Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
leaked-secret-api-keythird-party-vendor-breachgovernment-diplomatic-threatcloud-misconfiguration

CISA Contractor GitHub Repository Exposed AWS GovCloud Keys and Internal Credentials

Updated 27d agoFirst seen May 18, 202622 sources

A public GitHub repository tied to a contractor supporting the U.S. Cybersecurity and Infrastructure Security Agency (CISA) exposed plaintext passwords, access tokens, cloud keys, logs, spreadsheets, and deployment files that could provide access to CISA and Department of Homeland Security internal and cloud systems. Researchers from GitGuardian and Seralys reported that the repository, named "Private-CISA", contained administrative credentials for three AWS GovCloud accounts as well as numerous credentials for internal CISA systems; some of the exposed secrets were verified as valid.

The repository was reportedly linked to a Nightwing employee and appears to have been used as an informal working scratchpad rather than a controlled code repository, with commit history indicating GitHub secret-scanning protections had been disabled. After alerts to the contractor reportedly went unanswered, the issue was escalated and the GitHub account was taken offline, but exposed AWS keys were said to remain valid for roughly 48 hours after disclosure. CISA said it is investigating and that it had no indication the credentials were abused, though the incident represents a significant security lapse at the federal agency responsible for civilian cybersecurity.

Share:
CISA Contractor GitHub Repository Exposed AWS GovCloud Keys and Internal Credentials
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

8 events from the most recent confirmed update back to the earliest known activity.

8 EVENTS
May 22, 20261mo ago

CISA still rotating exposed credentials more than a week after notification

Researchers said that more than a week after GitGuardian notified CISA of the exposed repository, the agency was still revoking and rotating leaked credentials. The remaining remediation reportedly included an RSA private key that could have enabled broad access to CISA's GitHub environment and CI/CD infrastructure.

Lawmakers Demand Answers as CISA Tries to Contain Data Leak - Krebs on Security
May 19, 20261mo ago

Congressional Democrats demand briefings from CISA over credential leak

Lawmakers including Rep. Bennie Thompson, Rep. Delia Ramirez, and Sen. Maggie Hassan requested briefings from acting CISA Director Nick Andersen on the cause, impact, remediation, and oversight failures tied to the exposed GitHub repository. The request marked a congressional oversight response to the incident.

CISA credential leak raises alarms, and Capitol Hill demands answers | CyberScoop
May 18, 20261mo ago

CISA says it is investigating and sees no evidence of compromise

CISA acknowledged the exposure and said it was investigating the incident. The agency stated there was no indication that sensitive data had been compromised as a result of the leak.

Contractor GitHub account is taken offline after notification

Following notification about the exposed repository, the contractor's GitHub account was removed from public access. Despite that action, reports said some exposed AWS GovCloud credentials remained valid for about 48 hours afterward.

Researchers escalate after contractor fails to respond to alerts

After attempts to notify the contractor about the exposed secrets did not receive a response, the researchers escalated the issue to prompt remediation. The exposure was characterized by one researcher as among the worst credential leaks he had seen.

Researchers discover exposed CISA and DHS credentials in GitHub repo

Security researchers from GitGuardian and Seralys found a public repository containing plaintext passwords, access tokens, AWS GovCloud keys, logs, spreadsheets, and deployment information tied to CISA and Department of Homeland Security systems. Some of the exposed credentials were verified as valid, indicating potential access to internal and cloud environments.

May 14, 20262mo ago

GitGuardian researcher discovers exposed 'Private-CISA' repo

GitGuardian researcher Guillaume Valadon found a publicly accessible GitHub repository named 'Private-CISA' containing extensive CISA-related secrets and infrastructure material. He reported the exposure to CISA on May 14 after determining the repository had been publicly accessible for roughly six months.

America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens - and incredibly obvious filenames
Nov 13, 20258mo ago

Contractor creates public GitHub repository tied to CISA work

A GitHub repository later identified as exposing sensitive CISA-related data was reportedly created by a contractor employee and linked to work supporting CISA. The repository was created publicly and became the location where credentials and operational files accumulated.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

43 LINKEDOpen in app
Affected products
8 linked
GithubAmazon Web ServicesFirefoxMicrosoft Entra IdKubernetesChatgptSignalArtifactory
Organizations
35 linked
GitHubGitGuardianAmazon Web ServicesTruffle SecurityRisky BusinessKrebsOnSecurityNightwingAxiosJfrogOpenaiYahooSeralysKeeper SecurityCisco SystemsStandard CharteredThe RegisterXcape IncTom's HardwareTechCrunchFedexBlack DuckRecorded FutureDark ReadingNetskopeInfobloxWatchTowrRubrikKrebs on SecurityTechTargetNextgov/FCWVARBusiness MagazineCRNSuzu LabsTech RadarBizLink Tech Group
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.