A recent investigation by Truffle Security has revealed a critical vulnerability in cloud security: 768 publicly accessible AWS credentials still provide full administrative access to corporate AWS environments. This alarming discovery underscores ongoing issues in credential rotation and cloud account monitoring.
Persistent Credential Vulnerabilities
Truffle Security re-evaluated 10,616 leaked AWS credentials on August 10, 2026, uncovering that 88% remained valid and functional. These credentials were found across various public platforms such as Git histories, Docker images, and CI/CD logs, demonstrating that exposed keys often remain active long after initial exposure.
Of particular concern are the 526 root access keys and 242 IAM user credentials with AdministratorAccess policy. Such credentials grant comprehensive control over AWS accounts, making them especially dangerous. Root keys are notably risky as they bypass IAM policy restrictions, enabling critical account-level actions.
Widespread Exposure and Consequences
The investigation identified 64,024 unique AWS key pairs within 431,875 public findings. Alarmingly, the median age of these leaked keys was five years, with the oldest dating back over 17 years. Credential rotation was rare, with only 13.7% of keys having newer replacements.
Public repositories can perpetuate exposure even after deletion, as they may be cloned, indexed, or included in datasets. Hugging Face was a major source, with 8,482 active keys across 3,394 datasets. This creates persistent exposure risks, as keys may be redistributed in downstream projects.
Insufficient Cloud Cost Monitoring
Truffle Security’s analysis also highlighted weak cloud cost monitoring. Of 2,754 accounts with readable budget data, only 9.5% had budget alerts configured, with a median alert budget of just $8. Despite low median spending, some accounts incurred significant costs, raising concerns about potential misuse of exposed keys for activities like cryptomining.
Organizations are urged to remove root access keys, rotate exposed IAM keys, and enforce strict key age limits. Regular scans of Git histories, container images, and public datasets are recommended. Using least-privilege IAM roles rather than long-lived access keys is vital for safeguarding production environments.
Future Outlook and Recommendations
Security teams should also configure budget alerts and monitor IAM users with AWSCompromisedKeyQuarantine policies, indicating potential exposure. The launch of TruffleHog AWS Analyze offers a tool to assess the access capabilities of exposed AWS credentials.
In conclusion, immediate action is necessary to mitigate risks posed by exposed AWS credentials. By implementing robust security practices, organizations can protect sensitive cloud environments and prevent costly security breaches.
