768 Corporate AWS Keys Exposed, Still Grant Full Admin Privileges

An extensive cloud security review by Truffle Security has uncovered that 768 AWS credentials tied to businesses—and offering full administrative access—remain active despite being publicly exposed. The affected credentials were identified among more than 10,600 leaked AWS key pairs discovered between August 2022 and August 2026. Truffle verified these keys on August 10, 2026. The continued validity of most of them underscores widespread neglect around credential maintenance, secret management, and cloud monitoring. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/))

Within the sample of leaked credentials, Truffle found that about 88% still worked, letting malicious actors fully command compromised AWS accounts. Of the 768 active keys tied to corporate settings, 526 were root access keys and 242 belonged to IAM users with the AdministratorAccess policy—both roles effectively offer complete control over the environment. Root credentials are especially perilous as they bypass IAM policy controls and allow high-impact changes, even to account-wide security settings. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/))

Sources, Persistence & Weak Rotation Practices

The exposed credentials popped up in Git history, Hugging Face datasets, Docker images, package registries, and CI/CD logs. Some were years old—the median leak was five years old, with the oldest dating back over 17 years. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/)) Almost half of the credentials were found in more than one place, meaning exposure spreads far beyond a single leak. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/))

Rotation is barely happening. Among over 2,900 keys allowing enumeration of access keys, only 13.7% had replacements issued. Most credentials exposed publicly remain untouched once they’re published. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/))

Budget Blindspots & Abuse Risks

Truffle Security also found serious gaps in cost monitoring: only about 9.5% of the 2,754 AWS accounts it reviewed had budget alerts configured. The median budget alert threshold was just $8. Despite low median spend, 50 accounts exceeded $1,000 in the previous month, and nine spent more than $10,000. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/)) Leaked keys are not benign—they can be used for cryptomining, resource deployment, data theft, or to get deeper into an organization’s cloud environment. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/))

Recommendations to Mitigate Exposure

To close these gaping vulnerabilities, companies should immediately disable all root access keys. Any IAM credentials that have been exposed or are no longer essential must be rotated or removed. Keys should have a short maximum lifetime. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/))

Visibility is also critical. Security teams need to scan not only active source code but also Git histories, container images, CI/CD logs, package registries, and public datasets. Rather than relying on long-lived access keys, organizations should employ least-privilege IAM roles for production tasks. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/)) AWS accounts should also deploy budget alerts and investigate IAM users set up with AWS’s CompromisedKeyQuarantine policy, which signals that the provider has flagged possible credential exposure. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/))

Truffle Security has backed this report with a newly launched tool, TruffleHog AWS Analyze. It helps organizations identify what leaked credentials already have access to—policies, roles, trust relationships, and more. ([cybersecuritynews.com](https://cybersecuritynews.com/768-leaked-corporate-aws-keys-remain-active/))

This investigation reveals how deeply rooted the issues of credential exposure and inactive security controls are in cloud infrastructure. Leaked keys, once public, often remain active and continue to pose a risk far beyond their initial leak date, especially when organizations fail to rotate or revoke them. What matters now is how swiftly defenders adopt preventive practices to minimize long-term damage and stop exposures from snowballing.