Interestana
Home/News/Thousands of Leaked AWS Keys Grant Full Corporate Account Control
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Thousands of Leaked AWS Keys Grant Full Corporate Account Control

More than 9,300 Amazon Web Services (AWS) access keys, publicly exposed between August 2022 and August 2026, are still active and valid, granting attackers full control over corporate accounts. These credentials, which allow users to programmatically access AWS services, were found on public code repositories and cloud storage services. The ongoing validity of these keys presents a significant security risk, as they can be exploited to access sensitive data, deploy malicious infrastructure, or incur substantial costs through unauthorized resource usage.

Security researchers at cloud security firm Wiz identified the exposed keys and reported that approximately 15% of them were still active as of their analysis. This indicates a persistent vulnerability in how organizations manage their cloud credentials. The keys, when active, provide the same level of access as if a legitimate user were logged in, enabling actions such as data exfiltration, unauthorized modifications to cloud resources, and the potential for widespread disruption. The sheer volume of exposed keys suggests a systemic issue with credential management practices across numerous organizations.

The implications of these exposed keys are far-reaching. Attackers could leverage them to gain unauthorized access to sensitive customer data, intellectual property, or financial information stored within AWS environments. Furthermore, they could deploy ransomware, launch denial-of-service attacks, or use the compromised accounts for cryptocurrency mining, leading to significant financial losses and reputational damage for the affected companies. The prolonged period during which these keys have remained exposed, spanning over four years, highlights a critical gap in security monitoring and remediation processes.

AWS provides robust security features, including identity and access management (IAM) tools, to help customers control access to their resources. However, the continued presence of active, exposed keys underscores the importance of diligent credential rotation, least privilege principles, and continuous monitoring for suspicious activity. Organizations are urged to immediately audit their AWS environments for any exposed access keys, revoke any found credentials, and implement stricter access control policies to prevent future incidents. The findings serve as a stark reminder of the ongoing threats in the cloud security landscape and the necessity of proactive security measures.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next