IC Technology & Surveillance — 2026-05-20

CISA Contractor Leaked AWS GovCloud Credentials on Public GitHub for Six Months, Congress Demands Briefing

BLUFPublic confirmation of intrusion is unlikely within six months, but the half-year exposure window leaves a credible probability that sophisticated actors harvested credentials and established persistence undetected.

GitGuardian researcher Guillaume Valadon found a public GitHub repository named "Private-CISA," linked to CISA contractor Nightwing, containing plaintext AWS GovCloud keys and other CISA and DHS credentials that had been publicly accessible since at least November 12. Valadon tested a sample of the exposed keys, confirmed they were valid, and escalated to journalist Brian Krebs after the contractor did not respond to GitGuardian's alerts 1. CISA spokesperson Marco DiSandro said the agency is investigating and has found "no indication that any sensitive data was compromised"; the repository has since been removed 12. House Homeland Security Democrats Reps. Bennie Thompson and Delia Ramirez and Sen. Maggie Hassan sent letters Tuesday to CISA acting director Nick Andersen demanding briefings on how the lapse occurred, its potential consequences, and corrective actions taken against the contractor personnel involved 23.

Analysis
CISA's "no indication of compromise" reflects telemetry limits rather than forensic clearance; cloud credential abuse by patient adversaries rarely generates immediately attributable artifacts. Six months of unmonitored public exposure, reported by Krebs on Security and amplified but not independently verified across three outlets, creates a meaningful, unresolved risk that state-sponsored actors accessed and retained persistence before the repository came down. Public confirmation of unauthorized access is unlikely within the next six months, though the swift removal and absence of weaponized data may instead reflect genuine forensic clearance. A confirmed breach escalates congressional oversight letters to formal hearings with mandatory contractor audit provisions, while absent confirmation CISA absorbs the incident without new legislative action on contractor procurement.
4 sources
  1. US cyber agency CISA exposed reams of passwords and cloud keys to the open web - TechCrunch
  2. CISA credential leak raises alarms, and Capitol Hill demands answers - CyberScoop
  3. House Homeland Dems request CISA briefing amid report of leaked agency credentials - Nextgov
  4. CISA Admin Leaked AWS GovCloud Keys on Github - Krebs on Security

View in full brief →

UNCLASSIFIED // OPEN SOURCE