768 Leaked Corporate AWS Keys Remain Active With Full Administrator Access
Brief
A new cloud security investigation from Truffle Security has found that 768 publicly exposed AWS credentials still provide full administrative control over corporate AWS environments.
The findings highlight a persistent failure in credential rotation, secret management, and cloud account monitoring. Truffle Security re-verified 10,616 leaked AWS credential pairs on August 10, 2026, after locating them in public sources between August 2022 and August 2026.
These sources included Git history, Hugging Face datasets, Docker images, package registries, and CI/CD logs. About 88% of the tested credentials still authenticated successfully, showing that exposed cloud keys often remain usable long after their initial leak.
Of the active corporate-linked credentials, 526 were AWS root access keys , and 242 belonged to IAM users with the powerful AdministratorAccess policy.
