The Cybersecurity and Infrastructure Security Agency has released a postmortem report detailing how a contractor’s six-month data leak exposed sensitive AWS GovCloud credentials and internal system passwords.
Key Points
- A public GitHub repository titled "Private CISA" exposed 844 MB of sensitive data, including administrative AWS GovCloud keys and plaintext passwords.
- The exposed credentials remained accessible for six months despite nine automated alerts from the security firm GitGuardian.
- CISA required over 48 hours to invalidate the leaked secrets, citing complex system interconnections and a lack of defined internal reporting channels.
- The agency has since revoked the contractor's access, rotated all compromised secrets, and committed to improving its incident response playbooks.
- CISA now advocates for continuous public repository scanning and the establishment of clear, accessible reporting channels for external security researchers.