type: incident ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [data-leak, government-agency, supply-chain, incident] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true
CISA GitHub Data Leak
CISA published a postmortem on a significant data leak in which a contractor published 844 MB of sensitive internal data โ including AWS GovCloud keys and plaintext passwords for dozens of internal systems โ in a public GitHub repository for nearly six months.
Timeline
| Date | Event |
|---|---|
| ~Jan 2026 | Contractor inadvertently publishes data to public repo |
| Multiple | GitGuardian sends 9 automated alerts to CISA during exposure window |
| May 2026 | KrebsOnSecurity notifies CISA directly |
| May 2026 | CISA acknowledges โ takes over 48 hours to rotate all exposed keys |
| July 13, 2026 | CISA publishes postmortem via Krebs on Security (raw/digests/Cyber-Digest-2026-07-18) |
What Was Exposed
- 844 MB of sensitive internal data
- AWS GovCloud keys (highly sensitive โ GovCloud is CISA's own cloud infrastructure)
- Plaintext passwords for dozens of internal systems
- Access data to CISA's operational environments
Security Failures Identified
- GitGuardian sent 9 alerts before the leak was acted upon through journalism โ the automated alerting system worked, but the escalation/remediation process failed
- No audit trail for credential rotation in third-party contractor environments
- 48+ hour key rotation time โ far exceeding CISA's own standards for incident response
Significance for Australia
The incident serves as a case study for Australian government agencies (Acsc, Asd, Home Affairs Cyber) managing cloud infrastructure through third-party contractors. Key lessons: - Automated security tooling is only as good as the escalation path - GovCloud/Protected-level credential management requires contractor auditing - Plaintext passwords in repositories violates ACSC's Essential Eight guidelines
Related Pages
- Acsc Cms Exploitation โ ACSC alert on CMS exploitation (same period)
- Cisa Fortinet Credential Exposure โ CISA alert on Fortinet credential exposure