Researchers discovered 768 leaked AWS keys that are still operational, and the containment policy allows for many possibilities.

Researchers discovered 768 leaked AWS keys that are still operational, and the containment policy allows for many possibilities.

      Truffle Security discovered 768 leaked AWS keys that provide complete control over corporate accounts, including 526 root keys, with 88% of the examined credentials still active. AWS implements a quarantine policy for keys identified as leaked, which still allows numerous harmful actions.

      Researchers reported finding 768 compromised Amazon Web Services keys that continue to enable full access to a company’s account. Among these exposed credentials were 526 root keys, representing the highest level of privilege an AWS customer can have.

      The large number of findings is due to the extensive nature of the investigation. Truffle Security gathered 431,875 AWS secrets from various sources such as repositories, git history, datasets, Docker images, and CI logs, narrowing them down to 64,024 unique keys, and tested those with complete credential access.

      Most of these credentials were still functional. As of August 10, 88% of the verified keys continued to authenticate successfully, out of 10,616 tested.

      The largest single source was not a traditional code host. Hugging Face was responsible for 8,482 unique key exposures, illustrating how model repositories can adopt practices from software repositories.

      There is little evidence of key rotation. The median age of keys with known creation dates was around five years, and only 13.7% had a newer key issued for the same user.

      Amazon responds to detected leaks by applying a quarantine policy designed to minimize fraud-related damage while maintaining, in its words, the functionality of existing resources, amid a growing issue of credential theft.

      In an article for The Register, cloud economist Corey Quinn argues that this policy allows too many permissions to remain intact. Quarantined credentials can still perform certain functions in the account, execute commands on running instances, halt CloudTrail logging, and erase the audit trail completely.

      One concerning example is that writing to a bucket is permitted, along with setting object locks and retention, enabling an attacker to fill storage and enforce compliance-mode retention that cannot be altered by anyone, including AWS support, without deleting the entire account.

      This analysis reflects one professional's interpretation of a published policy rather than an actual incident, and it’s also a checklist that anyone can reference against Amazon’s own documentation, which is a disconcerting aspect.

      For European firms, this situation presents a particular challenge. Financial institutions have been governed by the Digital Operational Resilience Act since January 2025, and TNW has reported that many of them are not adequately prepared.

      A five-year-old root key in a public dataset exemplifies the third-party technology risks that these regulations require companies to identify and document. The lack of key rotation is contrary to the expectations of control that the regulation assumes should be in place.

Other articles

Letara secures ¥2.6 billion (approximately $16 million) for hybrid rocket engines that are not classified as explosive by law. Letara secures ¥2.6 billion (approximately $16 million) for hybrid rocket engines that are not classified as explosive by law. Letara has secured approximately $16 million for hybrid rocket engines powered by plastic, in an area where Germany's HyImpulse raised €45 million the previous year. Anthropic could secure $100 billion, which is ten times the size of Europe's largest public offering in many years. Anthropic could secure $100 billion, which is ten times the size of Europe's largest public offering in many years. Anthropic may generate approximately $100 billion through a listing in October, with investors projecting a valuation of at least $2 trillion. The company has stated that it has not established a specific target. A geothermal company that has been in operation for 60 years has recently transitioned into the AI infrastructure sector. A geothermal company that has been in operation for 60 years has recently transitioned into the AI infrastructure sector. Ormat has made a 150MW geothermal agreement with Google in Nevada, whereas Europe is addressing the same data center needs by encouraging households to reduce their energy consumption. AI data centers are acquiring the capacitors that automakers require. AI data centers are acquiring the capacitors that automakers require. Chinese automakers report that there is a 20-30% shortage of circuit boards and capacitors, with prices more than tripling due to demand from AI data centers. TikTok will pay $400 million for violations related to children's privacy, a figure that Europe achieved in 2023. TikTok will pay $400 million for violations related to children's privacy, a figure that Europe achieved in 2023. TikTok and ByteDance will pay $400 million to resolve the children's privacy lawsuit in the US. In 2023, Ireland imposed a fine of €345 million on the company for similar issues. Oura faced a lawsuit regarding claims that its sleep-tracking features are misleading. Oura faced a lawsuit regarding claims that its sleep-tracking features are misleading. Oura is confronting a proposed class-action lawsuit that alleges the company exaggerated the accuracy of its smart rings in tracking sleep stages.

Researchers discovered 768 leaked AWS keys that are still operational, and the containment policy allows for many possibilities.

Researchers discovered 768 leaked AWS keys that still provided complete account access, which included 526 root keys, and 88% of the tested credentials remained valid for authentication.