Thousands of leaked AWS keys remain active years after appearing in public sources, according to new research from Truffle Security. Hundreds of those credentials reportedly provide full administrative control over corporate Amazon Web Services accounts.

The researchers tracked exposed cloud credentials between August 2022 and August 2026. They found that more than 9,300 publicly exposed keys could still authenticate as of August 10.

Hundreds of credentials have powerful account access

Truffle Security identified 817 leaked AWS keys connected to company accounts. Of those, 526 were root keys, which belong to the most privileged identity in an AWS environment.

The research also found 242 keys linked to IAM users with the AdministratorAccess policy. That permission set can allow a user to create, change, delete and view almost all AWS services and resources in an account.

According to the researchers, 768 of the active credentials in the two highest-risk groups could provide complete control over a company’s AWS account.

An attacker who obtains that access could steal or delete cloud-hosted data, take over applications and servers, or create new administrator accounts to maintain access.

Public sources continue to expose cloud credentials

The researchers found 431,875 AWS secrets in code repositories, Git histories, datasets, Docker images, registries and continuous-integration logs.

After removing duplicates, the team identified 64,024 unique AWS keys linked to 50,654 AWS accounts. They could fully re-verify 10,616 of those keys because they had the complete credentials needed to test them.

Of that smaller set, 88% still authenticated in August.

Hugging Face was the largest individual source of exposed AWS keys in the research, accounting for 8,482 unique exposures. Researchers said 17.9% of those credentials were root keys.

Old credentials create a long-term risk

Many of the exposed keys had existed for years. Among the 2,903 credentials with available creation dates, the median age was 1,831 days, or roughly five years.

The oldest key in the dataset was more than 17 years old.

Only 398 of those entries had a newer access key connected to the same user. That suggests many organisations had not rotated their credentials after creating them.

Poor credential rotation can turn an accidental public upload into a long-term security problem. Once attackers find an active key, they may use it to access cloud resources or generate costs by deploying cryptominers.

Truffle Security found that only 262 of 2,754 readable accounts had budget alerts configured.

AWS urges customers to revoke exposed keys

AWS said it notifies affected customers when it becomes aware of exposed credentials. The company also said it investigates reports and can apply quarantine policies to reduce risk without disrupting customer environments.

Organisations should treat any credential committed to a public source as compromised. Security teams should revoke or rotate leaked AWS keys immediately, remove root access keys, review older IAM credentials and enable budget alerts.

Truffle Security said it limited its testing to read-only metadata and notified identifiable owners of the exposed credentials.


0 responses to “Hundreds of Leaked AWS Keys Give Full Control of Corporate Accounts”