More than 9,300 Amazon Web Services (AWS) access keys that were publicly exposed between August 2022 and August 2026 are still active and valid, according to security researchers at Truffle Security.
The company has tracked publicly exposed AWS credentials for the past four years and found that 817 of the exposed keys were connected to companies. Among them were 526 AWS root keys, which represent some of the highest-privileged credentials in an AWS account.
Researchers also identified 242 keys associated with Identity and Access Management (IAM) users that had the AdministratorAccess policy. This level of access can allow users to create, modify, delete and view virtually all AWS services and resources within an account.
Truffle Security said it discovered 431,875 AWS secrets across code repositories, Git history, datasets, Docker images, registries and CI logs. After removing duplicates, the researchers identified 64,024 unique AWS keys associated with 50,654 AWS accounts.
The researchers had complete credentials that could be used for re-verification for 10,616 of those keys. Of that group, 88 percent were still able to authenticate as of August 10. The researchers said 768 live keys across the two corporate-related sets had enough privileges to provide full control of a company’s AWS account.
AWS is Amazon’s cloud computing platform and is widely used to host websites and applications, store data, operate databases and servers, manage domains and run other online infrastructure.
An attacker gaining full control of an AWS account could potentially access, steal or delete cloud-hosted data, take control of servers and applications, and create unauthorized administrator accounts to maintain access. Attackers could also deploy cryptocurrency miners and leave the affected company with significant cloud computing bills.
Truffle Security found that only 262 of 2,754 readable accounts had a budget alert configured, potentially leaving many organizations with limited warning if attackers used their credentials to generate unexpected cloud costs.
Hugging Face was the largest single source of exposed AWS keys identified in the research, accounting for 8,482 unique key exposures. The researchers also found that 17.9 percent of the exposed keys were root credentials, which represent the highest-privileged identity in an AWS account and are not restricted by IAM permissions.
The age of many exposed credentials was another concern. Among the 2,903 keys for which creation dates were available, the median age was 1,831 days, or around five years. The oldest exposed key had existed for 17.4 years.
Only 398 of those 2,903 entries, or 13.7 percent, had a newer access key associated with the same user, suggesting that most of the credentials had never been rotated.
Truffle Security recommends deleting all root access keys, reviewing IAM credentials based on their age, rotating or revoking exposed credentials and setting up AWS budget alerts. The researchers also warn that any credential committed to a public source should be treated as compromised.
If this article helped you, please consider supporting our work. Every small contribution keeps Abijita.com independent and running.
The company said its testing was limited to read-only metadata and that it had notified all identifiable owners of the exposed credentials.
More Than 9,300 Exposed AWS Keys Still Active, Researchers Warn





