Truffle Security Reports Over 9,300 Leaked AWS Keys Remain Active, Posing Corporate Account Risks
Truffle Security has revealed that more than 9,300 Amazon Web Services (AWS) access keys, publicly exposed between August 2022 and August 2026, are still active and valid. Out of these, 817 keys were linked to companies, with 526 identified as AWS root keys, which possess the highest level of privilege. The researchers found that 242 of these keys are associated with Identity and Access Management (IAM) users having AdministratorAccess policy, granting full permissions across virtually all AWS services and resources. A significant portion, 88% of the 10,616 re-verified keys, remained active as of August 10. The median age of the exposed keys with available creation dates was 1,831 days (approximately five years), with the oldest existing for 17.4 years, and only 13.7% had been rotated.