Hundreds of leaked AWS keys give full control over corporate accounts

Executive Summary

Over 9,300 AWS access keys were publicly exposed from August 2022 to August 2026 and remain active. The leaked credentials grant full administrative control over corporate AWS accounts, enabling attackers to manipulate resources, exfiltrate data, and deploy malicious workloads. The exposure highlights ongoing credential management gaps and the need for stricter key rotation and monitoring.


Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-21T15:55:15+00:00 - Category: threat-intel

Original Description: More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]

"Some people thrive on huge, dramatic change. Some people prefer the slow and steady route. Do what's right for you."

— Julie Morgenstern
Source: Bleeping Computer