Back to advisories

Hundreds of leaked AWS keys give full control over corporate accounts

Over 9,300 active AWS access keys with admin privileges have been publicly exposed in code repositories and public sources, with Hugging Face identified as a major leak vector. Attackers with these keys can take full control of affected AWS accounts, exfiltrate data, compromise infrastructure, and deploy cryptominers. Any organization using AWS needs to assume their credentials may be compromised.

CRITICALAdvisoryAug 22, 2026
Action required
Immediately audit all AWS access keys in your environment. Revoke any keys found in public repositories or source code. Rotate all remaining keys and enable CloudTrail logging to detect unauthorized access or API activity. Check CloudTrail for any suspicious activity dating back 90 days.
Affected products
AWSAmazonTruffle SecurityHugging Face