Hundreds of leaked AWS keys give full control over corporate accounts

Summary

Over 9,300 Amazon Web Services (AWS) access keys were publicly exposed between August 2022 and August 2026, and many of them remain active and valid. This exposure grants full administrative control over affected corporate AWS accounts, allowing attackers to access, modify, or delete sensitive data and resources.

IFF Assessment

FOE

The exposure of active AWS access keys gives attackers full control over corporate accounts, posing a significant threat to data and resources.

Defender Context

This highlights a critical vulnerability where improperly secured AWS access keys can lead to complete account compromise. Defenders must implement robust key management practices, including regular rotation, least privilege principles, and continuous monitoring for unauthorized access or exposure.

Read Full Story →