For almost six months, the internal passwords and keys of the American cyber agency were in public access on GitHub, and the agency received automatic notifications nine times and did not respond to them. The U.S. Cybersecurity and Infrastructure Protection Agency (CISA) acknowledged errors after the leak and described in detail why it could not quickly close access.
In an open repository called Private CISA there were 844 MB of service data. The contractor published the administrative keys from the three servers of Amazon AWS GovCloud, as well as usernames and passwords from dozens of internal systems. Some of the credentials were stored in normal text form.
GitGuardian discovered a leak during automatic inspection of open code storage. Before the journalists asked for comment, the system notified the owner nine times, but no one responded. The agency learned about the problem on May 15, 2026, but turned off cloud keys and other important data only after more than 48 hours.
The agency explained the delay in a complex device of its systems and many ties with federal agencies and private organizations. After the incident, the agency advised other companies to work out key replacements in advance and regularly check how quickly employees can withdraw the compromised data.
Problems have also arisen with communication channels. The specialist GitGuardian tried to contact the contractor, sent a message through a platform for revealing vulnerabilities and eventually turned to the journalist. Such a platform was intended for reports of threats to widespread cybersecurity, and not for leaks inside the agency itself.
CISA acknowledged that the instructions for external specialists were confusing. The agency promised to place clear ways of communication in several notable places at once and separate reports of its own infrastructure from appeals about other people's products and systems. Responding to incidents, the agency also did not take into account possible leaks through GitHub and other cloud services. Now CISA has replaced all the secrets disclosed, the beginning is better to store the data of developers and has become constantly and more thorough to check the open storage facilities.
According to the agency, the stolen data was not used outside its infrastructure, and customer information and work data were not affected. Detailed journals of events and principles of zero trust helped to verify the consequences. The access of the contractor who published the files was withdrawn.
In an open repository called Private CISA there were 844 MB of service data. The contractor published the administrative keys from the three servers of Amazon AWS GovCloud, as well as usernames and passwords from dozens of internal systems. Some of the credentials were stored in normal text form.
GitGuardian discovered a leak during automatic inspection of open code storage. Before the journalists asked for comment, the system notified the owner nine times, but no one responded. The agency learned about the problem on May 15, 2026, but turned off cloud keys and other important data only after more than 48 hours.
The agency explained the delay in a complex device of its systems and many ties with federal agencies and private organizations. After the incident, the agency advised other companies to work out key replacements in advance and regularly check how quickly employees can withdraw the compromised data.
Problems have also arisen with communication channels. The specialist GitGuardian tried to contact the contractor, sent a message through a platform for revealing vulnerabilities and eventually turned to the journalist. Such a platform was intended for reports of threats to widespread cybersecurity, and not for leaks inside the agency itself.
CISA acknowledged that the instructions for external specialists were confusing. The agency promised to place clear ways of communication in several notable places at once and separate reports of its own infrastructure from appeals about other people's products and systems. Responding to incidents, the agency also did not take into account possible leaks through GitHub and other cloud services. Now CISA has replaced all the secrets disclosed, the beginning is better to store the data of developers and has become constantly and more thorough to check the open storage facilities.
According to the agency, the stolen data was not used outside its infrastructure, and customer information and work data were not affected. Detailed journals of events and principles of zero trust helped to verify the consequences. The access of the contractor who published the files was withdrawn.