Several outlets report that a contractor working for the U.S. Cybersecurity and Infrastructure Security Agency (CISA) maintained a publicly accessible GitHub repository that contained credentials and internal data. The repository exposed sensitive information for highly privileged AWS GovCloud accounts and included a large set of internal CISA systems and files. Security researcher Guillaume Valadon of GitGuardian reportedly flagged the exposure after routinely scanning public repositories for exposed secrets; he said the repository owner was not responding and that the material appeared highly sensitive.
The GitHub repository, reportedly named “Private-CISA,” allegedly included cloud keys, tokens, plaintext passwords, logs, and other CISA-related assets. Valadon and other security observers cite evidence consistent with poor secret-handling practices, including commit activity and steps described as disabling GitHub features intended to prevent publishing secrets. According to CISA, there is no indication that sensitive data was compromised as a result, and the agency says it is implementing additional safeguards to prevent recurrence.
The repository was taken offline after CISA was notified, though at least one account of the timeline suggests the exposed AWS credentials may have remained valid for some time afterward.