Briefing

CISA Contractor’s GitHub Repo Exposes AWS GovCloud Credentials

security
by BrianKrebs ·

Revoke all exposed AWS GovCloud credentials and enable GitHub secret scanning for all repositories.

What to do now

Revoke all exposed AWS GovCloud credentials, enable GitHub secret scanning, audit repositories for secrets, enforce MFA on all accounts, and conduct a full security review of internal credential handling.

Summary

On May 15, KrebsOnSecurity reported that a GitHub repository named Private‑CISA, maintained by a Nightwing contractor, exposed a trove of credentials for AWS GovCloud servers and internal CISA systems. The repo, created on Nov 13 2025 and linked to a GitHub account established in Sep 2018, contained files such as importantAWStokens with admin keys to three GovCloud accounts and AWS‑Workspace‑Firefox‑Passwords.csv listing plaintext usernames and passwords for dozens of internal services, including the Landing Zone DevSecOps (LZ‑DSO) environment. GitGuardian’s researcher Guillaume Valadon alerted CISA after discovering that the account had disabled GitHub’s default secret‑scanning feature, allowing the repository to publish SSH keys and other secrets publicly. Despite the repo being taken offline shortly after notification, the exposed AWS keys remained valid for an additional 48 hours, raising concerns about potential lateral movement via CISA’s internal artifactory.

CISA’s spokesperson confirmed that no sensitive data had been compromised yet but said the agency is implementing additional safeguards to prevent future incidents. The incident highlights the risks of using public code hosting for internal credentials and the importance of enforcing secret scanning and MFA across all accounts.

Key changes

  • Private‑CISA repo exposed AWS GovCloud admin keys to three servers via importantAWStokens
  • Repository contained plaintext usernames and passwords for dozens of internal CISA systems in AWS‑Workspace‑Firefox‑Passwords.csv
  • GitHub secrets detection was disabled in the account, allowing public publication of SSH keys and secrets
  • Exposed AWS keys remained valid for 48 hours after the repo was taken offline
  • Repo was created on Nov 13 2025; GitHub account created in Sep 2018
  • Nightwing contractor maintained the repo and used it to sync files between work and home environments

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting