More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.
Truffle Security has been tracking this exposure for the past four years and says that 817 of the exposed keys were linked to companies, 526 of them being AWS root keys.
According to the researchers, 242 of the keys are associated with Identity and Access Management (IAM) users with the AdministratorAccess policy. This role has full permissions to create, modify, delete, and view virtually all AWS services and resources within an account.
They note that each key of the 768 live keys in the two sets “full control of a company’s AWS account.”
The company found 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries, and CI logs and extracted 64,024 unique AWS keys that corresponded to 50,654 AWS accounts after removing duplicates.
However, the subset for which the researchers had complete credentials that could be used for re-verification was 10,616 keys, and 88% of them continued to authenticate as of August 10.
Amazon Web Services (AWS) is Amazon’s cloud-computing platform used by companies to host websites and applications, store data, run databases and servers, manage domains, and operate their online infrastructure.
Full control of a company’s AWS account could allow an attacker to access, exfiltrate, or wipe cloud-hosted data, take control of servers and applications, and create rogue admin accounts for persistent access
Threat actors could also use their access to deploy cryptominers, generating substantial charges for the company. Truffle Security says that only 262 of 2,754 readable accounts had a budget alert set up.
Hugging Face, a popular online platform where developers share AI models, datasets, and applications, was the largest single source of leaked AWS keys, accounting for 8,482 unique key exposures.
Also, 17.9% of those keys were root, meaning the highest-privileged identity, which isn’t restricted by IAM permissions.
Truffle Security found that, for the 2,903 keys with available creation dates, the median age was 1,831 days (about five years), while the oldest had existed for 17.4 years.
Only 398 (13.7%) of those entries had a newer access key associated with the same user, suggesting most had never been rotated.
To defend against potential abuse, the researchers recommend deleting all root access keys, reviewing IAM credentials by age, rotating or revoking exposed keys, and configuring budget alerts.
Also, any credential committed to a public source should be treated as compromised.
Truffle Security said its testing was limited to read-only metadata, and that it has notified all identifiable owners of the exposed credentials.
Update 22/8 – An Amazon spokesperson sent BleepingComputer the following statement about Truffle Security’s findings:
“Anytime AWS is aware of exposed keys, we notify the affected customers. We also thoroughly investigate all reports of exposed keys and quickly take any necessary actions, such as applying quarantine policies to minimize risks for customers without disrupting their IT environment. To report any security concern to AWS, including exposed customer credentials, please email aws-security@amazon.com (PGP key).”
“AWS helps customers secure their cloud resources through a shared responsibility model. We encourage all customers to follow security, identity, and compliance best practices. In the event a customer suspects they may have exposed their credentials, they can start by following the steps listed in this post. As always, customers can contact AWS Support with any questions or concerns about the security of their account.” – AWS spokesperson
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
whoAMI attacks give hackers code execution on Amazon EC2 instances
Sakura Internet hack exposes data of up to 1.36 million accounts
OpenAI agent used exposed credentials at 4 services in Hugging Face breach
OpenAI models used Artifactory zero-days to escape to the internet
OpenAI says its AI models hacked Hugging Face during testing
Microsoft patches max severity code execution, privilege escalation flaws
Microsoft rolls out Classic Outlook theme for New Outlook users
Microsoft blames Windows gaming issues on RGB lighting devices
Certighost CVE is new. The privilege behind it isn’t. Discover where yours is hiding.
Signature-based prevention fell to 50%. See what your controls still stop.
Protect yourself from data brokers, scammers, and the next data breach with digital identities.
Stay one step ahead of new threats in the new year. Join Huntress for the monthly Tradecraft Tuesday.
Discover how least agency keeps your AI tools capable, controlled, and secure.
See how AI is reshaping email attacks. Download the 2026 Kaseya Email Security Report.
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.



