Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-23 ยท updated: 2026-08-23 ยท tags: [incident, cloud-security, aws, credentials, secrets-leakage] ยท confidence: high ยท severity: high ยท affected_sectors: [technology, finance] ยท au_impact: false

Truffle Security reported that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 remain valid and active, including 526 AWS root keys and 242 keys tied to IAM users with administrative privileges; 817 exposed keys were linked to companies. Four years of tracking show secret leakage is persistent rather than transient, reinforcing short-lived credentials and automated rotation as baseline controls.

Source