Breaches · 63 days ago
The break is in what teams store inside a build repository, not in the source tree itself. In CISA’s case, a contractor copied a build and deployment repo to a personal GitHub account, and that bundle included administrator and build credentials plus Infrastructure as Code data that held AWS GovCloud keys.
CISA says logs showed no authorized use of the leaked credentials and no customer or mission data exposure. The point is that IaC and deployment artifacts can carry working secrets, so a repo copy can move cloud-admin access out of the controlled environment and into a personal account.
3 sources covering this story
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for almost six months…
CISA Details Incident Response to Exposed AWS GovCloud Keys
CISA reveals how it responded after sensitive AWS GovCloud credentials and internal data were exposed in a public GitHub repository
CISA details security lapses that led to GitHub leak of passwords, cloud access keys
The agency’s blog post came as lawmakers pressed the agency for answers.
Part of the PlainSec briefing for 2026-07-13