Massive CISA Data Leak: Contractor’s Public GitHub Repo Exposed AWS GovCloud Credentials, Plaintext Passwords & Internal Systems-One of the Worst Government Security Failures in Years” (Alternative optimized options:) “CISA Contractor’s GitHub Mistake Leaked AWS GovCloud Keys, Plaintext Passwords & Internal Systems-Security Experts Call It ‘One of the Worst Leaks Ever'” “Exclusive: CISA’s ‘Private CISA’ GitHub Repo Exposed Highly Privileged AWS GovCloud Accounts & Internal Credentials-How It Happened & Why It’s a National Security Risk” “CISA Contractor’s Public GitHub Repo Held AWS GovCloud Secrets for Over a Year-Security Researchers Warn of ‘Catastrophic’ Internal Exposure

May 19, 2026 • Updated May 19, 2026

CISA AWS GovCloud Credential Leak: How a Public GitHub Repo Exposed Highly Sensitive U.S. Cybersecurity Secrets

A contractor working for the U.S. Cybersecurity & Infrastructure Security Agency (CISA) left highly sensitive credentials exposed in a public GitHub repository for nearly seven months, according to security researchers who discovered the breach. The repository, named “Private-CISA,” contained administrative access keys to three Amazon Web Services (AWS) GovCloud accounts, plaintext passwords for dozens of internal CISA systems, and files detailing the agency’s secure software development processes. Security experts describe the incident as one of the most severe government data leaks in recent history, raising serious questions about internal security practices at an agency responsible for protecting America’s critical infrastructure.

The exposed credentials included administrative tokens for AWS GovCloud servers—used by federal agencies for highly classified workloads—and plaintext passwords stored in a CSV file labeled “AWS-Workspace-Firefox-Passwords.csv.” Among the systems accessible through these credentials was CISA’s “Landing Zone DevSecOps” (LZ-DSO) environment, a secure platform for building and testing government software. Researchers also found credentials for CISA’s internal “artifactory,” a repository containing all the code packages used to build agency software—a prime target for attackers seeking persistent access.

Linda Park is a technology journalist and editor with a strong background in software engineering and digital innovation. She holds an MSc in Computer Science from Stanford University and has spent nine years covering AI, cybersecurity, and emerging technologies for a global audience.

The leak was discovered by security researchers Guillaume Valadon of GitGuardian and Philippe Caturegli of Seralys, who independently confirmed the validity of the exposed credentials. Valadon’s team, which scans public code repositories for exposed secrets, reached out to CISA after the repository owner failed to respond to automated alerts. Caturegli tested the AWS keys and found they remained active for 48 hours after the GitHub repository was taken offline—a critical window that could have allowed malicious actors to exploit the breach.

While CISA has stated there is “no indication that any sensitive data was compromised,” security experts warn the incident reveals alarming internal security practices. The repository was created on November 13, 2025, and maintained by a contractor employed by Nightwing, a government IT services firm based in Dulles, Virginia. The contractor’s GitHub account, active since September 2018, showed signs of being used as a personal synchronization tool rather than a secure project repository.

What Was Exposed—and Why It Matters

The “Private-CISA” repository contained a trove of sensitive materials, including:

  • Administrative credentials for three AWS GovCloud accounts (verified as still active for 48 hours after discovery)
  • Plaintext passwords for dozens of internal CISA systems, including a CSV file labeled “AWS-Workspace-Firefox-Passwords.csv”
  • Files detailing CISA’s software development processes, including secure code repositories and deployment pipelines
  • Credentials for CISA’s internal artifactory, a repository containing all software packages used to build agency systems
  • Evidence of disabled GitHub security features, including explicit commands to bypass secret detection tools

The exposure represents a textbook example of poor security hygiene, according to Valadon, who described the incident as “the worst leak” of his career. “Passwords stored in plain text in a CSV, backups in Git, explicit commands to disable GitHub secrets detection feature,” Valadon wrote in an email to CISA. “I honestly believed that it was all fake before analyzing the content deeper.”

Philippe Caturegli, founder of Seralys, tested the exposed AWS keys and confirmed they granted high-privilege access to CISA’s cloud infrastructure. “That would be a prime place to move laterally,” Caturegli said. “Backdoor in some software packages, and every time they build something new they deploy your backdoor left and right.”

A Timeline of the Breach

September 2018: The contractor’s GitHub account is created.
November 13, 2025: The “Private-CISA” repository is created and begins accumulating sensitive files.
May 15, 2026: GitGuardian’s automated systems detect exposed secrets in the public repository and alert CISA.
May 16–17, 2026: The GitHub repository is taken offline after researchers notify CISA, but exposed AWS keys remain valid for an additional 48 hours.
May 19, 2026: CISA acknowledges the incident in a statement and confirms an ongoing investigation.

How Did This Happen—and What Does It Reveal?

Security researchers identified several red flags in the contractor’s GitHub activity:

From Instagram — related to Plaintext Passwords, Internal Systems
  • Disabled GitHub security features: The contractor explicitly configured GitHub to allow SSH keys and other secrets to be committed to public repositories, bypassing default protections.
  • Mixed personal and professional accounts: The repository used both a CISA-associated email address and a personal email, suggesting it was used across differently configured environments.
  • Weak password practices: Many credentials followed predictable patterns, such as appending the current year to platform names (e.g., “Artifactory2026”).
  • Repository used as a sync tool: Evidence suggests the contractor used GitHub to synchronize files between a work laptop and a home computer, treating it as a personal scratchpad rather than a secure repository.

Caturegli noted that such practices would pose a serious internal security threat even if credentials were never exposed externally. “Threat actors often use key credentials exposed on the internal network to expand their reach after establishing initial access,” he explained. “What I suspect happened is the contractor was using this GitHub to synchronize files between devices, because he has regularly committed to this repo since November 2025.”

CISA’s Response and Next Steps

In a statement, a CISA spokesperson confirmed the agency is aware of the exposure and continues to investigate. “Currently, there is no indication that any sensitive data was compromised as a result of this incident,” the spokesperson said. “While we hold our team members to the highest standards of integrity and operational awareness, we are working to ensure additional safeguards are implemented to prevent future occurrences.”

CISA's Response and Next Steps
AWS GovCloud credentials hack

However, the incident raises serious concerns about CISA’s internal security posture, particularly given the agency’s current operational challenges. CISA is operating with only a fraction of its normal budget and staffing levels after losing nearly a third of its workforce since the beginning of the second Trump administration. This workforce reduction has forced a series of early retirements, buyouts, and resignations across the agency’s divisions, potentially exacerbating existing security risks.

Key Concern: The exposed credentials could have granted attackers persistent access to CISA’s software development environment (LZ-DSO) and internal code repositories (artifactory). If exploited, this could have allowed malicious actors to insert backdoors into government software used across critical infrastructure sectors.

Why This Leak Raises Alarm Bells for National Security

CISA plays a critical role in protecting America’s critical infrastructure, including energy grids, financial systems, and emergency services. The agency’s mission includes:

What happens after leaking an API key on GitHub? Experiment leaking AWS API key into GitHub
  • Coordinating cybersecurity responses to major incidents
  • Providing technical assistance to state and local governments
  • Developing best practices for securing federal and private-sector systems
  • Investigating cyber threats targeting national security

The exposure of CISA’s internal credentials undermines public trust in the agency’s ability to safeguard sensitive information. “This is an embarrassing leak for any company, but it’s even more so in this case because it’s CISA,” Caturegli said. “When an agency responsible for securing the nation’s critical infrastructure fails to secure its own systems, it sends a dangerous message to both adversaries and the public.”

Security experts warn that the incident highlights systemic risks in government contracting. Nightwing, the contractor’s employer, declined to comment, directing inquiries to CISA. The company has a history of working with federal agencies on IT services, but this breach raises questions about oversight and accountability in the government contractor ecosystem.

What’s Next for CISA—and How Can This Be Prevented?

CISA has not yet provided details about the duration of the exposure or whether any internal systems were accessed using the leaked credentials. However, security researchers recommend several immediate steps:

  • Full credential rotation: Revoke all exposed credentials and issue new, unique access tokens for every affected system.
  • Independent security audit: Conduct a comprehensive review of CISA’s internal security practices, particularly around third-party contractors.
  • Enhanced monitoring: Implement real-time detection for credential exposure in development environments.
  • Contractor training: Mandate security awareness programs for all government contractors handling sensitive data.
  • Transparency report: Publish a detailed account of the breach, including timelines, affected systems, and corrective actions.

Congress may also scrutinize the incident, particularly given CISA’s reduced workforce and budget constraints. Lawmakers could demand explanations about how such a severe breach occurred and what steps are being taken to prevent recurrence.

Key Takeaways

  • Severity: The leak exposed administrative access to AWS GovCloud accounts and CISA’s internal software development environment.
  • Duration: Sensitive credentials were publicly accessible for nearly seven months before discovery.
  • Root Cause: Poor security hygiene, including disabled GitHub protections and weak password practices.
  • Risk: Attackers could have used the credentials to move laterally within CISA systems and potentially insert backdoors into government software.
  • Broader Impact: Undermines public trust in CISA’s ability to protect critical infrastructure from cyber threats.
  • Next Steps: CISA must conduct a full audit, rotate all exposed credentials, and implement stricter contractor oversight.

Official Statements and Updates

For the latest updates on this incident, readers can monitor:

Key Takeaways
CISA logo security breach

As the investigation into this breach continues, one thing is clear: the exposure of CISA’s internal credentials serves as a stark reminder of the evolving cybersecurity threats facing government agencies. With critical infrastructure increasingly reliant on digital systems, incidents like this underscore the need for robust security practices—not just in the private sector, but across all levels of government.

For readers concerned about protecting their own systems, security experts recommend:

  • Enabling all default security features in development tools (e.g., GitHub’s secret scanning).
  • Avoiding the use of personal repositories for work-related files.
  • Implementing strict password policies and credential rotation schedules.
  • Regularly auditing third-party access to sensitive systems.

What’s Next? CISA has not yet announced a public update timeline, but the agency’s next statement is expected to include:

  • A detailed timeline of the breach and corrective actions taken.
  • Confirmation of whether any internal systems were accessed using the leaked credentials.
  • Plans for enhanced security training for contractors and employees.
  • Proposed legislation or policy changes to prevent similar incidents.

We’ll continue to monitor developments and provide updates as they become available. In the meantime, we welcome your thoughts on this critical cybersecurity failure—share your concerns or insights in the comments below.

Redacted screenshot of the now-defunct 'Private CISA' GitHub repository maintained by a CISA contractor
Redacted screenshot of the now-defunct “Private-CISA” GitHub repository. The repository contained sensitive CISA credentials and internal system access details.

About the Author
Linda Park is a technology journalist and editor with a strong background in software engineering and digital innovation. She holds an MSc in Computer Science from Stanford University and has spent nine years covering AI, cybersecurity, and emerging technologies for a global audience. As Editor of the Tech section at World Today Journal, she delivers in-depth reviews, breaking news, and expert analysis to readers worldwide.

Leave a Comment