Skip to content

CISA Analyzes Own GitHub Leak: Credential Management and Reporting Channels Were Critical

Bottom line: CISA took over 48 hours to invalidate leaked AWS keys, ignored nine automatic security alerts, and had no defined incident reporting procedures for its own infrastructure.

The Cybersecurity and Infrastructure Security Agency (CISA) has published an analysis of a data breach in which a contractor exposed AWS credentials and other sensitive data in a public GitHub repository for months. The postmortem reveals deficiencies in response speed and incident reporting channels.

On May 15, 2026, the security company GitGuardian notified CISA of a publicly accessible GitHub repository called “Private CISA”. The repository contained 844 megabytes of sensitive data, including the file “importantAWStokens” with administrative credentials for three AWS GovCloud servers. Another file named “AWS-Workspace-Firefox-Passwords.csv” contained usernames and passwords in plaintext for dozens of internal CISA systems. The repository had been publicly accessible for approximately six months before GitGuardian and security journalist Brian Krebs notified CISA.

Share on: