keys, accounting for 8,482 unique key exposures.

    Also, 17.9% of those keys were root, meaning the highest-privileged identity, which isn’t restricted by IAM permissions.

    Roles of exposed keys
    Roles of exposed AWS keys
    Source: Truffle Security

    Truffle Security found that, for the 2,903 keys with available creation dates, the median age was 1,831 days (about five years), while the oldest had existed for 17.4 years.

    Only 398 (13.7%) of those entries had a newer access key associated with the same user, suggesting most had never been rotated.

    Age of exposed keys
    Age of exposed AWS keys
    Source: Truffle Security

    To defend against potential abuse, the researchers recommend deleting all root access keys, reviewing IAM credentials by age, rotating or revoking exposed keys, and configuring budget alerts.

    Also, any credential committed to a public source should be treated as compromised.

    Truffle Security said its testing was limited to read-only metadata, and that it has notified all identifiable owners of the exposed credentials.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Accounts AWS control corporate Full Give hundreds keys Leaked
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Is Online Privacy Possible? How Digital Identities Can Help

    Why does it seem like food recalls are out of control this year?

    Microsoft blames Windows gaming issues on RGB lighting devices

    Reform corrects claim that ‘rising’ share of Universal Credit went to foreign nationals – Full Fact

    OpenAI Adds Controls That Should’ve Been There Already

    Critical Isolated-vm Vulnerability Leads to RCE on Host

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Thunderquakes can act like X-rays for the ground

    August 21, 2026

    American Oversight Presses N.C. Auditor’s Office Over Missing Woodhouse Records and Search of Boliek’s Device

    August 21, 2026

    How Oregon Hides the Details of Affordable Housing Spending — ProPublica

    August 21, 2026

    Arsenal sign Konsa from Villa as Premier League holders bolster defence | Football News

    August 21, 2026
    Latest Posts

    ‘Running Away Balloon’ Artist Sues AI Meme Generator Over Ad Templates

    July 28, 2026

    Hush Security Raises $30 Million for AI Agent Governance

    July 28, 2026

    Armenia’s AI Bet Is Not Chip Manufacturing. It Is Compute Sovereignty 

    July 28, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Thunderquakes can act like X-rays for the ground

    August 21, 2026

    American Oversight Presses N.C. Auditor’s Office Over Missing Woodhouse Records and Search of Boliek’s Device

    August 21, 2026

    How Oregon Hides the Details of Affordable Housing Spending — ProPublica

    August 21, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.