CISA, the GitHub leak: when the watchdog leaves the keys in the door
CISA, the US cyber agency, exposed its own AWS GovCloud credentials on public GitHub for 6 months. Anatomy of a leak in 7 failures.

Picture it. You are the US federal agency in charge of protecting government systems against cyberattacks. Your mission is to tell everyone else how to secure themselves. You publish guides, alerts, recommendations on the top ten flaws to avoid, on secrets management, on the zero trust posture. And one fine day, security researchers discover that one of your own contractors has posted, in public access, on GitHub, a repository named Private-CISA. Eight hundred and forty-four megabytes of data, including Amazon AWS GovCloud administrative credentials, cleartext passwords in a CSV file, Entra ID SAML certificates, SSH keys, and access to your internal software package repository. All of it exposed since November 2025. Six months.
That is the story Brian Krebs tells on his blog on 18 May 2026, based on a discovery by the French company GitGuardian. And it is probably the most emblematic leak of the year, not for its volume, but for what it says about the real state of public cybersecurity in 2026.
What was in the Private-CISA repository?
The repository was called Private-CISA. The contractor who created it worked for Nightwing, a company based in Dulles, Virginia. It had gone online on 13 November 2025, hosted on GitHub.com in public visibility, accessible without authentication, indexed by search engines. Inside, GitGuardian's researchers found exactly what you hope never to see.
Three sets of administrative credentials for AWS GovCloud, Amazon's cloud environment reserved for sensitive US government workloads, gathered in a file soberly named importantAWStokens. These credentials granted high-privilege access to accounts holding the services hosted by CISA. A CSV file named AWS-Workspace-Firefox-Passwords containing, in cleartext, the Firefox credentials of dozens of internal systems. A private RSA key opening the CISA-IT code repositories. Access to the agency's Artifactory repository, that is, the library of every software package used to build its internal tools. Kubernetes manifests, Terraform files, ArgoCD files, CI/CD logs, access to the LZ-DSO environment (Landing Zone DevSecOps) and SAML certificates for Entra ID, meaning the organization's federated identity.
Guillaume Valadon, the GitGuardian researcher who made the discovery, does not mince his words. I quote. Passwords stored in cleartext in a CSV file, backups in Git, explicit commands to disable GitHub's secret detection. I honestly thought all of this was fake before analyzing the content in depth. This really is the worst leak I have witnessed in my career.
To really grasp what this represents, you have to understand that access to an Artifactory is not a simple credential leak. It is an ideal entry point for a supply chain attack. An attacker who gains this level of access can inject malicious code into the packages used internally, wait for the next builds to automatically pull in that code, and watch their backdoor spread through every system that consumes those packages. That is exactly the category of threat CISA is supposed to prevent and fight.

Human error or deliberate bypassing of the protections?
For several years GitHub has offered an automatic scanning feature that detects secrets placed in public repositories and blocks their publication. It is enabled by default on all accounts. When you try to push a file containing an AWS key, a JWT token, or a private certificate, GitHub stops you and asks you to confirm.
The commit logs of the Private-CISA repository show that the contractor manually disabled this protection before pushing the data. This is not an oversight. It is a deliberate action, documented, traceable. Someone, at a specific moment, clicked to bypass a security measure that is imposed by default on every user of the platform.
And that detail changes the nature of the incident. We are not talking about a developer who made a mistake by forgetting a file in their repository. We are talking about someone who deliberately disarmed a protection mechanism in order to publish their own personal backups. Several commenters on Krebs's forum see in it a misuse of GitHub as a synchronization system between a work machine and a personal one, in an environment where USB ports and third-party clouds would probably be blocked by Nightwing's security policy.
If that is the case, and it is plausible, we are touching on something that goes far beyond the CISA incident. We are touching on the structural shadow IT of the state's subcontractors, on the practice of daily circumvention of security rules because they are experienced as obstacles to getting work done. That is exactly the subject I covered two weeks ago about the Europol Pressure Cooker scandal. The pattern repeats, on every continent, in every agency.
The 48 hours that speak volumes
On 14 May 2026, GitGuardian detects the repository. Its automated systems send nine alerts to the account owner. No response, apart from the automatic acknowledgments. On the morning of 15 May, the team contacts the CERT/CC incident center directly, and in parallel Brian Krebs so that he can activate his personal contacts at CISA. The agency is reached in the early European afternoon. The repository is taken down at six in the evening, Eastern time, which corresponds to about twenty-six hours between the first alert to CISA and the takedown.
On this point, the agency reacted fast, and credit is due. Most responsible disclosures take much longer.
But here is the detail that should give us pause. The exposed AWS credentials remained valid for forty-eight hours after the repository was removed. That is two full days during which an attacker who had copied the secrets during the six months of exposure could keep using them to access the GovCloud accounts. Key rotation, which should be an automatic and immediate action in any incident of this kind, was triggered only belatedly.
Why this matters. Because in a forensic investigation, an attacker's actions during the window when the credentials are still valid look identical to the legitimate actions of administrators. The logs do not tell an authorized use from a fraudulent one until the key has been flagged as compromised. So auditing those forty-eight hours to rule out exploitation is extraordinarily difficult, and for now CISA has not published any full forensic assessment.
The statement no one can prove
Under media pressure, CISA issued an official statement that deserves to be read carefully. I quote. At this time, there is no indication that any sensitive data was compromised as a result of this incident.
This sentence is technically correct, but it is also technically empty. How can you claim that there was no compromise over one hundred and eighty-three days of public exposure, with administrative access to three GovCloud accounts, and with credentials that stayed valid forty-eight hours after the discovery? You cannot. Not unless you produce a full forensic audit of all access over that period, which CISA has not published at the time I write, and which CISA would probably have a great deal of trouble producing given its current headcount.
Because it bears repeating, the agency today runs at about seventy percent of its pre-2025 headcount. It had close to three thousand four hundred people at the start of fiscal year 2025; by December there were only two thousand four hundred left, a drop of nearly a third. Budget cuts, resignations, early retirements, departures under the Trump administration. The capacity to conduct a forensic investigation into an incident of this magnitude, with reduced staff, becomes a structural challenge.
Seven layers of protection, seven failures
What makes this incident instructive is that it reveals a stack of failures that should each, on their own, have prevented the leak or dramatically limited it.
GitHub blocks the publication of secrets by default. The contractor disabled that protection. First defense down.
AWS GovCloud supports temporary credentials via IAM with STS tokens that expire within a few hours. The exposed credentials were static, long-term credentials. Second defense absent.
AWS Secrets Manager allows automatic key rotation at regular intervals. Rotation was not enabled. Third defense absent.
GovCloud administrative accounts can be protected with hardware security keys, such as YubiKeys. Apparently, that was not the case. Fourth defense absent.
CISA should have an internal system for monitoring credential leaks that would detect its own keys appearing in public repositories. It was GitGuardian, a private French company, that made the discovery, not the agency itself. Fifth defense absent.
The internal password policy should forbid trivial conventions of the platform_name + year type. Several of the exposed credentials followed exactly that pattern. Sixth defense absent.
And the contractor should have been required to use enterprise tools for their backups, not their personal GitHub account. Seventh defense absent.
When seven independent layers of control fail at the same spot, you are no longer dealing with an incident. You are dealing with a system.
What this teaches us, about ourselves
And here you might say to me, yes, but that is in the United States, that is CISA, it is complicated, it is a special case. Except it is not. And that is precisely the point of this article.
The organizations with the most mature frameworks, the strongest certifications, the most comfortable budgets, can get burned the same way as the humblest small business. Because security, in operational reality, does not depend on the number of pages in the ISO 27001 manual. It depends on what humans do when they are alone in front of their screen, at six in the evening, with a file to transfer onto their personal machine so they can finish up in peace at home.
You can have every annual audit in the world, every compliance certificate, every policy in triplicate signed by your CISO, your DPO, and your executive management. If the operational culture does not follow, if automatic controls can be disabled with one click, if credential rotation is not automatic, if your contractors use GitHub as a personal cloud without your knowing, you are in CISA's situation.
That is what real cybersecurity is. Not the documentation. Not the frameworks. Not the announcements. Daily operational culture, meaning what happens when no one is watching.
And now
As I write these lines, on 19 May 2026, Senator Maggie Hassan has just requested an urgent classified briefing from CISA's acting director. Her letter attaches twelve precise questions about the policies and procedures that made the incident possible, and demands an answer by 5 June at the latest. Democrats on the House Homeland Security Committee are asking for a briefing of their own. The White House, the Department of Homeland Security, and the US administration will have to answer precise questions about their internal practices.
And the incident lands in the middle of the budget debate. The agency has already lost close to a third of its headcount since January 2025, and the next budget proposal plans to cut about a thousand more positions, while stripping roughly four hundred and ninety-five million dollars from the agency and shutting down entire programs, from the election security program to the funding of MS-ISAC, the information sharing center for states and localities. A Cloud Security Alliance research note draws the link with the leak in black and white: the controls that should have caught this exposure sooner, active secret scanning, contractor oversight, credential lifecycle management, had been either disabled, deprioritized, or never applied. We ask the organization charged with defending the country to do it with a third fewer people, then act surprised when a contractor under pressure takes a shortcut.
What does CISA's post-mortem report say?
It took until 13 July 2026, almost two months after the discovery, for CISA to publish its post-mortem report, signed by acting chief information officer Preston Werntz and acting chief information security officer Brad Libbey.
The document confirms, almost word for word, the hypothesis set out above. I quote. The individual had uploaded copies of a CISA build and deployment repository to his personal GitHub account in order to create cloud infrastructure on his own. In other words, exactly the shadow IT I was describing: a contractor who works around the official tooling to move faster, and who takes the keys to the kingdom along for the ride. And what the incident reveals goes beyond one person's gesture. For several analysts in the sector, US federal cyber defense now rests on a contractor base too vast to be governed at the level of sensitivity it demands, which makes identity and access management for those providers the real breaking point.
On the forty-eight-hour window, the agency half admits what the logs already suggested. Key rotation took longer than expected, it concedes, because of the complexity of its systems and their interconnections with its federal and industry partners. Translation: nobody knew precisely where all those keys were being used, so nobody could revoke them in a single move.
On compromise, CISA holds its line, but with a stronger argument than in May. No customer or mission data was exposed, no unauthorized use of the credentials was detected, and this time the agency states that complete logging allowed it to investigate quickly. That is better supported than the initial statement, but it still requires taking on trust an agency that had not noticed its own keys sitting in public for one hundred and eighty-three days.
The most honest part of this report fits in a single sentence of contrition. No repository should contain secrets, CISA writes, yet secrets ended up in its repositories. When it went to check, the agency in fact discovered secrets in its own private repositories too, which had to be deleted and then renewed, before launching a monitoring plan extended to all of its repositories. So the problem was not confined to one contractor's account. The agency also admits it had no playbook for a cloud security incident that started on GitHub. And there is something even more embarrassing. The GitGuardian researcher had found no obvious channel to alert the agency and had to go through Brian Krebs's personal contacts. The organization that coordinates the country's vulnerability disclosure acknowledges, in black and white, that there was no easy way to report its own. The announced measures follow: blocking staff pushes to public repositories, new access controls on code repositories, reinforced logging, clarification and publication of reporting channels for researchers, the contractor's access revoked, passwords changed across all development environments.
These are, line for line, the elementary controls that were missing. They get put in place afterwards. They always get put in place afterwards.
Meanwhile, in France, we keep discussing the transposition of NIS2 eighteen months behind schedule. We keep debating backdoors in encrypted messaging apps. And we keep publishing Matignon roadmaps that ask ministries to put in place in 2026, by 2027, the basic controls you would expect from an average French small business.
At what point do we stop reacting to each incident as if it were an exception, and start treating them as the systemic symptoms they are?
Sources
- KrebsOnSecurity, "CISA Admin Leaked AWS GovCloud Keys on Github", 18 May 2026
- KrebsOnSecurity, "Lessons Learned from CISA's Recent GitHub Leak", July 2026
- Cybersecurity Dive, "CISA details security lapses that led to GitHub leak", 14 July 2026
- SC Media, "CISA shares postmortem of GitHub credential leak", July 2026
- GitGuardian, "How We Got a CISA GitHub Leak Taken Down in Under a Day", May 2026
- Senator Maggie Hassan, press release and letter to CISA, 19 May 2026
- Axios, "Senator requests classified briefing on CISA credentials leak", 19 May 2026
- Nextgov/FCW, "House Homeland Dems request CISA briefing amid report of leaked agency credentials", May 2026
- Cloud Security Alliance, research note "Private-CISA: GovCloud Leak and the Hollowing of U.S. Cyber Defense", 2026
- Biometric Update, "GitHub exposure points to broader contractor identity security gaps at CISA", June 2026
- Cybersecurity Dive, "CISA workforce cut by nearly one-third so far", 2025
- Federal News Network, "DHS budget request would cut CISA staff by 1,000 positions", May 2025
Frequently asked questions
What did the GitHub repository exposed by the CISA contractor contain?
The Private-CISA repository, public since 13 November 2025, contained 844 MB of data: three sets of AWS GovCloud administrative credentials bundled in a file named importantAWStokens, a CSV file of cleartext passwords, an RSA key opening the CISA-IT code repositories, access to the agency's Artifactory, Kubernetes manifests, ArgoCD files, CI/CD logs and SAML certificates for Entra ID.
Was this a simple mistake or a deliberate act?
The commit logs show that the contractor manually disabled GitHub's secret-scanning protection before pushing the data. The post-mortem report CISA published on 13 July 2026 confirms it: the employee had uploaded copies of one of the agency's build and deployment repositories to his personal GitHub account in order to create cloud infrastructure on his own. This was a deliberate, documented action, not an oversight.
Why is the 48-hour window a problem?
The AWS credentials stayed valid for 48 hours after the repository was removed. As long as a key is not flagged as compromised, the logs cannot tell legitimate use from fraudulent use, which makes a forensic audit of that period extraordinarily difficult. CISA acknowledged in its report that rotation took longer than expected, because of the complexity of its systems and their interconnections with its partners.
Who is the contractor behind the leak?
The GitHub account belonged to an employee of Nightwing, a company based in Dulles, Virginia, that holds sensitive contracts for CISA. According to the agency's report, the person had copied an internal build and deployment repository onto his personal account in order to provision cloud resources without going through the official tooling.
Is CISA's statement about the absence of compromise credible?
In May 2026 the agency said it had no indication of compromise, a sentence that is technically correct but unverifiable across 183 days of public exposure. Its 13 July report goes further and states that complete logging made it possible to rule out any unauthorized use and that no customer or mission data was exposed. Even so, you have to take the word of an agency that had not noticed its own keys sitting in public for six months.
What did CISA's post-mortem report conclude?
Published on 13 July 2026 and signed by the acting chief information officer and the acting chief information security officer, the report confirms the misuse of GitHub, admits there was no playbook for this type of incident and acknowledges that no repository should contain secrets. CISA announced new controls: blocking pushes to public repositories, tighter access controls and extended logging.
What is the main lesson for organizations?
Real security does not depend on the number of pages in the ISO 27001 manual but on daily operational culture. Even a very mature organization can fail if automatic controls can be switched off with one click, if credential rotation is not automatic and if contractors' shadow IT stays invisible.
Sources & methodology
- Brian Krebs, KrebsOnSecurity, 18 May 2026
- GitGuardian (Guillaume Valadon)
- Seralys (Philippe Caturegli)
- CISA (post-mortem report of 13 July 2026)
- Cloud Security Alliance (research note, 2026)
- Axios, The Record and Nextgov (reaction from Congress)

Être en cybersécurité
A cyber roadmap in plain language, for everyone, not just the experts.
