More than 9,300 Amazon Web Services access keys that were publicly exposed between August 2022 and August 2026 remain active and valid, according to cybersecurity firm Truffle Security, which has tracked the issue for four years. Of those exposed keys, 817 were linked to companies, and 526 were AWS root keys. Researchers also found that 242 of the keys belonged to Identity and Access Management users with the AdministratorAccess policy, a role that grants full permissions to create, modify, delete, and view nearly all AWS services and resources within an account. Truffle Security stated that each of the 768 live keys in the two sets provided full control of a company鈥檚 AWS account.
The firm discovered 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries, and CI logs. After removing duplicates, the team extracted 64,024 unique AWS keys that corresponded to 50,654 AWS accounts. However, the subset for which researchers had complete credentials for re-verification was 10,616 keys, and 88 percent of those still authenticated as of August 10.
AWS is Amazon鈥檚 cloud-computing platform used by companies to host websites and applications, store data, run databases and servers, manage domains, and operate online infrastructure. Full control of a company鈥檚 AWS account could allow an attacker to access, exfiltrate, or wipe cloud-hosted data, take over servers and applications, and create rogue admin accounts for persistent access. Threat actors could also use the access to deploy cryptominers, generating substantial charges for the company. Truffle Security noted that only 262 of 2,754 readable accounts had a budget alert set up.
Hugging Face, an online platform where developers share AI models, datasets, and applications, was the largest single source of leaked AWS keys, accounting for 8,482 unique key exposures. Additionally, 17.9 percent of those keys were root keys, meaning the highest-privileged identity that is not restricted by IAM permissions. For the 2,903 keys with available creation dates, the median age was 1,831 days, about five years, while the oldest had existed for 17.4 years. Only 398 of those entries, or 13.7 percent, had a newer access key associated with the same user, suggesting most had never been rotated.
To defend against potential abuse, researchers recommend deleting all root access keys, reviewing IAM credentials by age, rotating or revoking exposed keys, and configuring budget alerts. They also advise that any credential committed to a public source should be treated as compromised. Truffle Security said its testing was limited to read-only metadata and that it has notified all identifiable owners of the exposed credentials.
The findings come as part of a broader assessment of cloud security defenses. Truffle Security noted that overall prevention scores can hide what happens after initial access, and that once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. The report also references an incident where an OpenAI agent used exposed credentials at four services in a Hugging Face breach, underscoring the real-world risk of leaked keys.
More cybersecurity news from TechManNews.






