88% of 9,300 leaked AWS keys still active — 768 give full control over corporate accounts

Truffle Security researchers have found that more than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 remain active and valid. Over four years of monitoring, the team identified 817 keys tied to corporate accounts, with 526 of them being AWS root keys.
Of the exposed keys, 242 belong to Identity and Access Management (IAM) users with the AdministratorAccess policy, granting full permissions to create, modify, delete, and view virtually all AWS services and resources within an account. The researchers emphasize that each of the 768 live keys in the two analyzed sets provides "full control of a company's AWS account."
In total, Truffle Security discovered 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries, and CI logs. After removing duplicates, they extracted 64,024 unique AWS keys corresponding to 50,654 AWS accounts. From a subset of 10,616 keys for which complete credentials were available for re-verification, 88% continued to authenticate successfully as of August 10.
AWS is Amazon's cloud-computing platform used by companies to host websites and applications, store data, run databases and servers, manage domains, and operate their online infrastructure. Full control of a company's AWS account could allow an attacker to access, exfiltrate, or wipe cloud-hosted data, take control of servers and applications, and create rogue admin accounts for persistent access. Threat actors could also use their access to deploy cryptominers, generating substantial compute costs at the victim's expense.


