Truffle Security has reported that over 9,300 Amazon Web Services (AWS) access keys, publicly exposed between August 2022 and August 2026, remain active and valid. Of these, 817 keys are associated with companies, and 242 provide AdministratorAccess, granting full control over AWS services and resources within an account. The researchers confirmed that 768 live keys in these sets offer complete control over a company's AWS account.
The security firm discovered 431,875 AWS secrets across various repositories and logs, extracting 64,024 unique AWS keys. A subset of 10,616 keys was re-verified, with 88% still authenticating as of August 10. Full control of an AWS account enables attackers to access, exfiltrate, or wipe cloud data, take over servers and applications, and create rogue administrator accounts for persistent access. Attackers could also deploy cryptominers, incurring substantial costs for companies, as only 262 of 2,754 readable accounts had budget alerts configured.
Hugging Face, a platform for sharing AI models and datasets, was the largest single source of leaked AWS keys, contributing 8,482 unique key exposures. Notably, 17.9% of these keys were root keys, which possess the highest level of privilege and are not restricted by IAM permissions.
Analysis of 2,903 keys with available creation dates revealed a median age of 1,831 days (approximately five years), with the oldest key existing for 17.4 years. Only 398 (13.7%) of these entries had a newer access key associated with the same user, indicating a widespread lack of key rotation. To mitigate potential abuse, Truffle Security recommends deleting all root access keys, reviewing IAM credentials by age, and rotating or revoking exposed keys.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Truffle Security identified over 9,300 publicly exposed Amazon Web Services (AWS) access keys that are still active and valid, with 817 linked to companies and 242 granting administrator access. This exposure allows full control over affected AWS accounts, posing significant data and infrastructure security risks. The findings highlight widespread issues with key rotation and security practices among AWS users.