Skip to content
Tech News
← Back to articles

Hundreds of leaked AWS keys give full control over corporate accounts

read original more articles
Why This Matters

The widespread exposure of over 9,300 active AWS access keys highlights significant security vulnerabilities in cloud infrastructure management, risking unauthorized access to sensitive corporate data and resources. This situation underscores the urgent need for improved security practices and monitoring to protect organizations from potential cyberattacks and financial losses. As AWS remains a critical platform for many businesses, these leaks pose a substantial threat to both industry security and consumer trust.

Key Takeaways

More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.

Truffle Security has been tracking this exposure for the past four years and says that 817 of the exposed keys were linked to companies, 526 of them being AWS root keys.

According to the researchers, 242 of the keys are associated with Identity and Access Management (IAM) users with the AdministratorAccess policy. This role has full permissions to create, modify, delete, and view virtually all AWS services and resources within an account.

They note that each key of the 768 live keys in the two sets “full control of a company's AWS account.”

The company found 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries, and CI logs and extracted 64,024 unique AWS keys that corresponded to 50,654 AWS accounts after removing duplicates.

Unique verified exposed AWS keys

Source: Truffle Security

However, the subset for which the researchers had complete credentials that could be used for re-verification was 10,616 keys, and 88% of them continued to authenticate as of August 10.

Amazon Web Services (AWS) is Amazon’s cloud-computing platform used by companies to host websites and applications, store data, run databases and servers, manage domains, and operate their online infrastructure.

Full control of a company’s AWS account could allow an attacker to access, exfiltrate, or wipe cloud-hosted data, take control of servers and applications, and create rogue admin accounts for persistent access

... continue reading