9,300+ Leaked AWS Keys Still Authenticate, Truffle Security Finds
Truffle Security re-verified 10,616 AWS keys it had found exposed in git history, Hugging Face datasets, Docker images, package registries, and CI logs between August 2022 and August 2026 - and 88% (more than 9,300) still worked as of August 10.
Of those, 817 belonged to identifiable companies; 768 of those corporate keys carried full administrative control (526 root keys, 242 IAM users with AdministratorAccess). Among the subset of keys with an available creation date, the median age was about five years, and only 13.7% showed a newer key had since been issued - suggesting most had never been rotated.