Thousands of Leaked AWS Keys Still Grant Attackers Full Corporate Cloud Access
Truffle Security reports that more than 9,300 Amazon Web Services access keys exposed publicly between August 2022 and August 2026 remain active and valid. After sifting through 431,875 AWS secrets found in code repositories, Git history, datasets, Docker images, registries, and CI logs, researchers extract 64,024 unique keys tied to 50,654 AWS accounts. Of the 10,616 keys they can fully re-verify, 88 percent still authenticate as of August 10.
The danger is severe: 817 of the exposed keys belong to companies, including 526 root keys and 242 IAM keys with the AdministratorAccess policy, meaning each of 768 live keys grants complete control over a corporate AWS account. Attackers could steal or wipe cloud-hosted data, hijack servers and applications, create rogue admin accounts for persistent access, or deploy cryptominers that rack up substantial charges. Only 262 of 2,754 readable accounts have budget alerts configured to catch such abuse.
Hugging Face, the popular AI model-sharing platform, stands out as the largest single source of leaked keys, accounting for 8,482 unique exposures, with 17.9 percent of those being root keys. The exposed credentials also tend to be old, with a median age of about five years and the oldest key dating back 17.4 years, while only 13.7 percent of affected entries have newer replacement keys. The findings underscore the need for organizations to rotate credentials, avoid root keys, and monitor for exposed secrets.