Lawmakers in both chambers of Congress are pressing the U.S. Cybersecurity and Infrastructure Security Agency (CISA) for answers after a contractor intentionally published AWS GovCloud credentials and a large cache of internal agency secrets on a public GitHub repository. The breach, first reported by KrebsOnSecurity, reveals that a contractor with administrative access to CISA’s code development platform created a public profile called “Private-CISA” containing plaintext credentials to dozens of internal systems. The agency is still working to invalidate the leaked keys more than a week after being notified.
The Private-CISA Repository: What Was Exposed
The contractor disabled GitHub’s built-in protections against publishing sensitive credentials in public repositories, according to commit logs reviewed by security researchers. The repository, created in November 2025, functioned as a synchronization scratchpad rather than a curated project, accumulating sensitive files over several months. The most damaging secrets appear to have been added in late April 2026. Files exposed included AWS GovCloud tokens, AWS-Workspace bookmarks, Firefox password exports, Kubernetes configuration files, and a file labeled “Important AWS Tokens.txt.” Security firm GitGuardian first alerted CISA to the leak, but the agency has not disclosed how long the data was publicly accessible.
Lawmakers Demand Accountability
Sen. Maggie Hassan (D-NH) sent a letter on May 19 to CISA Acting Director Nick Andersen, describing the leak as a serious failure of internal security policy at an agency responsible for defending critical infrastructure. “This reporting raises serious concerns regarding CISA’s internal policies and procedures at a time of significant cybersecurity threats against U.S. critical infrastructure,” Hassan wrote. Her letter posed a dozen specific questions about how the lapse occurred and what steps are being taken to prevent recurrence. Rep. Bennie Thompson (D-MS), ranking member of the House Homeland Security Committee, and Rep. Delia Ramirez (D-Ill) co-signed a separate letter warning that the exposed repository provided adversaries with “the information, access, and roadmap” to penetrate federal networks. The lawmakers noted that the incident follows a period of severe internal disruption at CISA, which lost more than a third of its workforce and nearly all senior leaders after the Trump administration forced early retirements, buyouts, and resignations across the agency.
Critical RSA Private Key Remained Active for Days
Dylan Ayrey, creator of the open-source secret-scanning tool TruffleHog, analyzed the exposed repository and found that an RSA private key granting full access to the CISA-IT GitHub organization was still valid days after the initial disclosure. That key controlled a GitHub app installed on the CISA enterprise account with privileges to read all source code, hijack CI/CD pipelines, access repository secrets, and modify administrative settings including branch protection rules and deploy keys. Ayrey reported his findings to CISA on May 20, and the agency invalidated that key shortly afterward. However, Ayrey noted that other leaked credentials tied to critical security technologies deployed across the agency remained unrotated at the time of reporting. CISA stated in response that it is “actively responding and coordinating with the appropriate parties and vendors to ensure any identified leaked credentials are rotated and rendered invalid.”
Attackers Likely Harvested the Secrets
Ayrey warned that cybercriminal groups and foreign adversaries routinely monitor GitHub’s public event feed for exposed keys. “We have evidence attackers monitor that firehose as well. Anyone monitoring GitHub events could be sitting on this information,” he said. The implication is significant: the sensitive CISA data likely remained publicly accessible long enough for malicious actors to copy it. Adam Boileau, co-host of the Risky Business security podcast, characterized the incident as fundamentally a human problem rather than a technical one. “Ultimately, this is a thing you can’t solve with a technical control,” Boileau said. “This is a human problem where you’ve hired a contractor to do this work and they have decided of their own volition to use GitHub to synchronize content from a work machine to a home machine.” Organizations using GitHub can enforce top-down policies preventing users from disabling secret-scanning protections, but no technical measure can prevent an employee from using a personal account to store proprietary data.
What Organizations Should Do Now
This incident underscores the need for organizations handling sensitive government or enterprise data to implement several critical measures. First, enforce mandatory secret-scanning policies at the organization level on all code platforms, with no option for individual users to override them. Second, deploy automated monitoring tools that can detect exposed credentials in real time across both managed and unmanaged repositories. Third, ensure that all contractors and employees with administrative access are subject to the same security controls as full-time staff, including mandatory training on secure code management practices. For individuals, use a reputable password manager with end-to-end encryption to store and sync credentials securely rather than relying on code repositories or unencrypted files. Finally, any organization that suspects credentials may have been exposed should immediately rotate all affected keys, tokens, and certificates, audit access logs for signs of unauthorized use, and enable multi-factor authentication on every system that supports it. The CISA breach is a stark reminder that no agency or company is immune to the consequences of human error in an increasingly hostile threat landscape.