Cybersecurity and Infrastructure Security Agency
Incident posture
Linked entities
- Victim
- Cybersecurity and Infrastructure Security Agency
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
The Cybersecurity and Infrastructure Security Agency discovered that a contractor employee had placed passwords, cloud keys and internal system data in a public GitHub repository, which was found by a security researcher and reported to the agency through a journalist. After being notified, the agency worked with GitHub to take the repository offline, revoked the exposed secret keys and issued replacements, and stated that no mission‑critical or personal data was compromised. In its after‑action report the agency acknowledged that it had no pre‑existing response plan for such a leak, forcing staff to create procedures during the incident, and noted that communication channels with external researchers were not clearly defined. The report also mentioned that the agency has been operating without a permanent director and that a significant portion of its workforce has been affected by cuts, furloughs and layoffs.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On November 13 2025 a contractor supporting the Cybersecurity and Infrastructure Security Agency (CISA) and the Department of Homeland Security created a private GitHub repository named “Private‑CISA” that remained publicly accessible until mid‑May 2026. The repository held roughly 844 megabytes of data, with 498 megabytes in the active working tree and the remainder in Git history and objects, and contained AWS GovCloud administrative credentials for multiple accounts, access keys, tokens, and plaintext usernames and passwords for internal CISA systems. Among the files were an “importantAWStokens” file, CSV exports of browser‑saved passwords, credentials for CISA’s Landing Zone DevSecOps environment, and authentication data for internal Artifactory and other development infrastructure. The repository also exposed CI/CD build logs, Kubernetes manifests, ArgoCD configuration, Terraform infrastructure code, GitHub Actions workflows, internal documentation, and scripts for managing cloud and container environments. Researchers from GitGuardian and other firms confirmed that the material provided a detailed view of CISA’s cloud footprint, deployment workflows, and software supply‑chain tools, including references to AWS accounts, internal service endpoints, and secret‑management paths. On May 14 2026 GitGuardian researcher Guillaume Valadon discovered the exposure, reported it to CERT/CC the same day, and contacted CISA directly on May 15. Security consultant Philippe Caturegli and others examined the contents and verified that several AWS GovCloud credentials were still active and could authenticate to privileged environments when tested, with some keys remaining valid for nearly 48 hours after CISA was notified. Multiple researchers independently confirmed the authenticity of the data and stated that at least some credentials worked against CISA‑linked GovCloud infrastructure before being revoked. Valadon described the repository as a “catalogue of unsafe practices,” citing plaintext passwords stored in CSV files, Git backups committed directly into the repo, and instructions to disable GitHub’s native secret‑scanning features, and noted the presence of easily guessed password patterns that combined platform names with the current year. After being contacted by researchers and journalists, CISA worked with GitHub to restrict access to the repository, which was taken offline on May 15 2026, roughly 26 hours after Valadon’s initial discovery. Upon taking the repository offline, CISA revoked all exposed secret keys and replaced them with new ones, and the agency stated that no mission‑critical or personal user data had been found to fall into the wrong hands as a result of the incident.
CISA acknowledged in its internal report that it lacked a ready‑made response plan for situations where secret keys and data allowing access to its systems were leaked to a public network, forcing staff to develop an action plan from scratch during the early stages of the incident. The agency also noted that communication channels with security researchers were not clearly defined at the time, and it subsequently promised to improve its communication system to enable faster reporting of risks by external experts. Reports indicated that CISA had been operating without a permanent director since January 2025, when Donald Trump began his presidential term, and that nearly a third of its workforce had been affected by cuts, furloughs, and layoffs, a situation experts said was negatively impacting the agency’s cybersecurity posture. Despite the lack of a prepared playbook, CISA conducted an investigation into the exposure and maintained that it had not found evidence so far that sensitive data was compromised or misused as a result of the leak. A spokesperson said the agency holds its team members to the highest standards of integrity and operational awareness and is working to ensure that additional safeguards are implemented to prevent similar incidents. CISA has not yet published a full technical incident report or a detailed timeline of remediation. The exposure occurred while CISA plays a central role in federal cyber defense, including securing cloud environments used by civilian agencies and promoting best practices across government and industry, and security professionals have pointed out the contrast between the agency’s public guidance on secure software development and the insecure practices revealed in the contractor‑managed GitHub repository. The incident prompted a sharp reaction from the security community, with several researchers describing it as one of the most serious government credential exposures they have encountered, and industry groups and experts have called for CISA to release a detailed post‑incident review that explains what systems were affected, what testing has been performed to look for potential compromise, and how the agency is tightening controls over contractor access and code repositories. On Capitol Hill, lawmakers have begun demanding briefings and written responses from CISA leadership about the incident, asking questions about the duration of the credential exposure, whether any malicious access occurred, what third‑party environments may have been at risk, and how CISA is updating policies for managing secrets in code and configuration files. Some members of Congress have also signaled interest in broader oversight of federal cloud and DevSecOps practices, including requirements placed on contractors that handle sensitive government infrastructure. The CISA GitHub exposure highlights a structural weakness in how federal agencies manage secrets across increasingly complex cloud and DevSecOps environments, as the repository aggregated a broad range of highly privileged credentials, scripts, and infrastructure descriptions in one public location, significantly amplifying potential risk. For an adversary, such a dataset would offer both direct access paths via still‑valid keys and a detailed blueprint of CISA’s internal architecture that could inform later intrusion attempts, supply‑chain attacks, or targeted phishing. The incident also exposes a gap between stated best practices and on‑the‑ground implementation among government contractors, as the presence of plaintext passwords, weak password patterns, disabled secret scanning, and Git history containing backups suggests that basic hygiene controls either were not enforced or were easily bypassed in this environment.
Sources
Sources available to members: 2 sources.