Severe data breach: a CISA contractor exposes sensitive credentials on GitHub
Until this weekend, a contractor for the Cybersecurity & Infrastructure Security Agency (CISA) maintained a public repository on GitHub that exposed credentials for several high-privilege AWS GovCloud accounts and a large number of CISA's internal systems. Security experts stated that the public archive included files detailing how CISA builds, tests, and deploys software internally, and that it represents one of the most serious government data leaks in recent years.
Discovery and response
On May 15, KrebsOnSecurity received a report from Guillaume Valadon, a researcher at the security firm GitGuardian. Valadon explained that his company constantly scans public code repositories on GitHub and elsewhere for exposed secrets, automatically alerting involved accounts of any sensitive data exposures. Valadon stated that he contacted CISA because the repository owner was not responding and the exposed information was highly sensitive.
Repository details
The GitHub repository reported by Valadon was named “Private-CISA” and contained a large number of CISA/DHS credentials and internal files, including cloud keys, tokens, plaintext passwords, logs, and other sensitive CISA assets. Valadon stated that the exposed credentials are a glaring example of poor security hygiene, noting that the commit logs in the offending GitHub repository showed that the CISA administrator had disabled GitHub's default setting that blocks users from publishing SSH keys or other secrets in public code repositories.
Impact and vulnerabilities
One of the exposed files, titled “importantAWStokens”, included administrative credentials for three Amazon AWS GovCloud servers. Another exposed file in the public GitHub repository, “AWS-Workspace-Firefox-Passwords.csv”, listed usernames and plaintext passwords for dozens of CISA's internal systems. According to Philippe Caturegli, founder of the security consulting firm Seralys, the systems include one called “LZ-DSO”, which appears to be CISA's secure code development environment.
Investigations and responses
Caturegli stated that he tested the AWS keys only to verify if they were still valid and to determine which internal systems the exposed accounts could access. He stated that the GitHub repository that exposed CISA's secrets exhibits a pattern consistent with an individual operator using the repository as a work notebook or synchronization mechanism rather than as a curated project repository.
In response to questions, a CISA spokesperson stated that the agency is aware of the reported exposure and is continuing to investigate the situation. “Currently, there are no indications that sensitive data has been compromised as a result of this incident,” wrote the CISA spokesperson. “While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure that additional safeguards are implemented to prevent future occurrences.”
Implications
The review of the GitHub repository and its exposed passwords showed that the “Private CISA” repository was maintained by an employee of Nightwing, a government contractor based in Dulles, Virginia. Nightwing declined to comment, referring requests to CISA. CISA did not respond to questions about the possible duration of the data exposure, but Caturegli stated that the Private CISA repository was created on November 13, 2025. The contractor's GitHub account was created in September 2018.
Comments and discussions
The GitHub repository that included the Private CISA repo was taken offline shortly after KrebsOnSecurity and Seralys notified CISA of the exposure. However, Caturegli stated that the exposed AWS keys remained inexplicably valid for another 48 hours. CISA is currently operating with only a fraction of its normal budget and staff. The agency has lost nearly a third of its staff since the beginning of Trump's second term, which has forced a series of early retirements, buyouts, and resignations in various divisions of the agency.
The incident highlights the importance of rigorous security hygiene and robust checks to prevent the exposure of sensitive data. CISA stated that it is working to implement additional safeguards to prevent future occurrences, but the incident raises concerns about the current state of cybersecurity within the agency.
Implications
The incident highlights structural criticalities in the management of cybersecurity within CISA and its partnerships with private contractors. The nature of the exposure - with administrative credentials for cloud systems and plaintext passwords for dozens of internal systems - suggests serious shortcomings in security protocols both at the technical and organizational level. Particularly concerning is the use of banal passwords like "AWS2025" or "CISA2025" for internal resources, a practice that represents a significant risk even in the absence of external exposure.
Philippe Caturegli of Seralys observed that the archive included plaintext credentials for the CISA's "artifactory" - a central repository of software packages used for development. This exposure represents a priority target for malicious actors, who could insert backdoors in software packages to maintain persistent access to the agency's systems.
Technical vulnerability analysis
The technical analysis reveals that the GitHub repository was configured to disable GitHub's automatic secret detection features, thus allowing the exposure of SSH keys, tokens, and passwords. This suggests a lack of adequate oversight over repositories managed by external contractors. Furthermore, the use of a personal GitHub account for work activities created additional vulnerabilities, with possible overlaps between work and personal environments.
The exposed AWS keys remained valid for 48 hours after the report, indicating potential delays in revoking compromised credentials. This time window represents a critical period during which malicious actors could have exploited the exposed credentials.
Organizational impact
The reduction in CISA's staff and budget - with nearly a third of the workforce lost since the beginning of Trump's second term - likely contributed to this incident. The decrease in resources has led to a reduced level of oversight and potentially greater pressure on remaining employees, increasing the risk of human error.
The use of the GitHub repository as a "work notebook" or synchronization mechanism between personal and work devices highlights a lack of clarity in protocols for managing data between personal and work devices.
CISA's incident serves as a warning for all organizations handling sensitive data. The combination of technical errors, organizational shortcomings, and operational pressures has created an environment in which a single misjudgment could lead to one of the most serious data leaks in recent history. While CISA is working on new safeguards, this incident underscores the need for a holistic approach to cybersecurity that considers technical, organizational, and human aspects.
Open questions
Several open questions remain that require further investigation:
- How long did it take for the exposed AWS keys to be revoked?
- What measures have been implemented to verify if the exposed credentials were actually used by malicious actors?
- How extensive was the access to CISA's internal systems through the exposed credentials?
- What are the legal implications for the contractor involved and for the CISA officials responsible for oversight?
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not provide real-time information.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.