CISA Contractor Sparks Historic Data Leak by Exposing AWS GovCloud Keys on GitHub
- Grace N
- 2 hours ago
- 1 min read

A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) inadvertently caused one of the most egregious government data leaks in recent history by exposing highly privileged AWS GovCloud administrative keys and internal system passwords on a public GitHub repository. The exposure was made significantly worse because the administrator explicitly disabled GitHub's built-in secret detection features, leaving sensitive U.S. government infrastructure wide open to potential attackers.