CISA Data Leak: AWS GovCloud Credentials and Internal Secrets Exposed on GitHub

A public GitHub repository exposed highly privileged AWS GovCloud account credentials and sensitive internal data from the U.S. agency CISA (Cybersecurity & Infrastructure Security Agency) for months. The leak, described by security experts as one of the most severe in recent government history, included cloud keys, tokens, plaintext passwords, and configuration files for critical systems.

Technical Details of the Exposure

The repository, named "Private-CISA," contained numerous credentials and internal files from CISA/DHS. Among the exposed files:

  • "importantAWStokens" with administrative credentials for three AWS GovCloud servers
  • "AWS-Workspace-Firefox-Passwords.csv" with usernames and plaintext passwords for dozens of internal systems
  • Easily guessable passwords based on platform names and years

Philippe Caturegli, founder of the consulting firm Seralys, verified that the exposed credentials could authenticate to three AWS GovCloud accounts with elevated privileges. He also noted the presence of plaintext credentials for CISA's "artifactory," a software package repository used for internal development.

Analysis of Causes

Guillaume Valadon of GitGuardian, who discovered the exposure, observed that the repository showed:

  • Passwords stored in plaintext in CSV files
  • Backups stored in the Git repository
  • Explicit commands to disable GitHub's secret detection feature

Caturegli noted that the repository appeared to be used as a temporary workspace or synchronization mechanism rather than a curated project. The use of an email address associated with CISA and a personal one suggested the repository might have been used in differently configured environments.

Security Implications

The leak represents a serious security risk for several reasons:

  • Access to highly privileged AWS GovCloud systems
  • Possibility of lateral movement within CISA systems
  • Potential for inserting backdoors in software packages

Caturegli observed that practices like using easily guessable passwords pose a serious threat even without external exposure, as malicious actors often use exposed primary credentials within internal networks to expand their reach after initial access to a targeted system.

CISA's Response and Organizational Context

A CISA spokesperson stated that the agency is aware of the exposure and is investigating. Currently, there are no indications that sensitive data has been compromised as a result of this incident. The agency stated it is working to implement additional safeguards to prevent future occurrences.

The repository was made accessible to the public by an employee of Nightwing, a government contractor based in Dulles, Virginia. CISA is currently operating with a fraction of its normal budget and staff, having lost nearly a third of its workforce since the beginning of the second term of the Trump administration.

Timeline and Resolution

The "Private CISA" repository was created on November 13, 2025, while the GitHub account of the contractor was created in September 2018. The repository was made inaccessible shortly after KrebsOnSecurity and Seralys notified CISA of the exposure. However, the exposed AWS keys remained valid for another 48 hours.

This incident raises serious concerns about security practices within CISA and its contractors, highlighting the need for greater vigilance and stricter security checks to prevent future data leaks.

Enhancing Security with Solutions like Nightfall

Incidents like CISA's highlight the need for robust security measures to prevent data leaks. Tools like Nightfall can analyze large amounts of data in real-time to identify sensitive information and block its dissemination. For example, Nightfall can automatically detect and classify passwords, credit card numbers, and other sensitive information in internal communications, reducing the risk of accidental exposure.

Additionally, artificial intelligence can be used to monitor user activities and identify anomalous behaviors that may indicate a cyberattack. For example, a user who suddenly starts downloading large amounts of data could be flagged for further investigation. Using these technologies can help organizations stay ahead of cybercriminals and protect their sensitive data more effectively.

Conclusions

The CISA incident is a powerful reminder of the importance of cybersecurity for organizations handling sensitive data. The combination of lax security practices, staff reductions, and inadequate training can create an environment where data leaks become more likely. To prevent similar incidents in the future, organizations must adopt robust security measures, provide adequate training to staff, and use advanced tools like artificial intelligence to protect their data.

As CISA continues to investigate the incident and implement additional security measures, this episode should serve as a wake-up call for all organizations about the need for greater vigilance and accountability in managing sensitive data.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all liability for the improper use of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.

📰 Source: krebsonsecurity.com ↗
✍️ Elaboration: Sebastiano · GoYou.it