type: incident ยท created: 2026-07-18 ยท updated: 2026-07-18 ยท tags: [incident, cisa, data-leak, github, credentials, postmortem] ยท confidence: high ยท affected_sectors: [government] ยท au_impact: true
Lessons Learned from CISA's Recent GitHub Leak
CISA published a postmortem on a data leak in which a contractor published 844 MB of sensitive internal data โ including AWS GovCloud keys and plaintext passwords for dozens of internal systems โ in a public GitHub repository for nearly six months.
| Attribute | Detail |
|---|---|
| Data | 844 MB incl. AWS GovCloud keys, plaintext passwords |
| Exposure window | ~6 months in a public GitHub repo |
| Detection | GitGuardian sent 9 automated alerts; KrebsOnSecurity notified CISA in May 2026 |
| Response | CISA took 48+ hours to rotate keys; outlined improved reporting channels |
| Source | Krebs on Security โ Tier 2/4 |
The postmortem is a benchmark for third-party contractor access and cloud-credential hygiene โ a reminder that sensitive keys and plaintext credentials must never sit in public repositories and that automated secret-scanning alerts need an effective human triage path.