Hundreds of leaked AWS keys give full control over corporate accounts
New findings reveal that thousands of Amazon Web Services access keys left publicly exposed remain active and valid.

A major cybersecurity concern has come to light regarding cloud infrastructure security. Reports indicate that more than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid.
This widespread exposure poses severe risks to corporate accounts, potentially granting unauthorized actors full control over vital cloud assets and sensitive company data.
Such security gaps typically occur due to accidental leaks in public code repositories or poor credential management practices by development teams.
As businesses worldwide increasingly rely on cloud-hosted infrastructure, including tech sectors in emerging markets, this incident highlights the critical need for proactive security measures.
Security experts advise organizations to immediately audit their active access keys, revoke any compromised credentials, and adopt robust secrets management practices.



