Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys have been publicly exposed between August 2022 and August 2026, with 817 linked to companies and 242 associated with Identity and Access Management (IAM) users with AdministratorAccess policy.
Intelligence analysis by Llama

A security researcher has discovered hundreds of leaked AWS keys that grant full control over corporate accounts, allowing attackers to access, exfiltrate, or wipe cloud-hosted data, take control of servers and applications, and create rogue admin accounts.
Imagine you have a super powerful key that can unlock and control all the doors in your house. If someone finds that key and uses it to lock you out, you'll be in big trouble. That's what's happening with these exposed AWS keys - they're like super powerful keys that can control all the cloud data and servers. If someone gets their hands on them, they can do a lot of damage.
Analysis
Exposed AWS Keys: A Threat to Corporate Security
The discovery of hundreds of leaked AWS keys has sent shockwaves through the corporate world, highlighting the need for robust security measures to protect against data breaches. Truffle Security, a leading security research firm, has been tracking the exposure of AWS keys for the past four years, revealing a staggering 9,300 keys that are still active and valid.
Of these, 817 keys were linked to companies, with 526 being AWS root keys. The researchers found that 242 of the exposed keys were associated with IAM users with the AdministratorAccess policy, granting them full permissions to create, modify, delete, and view virtually all AWS services and resources within an account.
The implications of this discovery are severe, as attackers can use the exposed keys to gain full control over cloud-hosted data, servers, and applications. This can lead to data breaches, financial losses, and reputational damage. To defend against potential abuse, Truffle Security recommends deleting all root access keys, reviewing IAM credentials by age, rotating or revoking exposed keys, and configuring budget alerts.
The Age of Exposed AWS Keys
The researchers found that the median age of the exposed keys was 1,831 days (about five years), with the oldest key existing for 17.4 years. Only 398 (13.7%) of the entries had a newer access key associated with the same user, suggesting that most had never been rotated.
The Largest Source of Leaked AWS Keys
Hugging Face, a popular online platform where developers share AI models, datasets, and applications, was the largest single source of leaked AWS keys, accounting for 8,482 unique key exposures. The researchers also found that 17.9% of those keys were root, meaning the highest-privileged identity, which isn’t restricted by IAM permissions.
The Importance of Key Rotation
The discovery of exposed AWS keys highlights the importance of key rotation and regular security audits. Companies must take proactive measures to protect their cloud infrastructure, including deleting all root access keys, reviewing IAM credentials by age, and configuring budget alerts. By doing so, they can reduce the risk of data breaches and financial losses.
Key points
- More than 9,300 Amazon Web Services (AWS) access keys have been publicly exposed between August 2022 and August 2026.
- 817 of the exposed keys were linked to companies, with 526 being AWS root keys.
- 242 of the exposed keys were associated with Identity and Access Management (IAM) users with the AdministratorAccess policy.
- Hugging Face was the largest single source of leaked AWS keys, accounting for 8,482 unique key exposures.
- 17.9% of the exposed keys were root, meaning the highest-privileged identity, which isn’t restricted by IAM permissions.
If companies take proactive measures to protect their cloud infrastructure, such as deleting all root access keys, reviewing IAM credentials by age, and configuring budget alerts, they can reduce the risk of data breaches and financial losses. Additionally, the discovery of exposed AWS keys can lead to improved security measures and a greater emphasis on key rotation and regular security audits.
The exposed AWS keys pose a significant threat to corporate security, as they can be used to gain full control over cloud-hosted data, servers, and applications, potentially leading to data breaches and financial losses. If companies do not take proactive measures to protect their cloud infrastructure, they may be vulnerable to attacks and data breaches.


