768 Leaked AWS Keys Grant Full Admin Access to Corporate Accounts

768 Leaked AWS Keys Grant Full Admin Access to Corporate Accounts

First seen 21 Aug 2026, 16:18 UTC Bleepingcomputertrufflesecurity.comTheregisterGbhackersInfosecurity-Magazine+2 69.0

Article Content

Browse articles
ThreatCluster

A recent investigation by Truffle Security revealed that 768 AWS access keys, including 526 root keys, remain active and grant full administrative privileges to corporate accounts. These keys were publicly exposed between August 2022 and August 2026, with 88% still authenticating as of August 10, 2026. The keys were found across various sources, including GitHub repositories and datasets, with Hugging Face being the largest contributor. The potential impact includes unauthorized access to sensitive data, infrastructure abuse, and significant financial charges due to misuse. Only a small fraction of the compromised accounts had budget alerts set up, highlighting a lack of proactive security measures. Truffle Security has notified identifiable owners of the exposed credentials and recommends immediate action to rotate or revoke the compromised keys.

Key Points: • 768 AWS keys, including 526 root keys, are still active and grant full admin access. • 88% of the leaked keys were verified as still authenticating as of August 10, 2026. • Most compromised accounts lack budget alerts, increasing the risk of financial abuse.

Timeline

2026-08-10
Key verification conducted
Truffle Security verified 10,616 leaked AWS keys, finding 88% still active.
Truffle Security
2026-08-21
Truffle Security report published
Truffle Security reported 768 active AWS keys with full control over corporate accounts.
BleepingComputer
2026-08-21
The Register coverage
The Register discussed AWS's handling of leaked credentials and its quarantine policy.
The Register
2026-08-22
Gbhackers report published
Gbhackers highlighted the risks associated with the 768 active AWS keys and their potential for abuse.
Gbhackers