IC Technology & Surveillance — 2026-05-23

Lawmakers Demand Answers as CISA Contractor Publishes GovCloud Keys and Agency Secrets on Public GitHub

BLUFAbsent forensic evidence that exposed credentials were used, formal confirmation of unauthorized access remains unlikely before end of 2026, denying oversight bodies the breach trigger needed to compel mandatory remediation.

GitGuardian found the "Private-CISA" public repository on May 14, containing AWS GovCloud keys, Kubernetes secrets, and CI/CD credentials publicly accessible since November 13, 2025; CISA took it offline on May 15 after GitGuardian reached the agency directly 12. KrebsOnSecurity reported the contractor had deliberately disabled GitHub's secret-scanning protections before committing the credentials 2. Truffle Security's Dylan Ayrey told KrebsOnSecurity on May 20 that an RSA key granting access to all CISA-IT repositories had not yet been revoked; CISA rotated it following that notification but other critical credentials remain outstanding 2. Congressional letters from both chambers, sent May 19 to Acting Director Nick Andersen, demanded answers; CISA stated there is "no indication that any sensitive data was compromised" 2.

Analysis
A formal government confirmation that the exposed CISA credentials were accessed by unauthorized parties is unlikely by end of 2026, leaving Congressional oversight without the FISMA trigger that would compel mandatory remediation reporting. Confidence is moderate: GitGuardian and KrebsOnSecurity converge on the technical facts, but no forensic or signals reporting addresses whether any credential was actually used. The contractor's disabling of GitHub's secret-scanning and CISA's failure to rotate a critical RSA key until outside researchers intervened signal process failures extending beyond a single actor's conduct. The use of a personal GitHub account to sync work materials is more consistent with negligent convenience than deliberate exfiltration, which would shift remediation emphasis toward contractor vetting and endpoint controls rather than insider threat investigation. Absent a confirmed breach, remediation funding and new contractor security legislation compete on a longer timeline.
2 sources
  1. How We Got a CISA GitHub Leak Taken Down in Under a Day - GitGuardian
  2. Lawmakers Demand Answers as CISA Tries to Contain Data Leak - Krebs on Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE