Executive Summary

Between August 2022 and August 2026, Truffle Security discovered over 9,300 Amazon Web Services (AWS) access keys publicly exposed across code repositories, Git history, datasets, Docker images, and CI logs. Of these, 817 keys were linked to corporate accounts, with 526 being AWS root keys granting unrestricted administrative access. Researchers found that 242 keys belonged to IAM users with AdministratorAccess policies, effectively providing full control over corporate AWS environments. Hugging Face emerged as the largest single source with 8,482 exposed keys, many remaining active for years without rotation.

This incident highlights the persistent challenge of credential management in cloud environments as organizations increasingly rely on Infrastructure as Code and automated deployment pipelines. With the median age of exposed keys being over five years and only 13.7% showing evidence of rotation, the findings underscore critical gaps in security hygiene that threat actors actively exploit for cryptomining operations, data exfiltration, and persistent access establishment.

Why This Matters Now

Cloud credential exposure continues to escalate as organizations accelerate digital transformation and adopt DevOps practices without proper secret management, creating widespread attack surfaces that threat actors increasingly target for initial access and privilege escalation.

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

Regular credential rotation, implementing secrets management solutions, enabling budget alerts, and treating any publicly committed credentials as immediately compromised would have significantly reduced exposure risks.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.

Aviatrix Zero Trust CNSF would have significantly constrained this AWS access key compromise by implementing network segmentation and identity-aware controls that limit lateral movement and reduce blast radius across cloud services and regions.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: Network microsegmentation would likely have limited the scope of services and resources accessible even with compromised credentials, constraining initial foothold establishment across cloud infrastructure components.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: Workload isolation policies would likely have constrained the blast radius of administrative privileges, limiting cross-service access even with escalated credentials to reduce account-wide compromise scope.

Lateral Movement

Control: East-West Traffic Security

Mitigation: Microsegmentation enforcement would likely have blocked unauthorized lateral movement between services and regions, significantly constraining attacker ability to traverse cloud infrastructure boundaries and expand compromise scope.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: Centralized policy enforcement would likely have detected and constrained suspicious cross-region API activity patterns, limiting persistent control establishment across distributed cloud infrastructure and reducing operational persistence.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Controlled egress policies would likely have restricted unauthorized data transfer patterns from sensitive storage services, constraining exfiltration volume and limiting outbound data movement to approved destinations.

Impact (Mitigations)

Resource-intensive cryptomining operations would likely remain isolated within specific workload segments, limiting computational impact scope and reducing unauthorized charges through constrained resource allocation and network boundaries.

Impact at a Glance

Affected Business Functions

  • Cloud Infrastructure Management
  • Data Storage and Backup Systems
  • Application Hosting Services
  • Identity and Access Management
Operational Disruption

Estimated downtime: N/A

Financial Impact

Estimated loss: N/A

Data Exposure

Over 9,300 AWS access keys publicly exposed with 817 linked to companies, including 526 root keys and 242 keys with AdministratorAccess policy providing full control over corporate AWS accounts. Potential access to cloud-hosted data, servers, applications, and ability to create persistent admin accounts across affected organizations.

Recommended Actions

  • Implement Zero Trust Segmentation with identity-based policies to limit blast radius even when credentials are compromised
  • Deploy Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and cryptominer communications
  • Enable Multicloud Visibility & Control for centralized monitoring of anomalous AWS API usage patterns
  • Configure Threat Detection & Anomaly Response to baseline normal cloud resource consumption and alert on suspicious activities
  • Establish comprehensive credential rotation policies and eliminate root access keys as recommended by AWS security best practices

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image