Truffle Security reported that more than 9,300 publicly exposed Amazon Web Services access keys remained active and valid after being leaked between August 2022 and August 2026, highlighting a widespread cloud credential exposure problem. Across public sources, the researchers identified 64,024 unique AWS keys and found that 88% of a subset of 10,616 keys with complete credentials still successfully authenticated as of August 10. The leaked secrets included 526 root keys and 242 IAM user keys with AdministratorAccess, creating a path to full AWS account compromise.
Researchers said the exposed credentials could allow attackers to steal or destroy data, take control of applications, establish persistence, and deploy cryptominers. Hugging Face was identified as the largest single source of leaked AWS keys in the dataset, while the persistence of valid credentials pointed to weak key rotation and poor credential hygiene across affected organizations. Truffle Security urged organizations to delete root access keys, rotate or revoke exposed credentials, review IAM key age and permissions, and enable AWS budget alerts to detect abuse.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Truffle Security found that 88% of 10,616 exposed AWS keys with complete credentials still authenticated, showing that thousands of leaked keys remained usable. The source explicitly anchors this verification status as of August 10.
A new report described AWS's quarantine policy for publicly leaked credentials and said it still permits numerous sensitive actions, including SSM command execution, STS role assumption, some RDS and Auto Scaling operations, CloudTrail disruption, SNS/SES abuse, S3 writes and retention locking, secret access, backup deletion, and CloudFormation stack deletion. The piece argued that AWS's approach limits some fraud-related abuse without fully neutralizing compromised keys, leaving significant residual risk.
Truffle Security reported that more than 9,300 publicly exposed AWS access keys observed between August 2022 and August 2026 remained active and valid. The dataset included 64,024 unique keys from 50,654 AWS accounts, with many highly privileged credentials such as root keys and AdministratorAccess IAM keys.
Truffle Security said it tracked the public exposure of AWS credentials over a four-year period spanning August 2022 through August 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
4 references tracked. Mallory keeps watching after this page renders.
theregister.com
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcedocs.aws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.