Researchers Discover Over 700 Active Leaked AWS Keys
Researchers from Truffle Security found 768 leaked Amazon Web Services (AWS) keys that still grant full control over corporate accounts. Among these, 526 are root keys, the highest level of privilege a customer can hold on AWS.
Methodology and Findings
The team collected 431,875 AWS secrets from various sources, including repositories, git history, datasets, Docker images, and CI logs. After deduplicating and testing available complete credentials for 10,616 keys, they found that 88% of them were still active.
The largest source of exposed keys was Hugging Face, a platform known for hosting machine learning models, with 8,482 unique key exposures.
Age and Rotation of Keys
The median age of the keys with known creation dates is approximately five years old. Only 13.7% of users had issued newer keys to replace their older ones.
AWS Quarantine Policy
Amazon applies a quarantine policy to leaked keys, aiming to limit fraud without impacting existing resources. However, Corey Quinn, a cloud economist, argues in The Register that this policy allows too much access.
Quarantined credentials can still:
- Assume other roles within the account
- Run commands on running instances
- Stop CloudTrail logging
- Delete the entire audit trail
Regulatory Implications for European Companies
For European firms, especially financial entities, these findings are particularly relevant given the Digital Operational Resilience Act (DORA) introduced since January 2025. TNW previously reported that many companies were not prepared for this regulation.
A five-year-old root key in a public dataset is a direct risk to DORA’s requirements, highlighting the importance of third-party technology risk management and control rotation.