Researchers warn thousands of active AWS access keys are publicly exposed
In hundreds of cases, the keys could give attackers complete administrative control
Tens of thousands of previously-exposed AWS access keys are still active and valid, researchers have warned, with hundreds holding full admin rights.
Truffle Security said its scanners verified 64,024 unique AWS key pairs across 431,875 public findings that surfaced publicly between August 2022 and August this year.
This includes git history, Hugging Face datasets, Docker images, package registries, and CI logs, the company said.
It then re-verified the 10,616 leaked keys with complete credentials and found that 88% still authenticate, including 526 root keys and 242 identity and access management (IAM) users holding AdministratorAccess - which have full admin rights.
"The largest single source is Hugging Face. AWS credentials are the second most common secret type we verify there, with 8,482 unique live keys across 3,394 public datasets," said the firm.
"Hugging Face keys also skew privileged: 17.9% are root, the highest share of any source we track. Most of those datasets are snapshots of public code repackaged for training."
Of the live keys with creation dates, the median age was 1,831 days. Half are over five years old. The oldest was 17.4 years, nearly as old as IAM itself.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
"Only 25 keys (0.9%) were created in the last 30 days. Almost none of this population leaked recently. The count has been building for years," Truffle Security said.
"Rotation is the rarer event. Of the keys where we could enumerate the user's access keys, only 13.7% (398 of 2,903) have any newer key alongside the leaked one. The other 86% were never rotated, superseded, or cleaned up."
Of the 7,590 active IAM users, 929 carry AWS's own AWSCompromisedKeyQuarantine policy, and were detected by AWS as exposed and restricted. Of these, 112 carry the original version, which AWS stopped applying in 2023.
Researchers noted that they were flagged at least three years ago and their owners notified by AWS. However, no action was apparently taken and the keys still authenticate.
Tighter access controls
Truffle Security said organizations delete root access keys. One-in-six leaked keys is root, for example, and as such there is no longer any legitimate reason for a root access key to exist in 2026.
They should also sort their IAM keys by age and set a budget alarm, even a small one, to catch cryptomining early - 90.5% of leaked-key accounts have none.
Elsewhere, researchers said security teams should assume that committed means leaked. Nearly half (43%) of keys were sighted more than once across repos, datasets, and images. Deleting the file does not help once it is in a training corpus.
"Any time AWS is aware of exposed keys, we notify the affected customers. We also thoroughly investigate all reports of exposed keys and quickly take any necessary actions, such as applying quarantine policies to minimize risks for customers without disrupting their IT environment," an AWS spokesperson told ITPro.
"As always, customers can contact AWS Support with any questions or concerns about the security of their account."
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Iranian cyber attack on UK power plant ‘should concern every organization responsible for keeping this country running’News The attack is believed to be the first of its kind in the UK
-
Sam Altman thinks AI will spark a new wave of entrepreneurshipNews The OpenAI chief executive thinks the tech industry needs to get better at selling the benefits of AI to small businesses and entrepreneurs