News

Thousands of leaked cloud keys still work years later

Researchers at Truffle Security re-checked 10,616 Amazon Web Services access keys that had been exposed publicly between 2022 and 2026, in places like code repositories, container images and CI logs.

88% still worked. 768 of the live keys belonging to companies carried full control of the company's AWS account.

Why a leaked key stays dangerous

An access key is a password for software. Once it's been posted publicly, removing the file doesn't help; copies exist. The key itself has to be disabled and replaced. The research found the median leaked key was five years old and had never been rotated.

Does this apply to us?

Most practices don't run their own AWS account, but your software vendors, your website developer and your BIM platform almost certainly do. And the same principle applies to any API key or service credential: the SharePoint integration, the accounting connector, the plotter's cloud print service.

Ask your developers and suppliers how these keys are stored, how they'd know if one leaked, and how often they're rotated. If you do use AWS or Azure directly and aren't sure how your keys are managed, we'll review them with you.

Want a hand with this? Talk to us.

Source: BleepingComputer: Hundreds of leaked AWS keys give full control over corporate accounts

← All insights