Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [incident, cisa, data-leak, github, credentials, postmortem] ยท confidence: high ยท affected_sectors: [government] ยท au_impact: true

Lessons Learned from CISA's Recent GitHub Leak

CISA published a postmortem on a data leak in which a contractor published 844 MB of sensitive internal data โ€” including AWS GovCloud keys and plaintext passwords for dozens of internal systems โ€” in a public GitHub repository for nearly six months.

Attribute Detail
Data 844 MB incl. AWS GovCloud keys, plaintext passwords
Exposure window ~6 months in a public GitHub repo
Detection GitGuardian sent 9 automated alerts; KrebsOnSecurity notified CISA in May 2026
Response CISA took 48+ hours to rotate keys; outlined improved reporting channels
Source Krebs on Security โ€” Tier 2/4

The postmortem is a benchmark for third-party contractor access and cloud-credential hygiene โ€” a reminder that sensitive keys and plaintext credentials must never sit in public repositories and that automated secret-scanning alerts need an effective human triage path.

Source