A newly identified 768 active, publicly exposed AWS access keys could provide attackers with complete administrative control over corporate cloud accounts.
The credentials include 526 root access keys and 242 IAM user keys assigned AWS’s AdministratorAccess permission, creating a direct path to account takeover, infrastructure abuse, data theft, and potentially substantial cloud-billing fraud.
The findings stem from a large-scale review of credentials that were publicly exposed between August 2022 and August 2026. Truffle Security re-verified 10,616 AWS key pairs on August 10 and found that 88% still authenticated successfully.
The keys originated from publicly accessible Git histories, Hugging Face datasets, Docker images, package registries, and CI/CD logs.
768 Leaked AWS Keys Expose Corporate Cloud Accounts
Although no credential material or account identities were disclosed, the scale of the problem illustrates how exposed secrets can remain usable long after their original publication.
Across the wider dataset, researchers verified 64,024 unique AWS access key pairs from 431,875 publicly identified findings. Of these, 10,625 were root credentials, accounting for 16.6% of the total.
A root access key is among the most severe AWS security failures because it cannot be constrained by IAM permissions.

Anyone holding a valid root key effectively becomes the account owner, with the ability to modify security controls, access billing settings, create users, delete resources, and close the AWS account entirely.
Hugging Face was identified as the largest single source of public AWS credentials. Researchers found 8,482 unique live keys across 3,394 public datasets, with root credentials making up 17.9% of the total.
Many affected datasets appear to contain copies of public source code collected for AI training and development. This creates a persistent exposure problem: a credential committed once can be copied into code archives, datasets, models, containers, and derivative repositories downloaded by thousands of users.
The research also showed that exposed credentials are often extremely old. Among 2,903 keys that allowed researchers to determine creation dates, the median live leaked key was 1,831 days old, or roughly five years.
The oldest identified key was 17.4 years old. Only 25 keys were created over the previous 30 days, suggesting the risk is driven primarily by forgotten, unrotated credentials rather than recent developer mistakes.
Rotation practices were equally weak. Only 398 of the 2,903 enumerable keys had a newer credential associated with the same IAM user. That means approximately 86% had never been superseded, rotated, or removed.

In many cases, old keys likely remained operational because they belonged to abandoned projects, experimental accounts, or legacy automation that organizations no longer actively monitored.
Truffle Security also found that AWS had previously identified many credentials as compromised. A total of 929 active IAM user keys were subject to the AWSCompromisedKeyQuarantine policy, which AWS applies when it detects public exposure.
More concerningly, 112 keys used an older version of that quarantine policy that AWS stopped issuing in 2023. Those credentials had likely been flagged years earlier, yet still authenticated and remained present in affected environments.
Of 817 business-linked active keys, 768 enabled full administrative control. The affected organizations were concentrated in software, cloud services, and IT consulting, including one global consultancy with 19 leaked keys across separate AWS accounts.
Truffle Security also identified 130 live root keys associated with AWS Organizations management accounts, the compromise of which could affect every member account connected to the organization.
The report recommends eliminating root access keys, enforcing IAM key age limits, rotating credentials immediately after exposure, and setting budget alerts to detect cryptomining or unauthorized resource deployments.
Organizations should assume that a secret committed publicly is permanently compromised, even after the original file is deleted.
Give your security team the visibility and context to investigate suspicious activity faster and contain threats before business impact grows. Strengthen Your Investigations with ANY.RUN