Back to all lessons
Awareness Lessons
2 months ago

Exposed AWS Key in Public JS Artifacts Leads to Mass Charity Data Breach

The root cause of this breach was a critical secret management failure: an AWS access key was inadvertently embedded in publicly accessible JavaScript build artifacts, granting attackers full access to cloud storage containing database backups. This represents a classic 'secrets in code' vulnerability that is entirely preventable with proper CI/CD pipeline hygiene and pre-commit scanning tools. The incident affected over 1,000 charities, exposing personal data of their donors and beneficiaries — populations who trusted these organisations with sensitive information. For SaaS providers serving mission-driven organisations, a single misconfiguration can have cascading reputational and regulatory consequences across an entire customer base, underscoring the outsized responsibility third-party vendors carry.

Tactical Insight

Immediate actions

  • Scan all public repositories and build artifacts immediately for exposed credentials using tools like GitGuardian, TruffleHog, or AWS Macie.
  • Rotate any exposed cloud access keys instantly and audit CloudTrail logs to determine the full scope of unauthorised access.
  • Encrypt database backups with customer-managed keys (CMK) and restrict S3 bucket access to least-privilege IAM roles only.

Long-term improvements

  • Integrate pre-commit hooks and secrets-scanning into every CI/CD pipeline to block credential exposure before code reaches public repositories.
  • Enforce short-lived, role-based IAM credentials (e.g., AWS STS assumed roles) rather than long-lived static access keys for all cloud operations.
  • Apply strict access controls and versioning on all backup storage, ensuring backups are never reachable via publicly discoverable credentials.

Detection measures

  • Enable AWS CloudTrail, S3 access logging, and GuardDuty to alert on anomalous access patterns such as bulk data downloads from unusual IP addresses.
  • Implement continuous secrets monitoring across all build pipelines and artifact registries with automated alerting on detection.
  • Conduct quarterly third-party penetration tests that specifically target secrets exposure in build artifacts and cloud configuration drift.