CISA Contractor Leaks GovCloud Keys, Lawmakers Probe

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- CISA acknowledged the leak but has not disclosed how long the credentials were exposed.
- KrebsOnSecurity reported that a CISA contractor created a public GitHub repo named “Private-CISA” containing plaintext credentials to dozens of internal CISA systems.
- Sen. Maggie Hassan wrote to CISA’s Acting Director Nick Andersen, citing the agency’s recent loss of senior leadership after forced retirements and questioning its internal policies.
- Rep. Bennie Thompson co‑signed a letter with Rep. Delia Ramirez warning that the leaked files could give adversaries such as China, Russia, and Iran a roadmap to access federal networks.
- Dylan Ayrey of Truffle Security said CISA had not yet invalidated an RSA private key that could let an attacker read code from every CISA‑IT repository and hijack CI/CD pipelines.
- Truffle Security monitors public code platforms for exposed secrets and observed that cybercriminals also monitor the GitHub firehose, meaning attackers could have quickly harvested the leaked CISA keys.
- CISA said it is actively coordinating with vendors to rotate and invalidate any identified leaked credentials.
Why it matters: Congressional scrutiny forces CISA to accelerate credential rotation, protecting federal networks from potential exploitation, while the agency’s reputation suffers and adversaries gain a window to target U.S. infrastructure. The breach also highlights gaps in contractor oversight, prompting calls for stricter controls that could reshape how the federal government secures its code and cloud assets.
Ask SkimNews



