I
Agentic Intelligence · Infomly

768 leaked AWS keys still work. Full admin rights. Median age: 5 years.

AI-Assisted Content — Produced with AI assistance and human editorial review. Learn more
Truffle Security just re-verified 10,616 leaked AWS credential pairs.

88% still authenticated.

768 of those corporate keys have full administrative control — 526 root keys plus 242 IAM users with AdministratorAccess.

Your attacker doesn't need to hack you. Your developer left the door open five years ago and nobody checked.

The median leaked key was 5 years old. The oldest was 17.4 years. Only 13.7% showed evidence of ever being rotated. AWS had already flagged 929 of them with its CompromisedKeyQuarantine policy — and they still authenticated.

Where did these keys leak? Git history. Docker images. Package registries. CI logs. And — critically — Hugging Face datasets were the largest single source, with 8,482 unique live keys across 3,394 public datasets.

Your AI pipeline is leaking credentials faster than your security team can count them.

Run a TruffleHog scan today. Delete every root access key. Rotate anything older than 90 days. Enable budget alerts on every account. If a credential has ever touched a public repo, it is compromised — regardless of when you committed it.

SOURCE: https://trufflesecurity.com/blog/leaked-corporate-aws-keys-held-full-admin-rights
VERIFIED: Truffle Security research (Aug 19), eSecurity Planet (Aug 24), BleepingComputer (Aug 21), GBHackers (Aug 22)
SIGNAL: Enterprise credential hygiene has failed at scale. 768 live admin keys — some flagged as compromised and still working — is a CISO-level crisis that the AI toolchain is making worse.
💬 Consultation · Got questions? Talk to an expert →
Enterprise AI Impact — filtered for signal, not noise The AI briefing CTOs read before their morning meeting 3 minutes. Zero fluff. Only what moves the needle. $5/mo — your cheapest competitive edge
Subscribe — $5/mo

0 Comments

No comments yet. Be the first.