Hundreds of exposed AWS keys still give full control over corporate accounts
More than 768 active Amazon Web Services access keys exposed between August 2022 and August 2026 still give full control over corporate cloud accounts, Truffle Security said.
Source: BleepingComputer · August 22, 2026 at 1:08 AM · AI-assisted report
Single-sourceKUALA LUMPUR, 22 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
More than 768 active Amazon Web Services access keys exposed between August 2022 and August 2026 still give full control over corporate cloud accounts, Truffle Security said.
Market Impact
The security firm tracked 9,300 AWS keys made public during the four-year period and found 768 that remained valid. Of those, 242 belong to Identity and Access Management users with the AdministratorAccess policy, which grants unrestricted rights to create, modify, delete and view virtually all AWS services and resources. Each of the 768 live keys “grants full control of a company’s AWS account,” Truffle Security said.
Truffle Security extracted 64,024 unique AWS keys from code repositories, Git history, Docker images and CI logs, corresponding to 50,654 AWS accounts after removing duplicates. It verified 10,616 keys and found that 88% were still authenticating as of August 10. Attackers can use such access to deploy cryptominers, potentially racking up large cloud charges; only 262 of 2,754 readable accounts had budget alerts enabled.
Hugging Face, a platform where developers share AI models, datasets and applications, was the largest single source of leaked AWS keys, accounting for 8,482 unique exposures. Of those, 17.9% were root keys—the highest-privileged identities not restricted by IAM permissions.
For the 2,903 keys with creation dates, the median age was 1,831 days (about five years), and the oldest had existed for 17.4 years. Only 398 (13.7%) had a newer access key associated with the same user, indicating most had never been rotated.
Truffle Security recommends deleting all root access keys, reviewing IAM credentials by age, rotating or revoking exposed keys, configuring budget alerts and treating any credential committed to a public source as compromised. Truffle Security said its testing was limited to read-only metadata and that it had notified all identifiable owners of the exposed credentials.
Once attackers use valid credentials, signature-based prevention falls to 50%, according to the Blue Report 2026, which measured defenses across 338 million simulations in customer production environments.
Related: Amazon