At a glance
| Factor | Details |
|---|---|
| Organization | Multiple enterprises, AI developers, and cloud users globally |
| Data Exposed | 64,024 live AWS access key pairs and root credentials |
| Accounts Affected | Over 9,900 distinct AWS accounts, including 768 corporate environments |
| Cause | Public repository commits, AI training datasets, container images, and CI logs |
| Disclosure Status | Direct notification to identifiable account owners and coordinated disclosure |
| Source | Truffle Security |
Security researchers identified thousands of active leaked corporate AWS keys across public datasets and code repositories. These exposed credentials grant administrative control over hundreds of commercial cloud environments. Consequently, attackers can manipulate cloud infrastructure and incur massive financial charges.
What Was Exposed
Security scanners verified 64,024 unique, live AWS access key pairs exposed across 431,875 public findings. Notably, the dataset includes 10,625 root account keys that span 9,945 distinct cloud accounts. Researchers emphasized that “a root key cannot be scoped down.” These root credentials grant unrestricted power over the entire cloud infrastructure.
In addition, researchers analyzed 7,590 active IAM user accounts. Among those that permitted policy inspection, 84 percent held complete administrative permissions. Furthermore, investigators discovered that hundreds of leaked corporate AWS keys carried full administrative permissions. Most alarmingly, 130 exposed root keys controlled entire organization management accounts.

How It Happened
Developers inadvertently committed static credentials into public Git repositories, Docker containers, package registries, and CI logs. Moreover, public machine learning platforms represent the single largest source of exposure. Researchers discovered 8,482 live keys embedded in 3,394 public Hugging Face datasets.
As Truffle Security explained, “A key committed once ends up tokenized into corpora that thousands of downstream projects download.”
Furthermore, organizations rarely rotated these exposed secrets. The investigation revealed that “the median live leaked key was created 1,831 days ago.” In fact, 86 percent of examined credentials were never superseded or revoked.
Who Is Affected
The exposure impacts software companies, cloud providers, and IT consulting organizations worldwide. In one instance, a global consulting firm leaked 19 separate keys across independent enterprise accounts.
Meanwhile, only 9.5 percent of exposed accounts had configured budget alerts. During July 2026, accounts behind readable keys generated $420,631 in cloud spending. Researchers observed that “the typical leaked key opens an abandoned experiment that costs its owner nothing.”
What Affected People Should Do
Administrators must immediately review and delete all root access keys. In addition, teams should audit IAM key age by establishing strict rotation limits. Organizations must protect against leaked corporate AWS keys by enforcing strict credential hygiene.
Organizations should also configure basic billing alarms to detect unauthorized compute activity immediately. Finally, security teams must monitor for the quarantine policy applied by AWS. This tag signals that AWS detected a public credential leak.
Company Response
Truffle Security stated that “no key material is published, and every owner we could identify is being notified.” The research team coordinated with AWS to flag compromised identities. According to the report from Truffle Security, defenders must treat every public commit as a permanent credential exposure.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.