CISA Contractor Exposes Federal Cloud Credentials in Public Repository

The agency tasked with defending federal networks had to improvise its own incident response after a contractor exposed sensitive government system access.

Illustration: CISA Contractor Exposes Federal Cloud Credentials in Public Repository
AI-generated illustration · Sylvaris

Discovery and Containment

In May 2026, security journalist Brian Krebs reported that a GitGuardian researcher had discovered reams of exposed passwords in a publicly accessible GitHub repository uploaded by a CISA contractor employee. The repository contained administrative credentials, infrastructure-as-code, and keys for accessing AWS GovCloud accounts used by the Cybersecurity and Infrastructure Security Agency.

CISA's Office of the Chief Information Officer removed the repository, preserved evidence for investigation, took the development environment offline, and reset credentials while revoking access for the individual responsible.

Missing Response Playbook

In a July postmortem report, CISA revealed its staff had to build an incident response playbook during the early stages of the incident rather than following a prepared plan. The agency acknowledged its channels for security researchers to report incidents were not well defined.

CISA confirmed no customer or mission data was exposed and determined the credentials had not been used outside CISA environments. The agency used the incident to emphasize the importance of preparing playbooks for anticipated needs before incidents occur.

Lessons for Critical Infrastructure

The agency released its findings to help organizations understand risks associated with delayed vulnerability remediation and insufficient cyber preparedness. CISA highlighted proactive vulnerability management, practiced incident response procedures, and centralized logging as foundational elements for improving cyber defense.

The incident occurred as CISA faced staffing cuts and operated without a permanent director. The repository had been uploaded to a contractor-owned personal GitHub account rather than following proper credential management procedures.

sources
more in Security
Upbound breach enabled $13 million in fraudulent Acima leases Stolen customer data was directly weaponized to create fraudulent financial contracts, demonstrating how breach data enables immediate financial crime. Fake job interview delivers malware through Git hooks in take-home coding projects Attackers are weaponizing the technical interview process itself, embedding malicious Git hooks in legitimate-looking coding assignments to compromise developer workstations. South Korea National Diplomatic Academy breach exposes global diplomat data after ten-month intrusion A prolonged breach of diplomatic training infrastructure exposed sensitive personnel data of current and former foreign service officers worldwide, demonstrating the targeting of government educational systems.