← Back to Feed

Hundreds of leaked AWS keys give full control over corporate accounts

August 21, 2026 · BleepingComputer · Severity: MEDIUM

More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.

Key Takeaways

  • Hundreds of leaked AWS access keys have been discovered that grant full control over corporate cloud environments and resources.
  • The exposed keys were found in public code repositories, misconfigured CI/CD pipelines, and exposed environment files.
  • Organizations must implement automated secret scanning, enforce key rotation policies, and use IAM roles instead of hardcoded credentials in cloud deployments.
☕ Buy a Coffee