Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [data-leak, government-agency, supply-chain, incident] ยท confidence: high ยท affected_sectors: [government, technology] ยท au_impact: true

CISA GitHub Data Leak

CISA published a postmortem on a significant data leak in which a contractor published 844 MB of sensitive internal data โ€” including AWS GovCloud keys and plaintext passwords for dozens of internal systems โ€” in a public GitHub repository for nearly six months.

Timeline

Date Event
~Jan 2026 Contractor inadvertently publishes data to public repo
Multiple GitGuardian sends 9 automated alerts to CISA during exposure window
May 2026 KrebsOnSecurity notifies CISA directly
May 2026 CISA acknowledges โ€” takes over 48 hours to rotate all exposed keys
July 13, 2026 CISA publishes postmortem via Krebs on Security (raw/digests/Cyber-Digest-2026-07-18)

What Was Exposed

  • 844 MB of sensitive internal data
  • AWS GovCloud keys (highly sensitive โ€” GovCloud is CISA's own cloud infrastructure)
  • Plaintext passwords for dozens of internal systems
  • Access data to CISA's operational environments

Security Failures Identified

  1. GitGuardian sent 9 alerts before the leak was acted upon through journalism โ€” the automated alerting system worked, but the escalation/remediation process failed
  2. No audit trail for credential rotation in third-party contractor environments
  3. 48+ hour key rotation time โ€” far exceeding CISA's own standards for incident response

Significance for Australia

The incident serves as a case study for Australian government agencies (Acsc, Asd, Home Affairs Cyber) managing cloud infrastructure through third-party contractors. Key lessons: - Automated security tooling is only as good as the escalation path - GovCloud/Protected-level credential management requires contractor auditing - Plaintext passwords in repositories violates ACSC's Essential Eight guidelines

Related Pages

  • Acsc Cms Exploitation โ€” ACSC alert on CMS exploitation (same period)
  • Cisa Fortinet Credential Exposure โ€” CISA alert on Fortinet credential exposure