Over 9,300 Leaked AWS Access Keys Found Still Active, Giving Full Control of Corporate Accounts

Security firm Truffle Security reported on August 21, 2026 that it has been tracking publicly exposed Amazon Web Services (AWS) access keys since 2022 and found more than 9,300 of them still active and valid as of this month. Of the exposed keys the company could tie to specific organizations, 817 belonged to companies, 526 were AWS “root” keys carrying the highest level of privilege, and 242 were linked to IAM users with full AdministratorAccess, meaning any of these credentials could give an attacker complete control over a company’s cloud infrastructure.

The researchers scanned code repositories, Git history, container images, registries, datasets and CI logs, uncovering 431,875 exposed AWS secrets in total and extracting 64,024 unique keys tied to roughly 50,654 distinct AWS accounts. Of a smaller subset of 10,616 keys that could be re-verified, 88% still authenticated successfully as of August 10. Hugging Face, the popular AI model-sharing platform, was by far the single largest source of exposure, accounting for 8,482 of the leaked keys, nearly 18% of which were root credentials.

Truffle Security found that many of these keys are old and neglected: among entries with a known creation date, the median age was roughly five years, and only about 14% had ever been rotated. Just a small fraction of the accounts examined had budget alerts configured, meaning organizations could face large, unnoticed cloud bills if attackers used the stolen credentials to deploy cryptomining operations, in addition to risks of data theft, deletion, or the creation of hidden backdoor accounts. Amazon said it notifies affected customers whenever it becomes aware of exposed keys and encourages organizations to treat any credential that appears in a public repository as compromised, rotate it immediately, and review IAM permissions regularly.

Read the original report →