← Home
TECH NEWS

Over 9,300 AWS Keys Leaked, Still Active and Valid

August 23, 2026 Daniel Cross

Of those, 817 successfully authenticated and returned administrative privileges

On August 21, 2026, security researcher Bill Toulas reported that more than 9,300 Amazon Web Services access keys exposed between August 2022 and August 2026 remain active and valid. Truffle Security has monitored the leak for four years, finding that 817 of those keys still grant full account control. The keys were discovered in public repositories and other open sources, where they were inadvertently posted by developers or leaked through misconfigured services. Because they were never revoked, the credentials continue to provide unrestricted access to the associated AWS environments, allowing anyone who possesses them to create, modify, or delete resources. How Truffle Security Tracked the Leak Truffle Security set up automated scans of public code repositories, forums, and paste sites to catch newly posted AWS keys. Over the four‑year period they collected more than 9,300 distinct keys and verified each one’s status by attempting to authenticate with the AWS API.

Of those, 817 successfully authenticated and returned administrative privileges, confirming they are still active and capable of full control. What Risks Do the Active Keys Pose? With full control, an attacker could launch virtual machines, access stored data, change security settings, or incur unexpected charges on the victim’s account. The persistence of these keys means that corporate assets remain vulnerable until the credentials are rotated or the associated accounts are secured. The exposure highlights the danger of hard‑coding secrets in publicly accessible code. Organizations should immediately audit their AWS usage for any signs of unauthorized access, rotate all keys that might have been exposed, and enable real‑time alerts for anomalous API calls. Implementing strict secret‑management practices and regular credential rotation will reduce the likelihood of similar incidents.

Until remediation is complete, the leaked keys represent an ongoing threat to corporate cloud security. Frequently Asked Questions How many AWS keys were found

Read full article on Tech Site News →