← CISA (Cybersecurity and Infrastructure Security Agency)

2026 CISA — contractor GitHub exposed plaintext credentials and cloud keys (May)

2026 Unknown records affected Share on X

Data compromised

Administrative credentials, cloud keys, and access tokens per researcher reporting (revocation status ongoing)

Technical writeup

In May 2026, GitGuardian researcher Guillaume Valadon and journalist Brian Krebs reported that a CISA contractor maintained a public GitHub repository containing spreadsheets with plaintext passwords, AWS GovCloud keys, access tokens, and SSH material for CISA and DHS systems. TechCrunch said Valadon verified some keys were valid and alerted Krebs after the contractor did not respond; CISA stated it was investigating with no indication sensitive data was compromised and no confirmed breach stemming from the exposure at catalog time. BreachHistory classifies the row as credential misconfiguration exposure rather than a confirmed adversary intrusion.

Root cause

Public GitHub repository misconfiguration by CISA contractor; plaintext credential storage

References