What's Happening?
Truffle Security has revealed that more than 9,300 Amazon Web Services (AWS) access keys, publicly exposed between August 2022 and August 2026, are still active and valid. Out of these, 817 keys were linked to companies, with 526 identified as AWS root
keys, which possess the highest level of privilege. The researchers found that 242 of these keys are associated with Identity and Access Management (IAM) users having AdministratorAccess policy, granting full permissions across virtually all AWS services and resources. A significant portion, 88% of the 10,616 re-verified keys, remained active as of August 10. The median age of the exposed keys with available creation dates was 1,831 days (approximately five years), with the oldest existing for 17.4 years, and only 13.7% had been rotated.
Why It's Important?
The continued activity of thousands of leaked AWS keys presents a severe security risk for corporate accounts. Attackers gaining full control of an AWS account could access, exfiltrate, or wipe cloud-hosted data, take over servers and applications, and establish persistent access through rogue administrator accounts. This vulnerability could lead to significant data breaches, operational disruptions, and financial losses for affected companies. Furthermore, threat actors could exploit this access to deploy cryptominers, incurring substantial and unexpected charges for the victim organizations, especially since only a small fraction of readable accounts had budget alerts configured. The long-term exposure and infrequent rotation of these keys highlight a systemic issue in credential management and security practices among some AWS users, making them susceptible to prolonged compromise. Hugging Face, a platform for AI models, was identified as the largest single source of leaked AWS keys, accounting for 8,482 unique exposures.
What's Next?
Truffle Security recommends several immediate actions to mitigate these risks. Companies should delete all root access keys, review IAM credentials based on their age, and promptly rotate or revoke any exposed keys. Implementing budget alerts is also advised to detect unauthorized resource usage. Any credential committed to a public source should be immediately considered compromised. Truffle Security has stated that its testing was limited to read-only metadata and that it has notified all identifiable owners of the exposed credentials. This ongoing issue underscores the need for continuous monitoring and proactive security measures within cloud environments to prevent unauthorized access and data breaches. AWS users are expected to enhance their security protocols and regularly audit their access keys to prevent such long-term exposures.
Beyond the Headlines
This incident highlights a critical challenge in cloud security: the human element in credential management. Despite the advanced security features offered by cloud providers like AWS, misconfigurations and negligence in handling access keys can lead to severe vulnerabilities. The long lifespan of many exposed keys suggests a lack of regular security audits and credential rotation policies within organizations. This situation also points to the broader implications of supply chain security, as platforms like Hugging Face, which facilitate development and collaboration, can inadvertently become sources of credential leaks. The findings emphasize the importance of a 'assume breach' mentality, where organizations must not only prevent initial access but also detect and respond to compromised credentials quickly. This ongoing threat necessitates a cultural shift towards more rigorous security practices, automated credential management, and continuous education for developers and IT professionals working with cloud services.











