CISA Contractor Apparently Leaked “Highly Sensitive” Government AWS Keys on Github


  • A public GitHub repository called “Private‑CISA” exposed internal credentials and highly sensitive systems used by the US Cybersecurity and Infrastructure Security Agency.
  • Security researchers have confirmed the authenticity of the leak, describing it as one of the worst government data leaks they have ever seen.
  • The repository, run by contractor Nightwing, was ultimately locked down, with CISA pledging to take protective measures to prevent future incidents.

Researchers have revealed details of what they called “one of the most egregious government data leaks in recent history” involving potentially incredibly sensitive US government information.

Security researcher Guillaume Valadon contacted KrebsOnSecurity to help contact someone in charge of a public GitHub repository.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top