Hundreds of leaked AWS keys give full control over corporate accounts
Executive Summary
Over 9,300 AWS access keys were publicly exposed from August 2022 to August 2026 and remain active. The leaked credentials grant full administrative control over corporate AWS accounts, enabling attackers to manipulate resources, exfiltrate data, and deploy malicious workloads. The exposure highlights ongoing credential management gaps and the need for stricter key rotation and monitoring.
Intelligence Metadata - Source Publisher: Bleeping Computer - Published Date: 2026-08-21T15:55:15+00:00 - Category: threat-intel
Original Description: More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
"Some people thrive on huge, dramatic change. Some people prefer the slow and steady route. Do what's right for you."
— Julie Morgenstern