CISA Contractor Exposes Federal Cloud Credentials in Public Repository
The agency tasked with defending federal networks had to improvise its own incident response after a contractor exposed sensitive government system access.
Discovery and Containment
In May 2026, security journalist Brian Krebs reported that a GitGuardian researcher had discovered reams of exposed passwords in a publicly accessible GitHub repository uploaded by a CISA contractor employee. The repository contained administrative credentials, infrastructure-as-code, and keys for accessing AWS GovCloud accounts used by the Cybersecurity and Infrastructure Security Agency.
CISA's Office of the Chief Information Officer removed the repository, preserved evidence for investigation, took the development environment offline, and reset credentials while revoking access for the individual responsible.
Missing Response Playbook
In a July postmortem report, CISA revealed its staff had to build an incident response playbook during the early stages of the incident rather than following a prepared plan. The agency acknowledged its channels for security researchers to report incidents were not well defined.
CISA confirmed no customer or mission data was exposed and determined the credentials had not been used outside CISA environments. The agency used the incident to emphasize the importance of preparing playbooks for anticipated needs before incidents occur.
Lessons for Critical Infrastructure
The agency released its findings to help organizations understand risks associated with delayed vulnerability remediation and insufficient cyber preparedness. CISA highlighted proactive vulnerability management, practiced incident response procedures, and centralized logging as foundational elements for improving cyber defense.
The incident occurred as CISA faced staffing cuts and operated without a permanent director. The repository had been uploaded to a contractor-owned personal GitHub account rather than following proper credential management procedures.