← All articles

Truffle Security finds hundreds of leaked AWS keys still fully controlling accounts

Researchers at Truffle Security reported that after four years of collecting leaked Amazon Web Services keys, they found 768 that still grant full control over a company's cloud account, with a median age of about five years. The keys were exposed in places like public code and configuration and were never rotated, so they remain live long after the people who created them have likely forgotten them. A single valid key with broad permissions can let an attacker read data, spin up resources, and move through a cloud environment. The finding is a reminder that leaked long-lived credentials remain one of the most durable and overlooked paths into cloud accounts.

Check
Scan code, configuration, and logs for exposed AWS keys, revoke and rotate any long-lived keys you find, and move toward short-lived credentials and roles instead of static access keys.
Affected
Organizations with old, long-lived AWS access keys exposed in code or configuration and never rotated; an attacker who finds a still-valid key can gain full control of the account it belongs to.
Fix
Replace static keys with temporary credentials and roles, enforce rotation and least privilege, add automated secret scanning across repositories and history, and monitor for use of old or unexpected keys.