The breach came to light on May 15, 2026, when the security firm GitGuardian alerted CISA to a public GitHub repository titled "Private CISA." This repository contained a substantial 844 MB of CISA-related data. Among the exposed files were "importantAWStokens," which held administrative credentials for three Amazon AWS GovCloud servers, and "AWS-Workspace-Firefox-Passwords.csv," a file containing plaintext usernames and passwords for numerous internal CISA systems. The fact that these credentials remained exposed for an extended period, despite automated alerts from GitGuardian, underscores a critical breakdown in CISA’s internal processes.
CISA acknowledged the initial alert but faced criticism for taking over 48 hours to revoke the compromised AWS keys and other sensitive secrets. In their official report, CISA attributed this delay to the complex interconnections of their systems and their collaborations with federal and industry partners, which complicated the key rotation process. This experience has led CISA to strongly advocate for the establishment of "mature and well-tested key management capabilities" across all organizations. This recommendation highlights the fundamental importance of robust and regularly audited credential management practices, moving beyond ad-hoc solutions to a systemic approach.
Furthermore, CISA candidly admitted that its response to external security incident notifications needs significant improvement. The postmortem report emphasizes the absolute necessity of clearly defined and distinct reporting channels. The agency recognized that the lack of such clarity led the security researcher, Guillaume Valadon of GitGuardian, to pursue multiple avenues, including direct contact with the contractor, submitting a report through CISA’s vulnerability disclosure platform (intended for broader community impacts), and ultimately involving a journalist. This multi-pronged approach indicates confusion and inefficiency in CISA’s initial handling of the notification, diverting valuable time and resources.
Preston Werntz, CISA’s acting chief information officer, and Brad Libbey, acting chief information security officer, detailed these findings in their analysis. They stressed that for CISA, these channels were not adequately defined, causing the researcher to navigate a complex and inefficient reporting pathway. To address this, CISA is actively refining its reporting channels to be more accessible and responsive to security researchers. They also highlighted the importance of diversifying reporting instruction dissemination, noting that while many researchers utilize the security.txt file, organizations should publish reporting guidelines in multiple prominent locations to ensure clarity and accessibility.
Guillaume Valadon, the GitGuardian researcher who initially flagged the exposed credentials, revealed a particularly concerning detail: CISA had reportedly ignored nine automated alerts from GitGuardian regarding the exposed credentials prior to the KrebsOnSecurity notification on May 15. GitGuardian’s service continuously scans public code repositories for exposed secrets and automatically alerts the affected accounts. Valadon’s analysis pointed out that "Letting nine notification emails go unanswered is how a one-day incident becomes a six-month exposure." This highlights a critical failure in CISA’s automated alert system and their internal triage process for security notifications. He strongly advised organizations to make reporting leaks about their own infrastructure as trivial as reporting vulnerabilities in their products, advocating for clear security.txt files and multiple prominent reporting instructions. He reiterated that reports about an organization’s own infrastructure should not be misrouted to product bug queues.
The CISA report also underscored the vital role of continuous scanning of public code repositories like GitHub for exposed secrets. The agency confirmed that it has since rotated all compromised secrets and developed an action plan to enhance developer secrets management and monitoring. This includes a commitment to more frequent scanning, moving away from potentially insufficient quarterly checks to a more continuous model, recognizing that a six-month exposure window is unacceptable. Valadon commented that "Comprehensive internal scanning could have caught the plaintext passwords and committed backups long before they left the building," reinforcing the importance of proactive internal security measures.
Despite the significant lapse, CISA also identified areas where its preparedness proved effective. The agency gave itself passing grades for its enhanced logging capabilities and the adoption of zero-trust principles across its production and development systems. These robust logging mechanisms allowed CISA to demonstrate that no customer or mission data was compromised, and the leaked credentials were not utilized outside of CISA’s internal environments. The contractor responsible for the exposure had their system access revoked, a standard security measure in such incidents.
Valadon viewed CISA’s transparent postmortem as the most significant takeaway from the entire incident. He commended the agency for its candidness about what worked and what did not. "To my knowledge, it is also the first time a national cybersecurity agency has publicly advocated for secrets scanning and for simplifying relations with security researchers," Valadon stated. He further emphasized that this level of transparency and proactive communication is precisely the incident response that all organizations should strive for. The incident, while exposing vulnerabilities, has ultimately served as a catalyst for CISA to strengthen its security posture and to share these hard-won lessons with the global cybersecurity community, fostering a more resilient and collaborative defense against evolving threats.

