The U.S. cyber regulator let its AWS keys slip six months ago.
A US federal cyber agency's subcontractor left their AWS GovCloud admin keys on a public GitHub repo for six months. Why not delegate your security, huh?
CISA, the U.S. federal cyber agency, has just discovered that its own subcontractor Nightwing had left a public GitHub repository stuffed with AWS GovCloud admin keys lying around for six months. Nobody on their side noticed. It was GitGuardian, from the outside, who rang the bell.
The Deal
On May 22, 2026, Brian Krebs published the investigation. An employee of Nightwing, a historic subcontractor of CISA based in Dulles, Virginia, created a GitHub repository named “Private-CISA” on November 13, 2025. The word “Private” in the name, the public setting in the parameters. The repo remained online, accessible to anyone, until mid-May 2026. Six months.
Inside, there’s heavy stuff. Three sets of admin keys for AWS GovCloud accounts, Amazon’s cloud environment dedicated to US federal agencies, certified FedRAMP High for hosting non-classified sensitive data (CUI).
Access tokens, SSH keys, internal logs, and clear-text passwords following the “platform-year” pattern that a third-year intern wouldn’t dare to try. Plus some internal documents about the agency’s software development processes. Almost nothing, huh!
And the detection? Neither CISA internal nor Nightwing audit. It’s Guillaume Valadon, a researcher at GitGuardian, who continuously scans public repos for forgotten secrets, who found the repo. Krebs and the consulting firm Seralys notified CISA, which had the repo taken down. The cherry on top: the AWS keys remained valid for 48 hours after the repo was removed before the agency decided to revoke them.
CISA’s official statement is one sentence we’ve seen a hundred times: “At this stage, there’s no indication that sensitive data has been compromised.” Nightwing refers to CISA, CISA refers to the investigation. Krebs qualifies the incident as “one of the most scandalous government data breaches in recent history,” and Bruce Schneier repeats the phrase without qualification.
Why it matters to you
You’re not CISA, you don’t have a Nightwing subcontractor, you don’t use AWS GovCloud. Great. Now, do the cold calculation. The agency that sets the cybersecurity standards for US administrations, that publishes “secure by design” guides and CVE alerts followed by the entire industry, just left its own cloud admin keys open for six months without noticing. Not some dodgy subcontractor or some third-rate SaaS: the cyber regulator itself.
The argument is structural, not anecdotal. When you entrust your secrets to a third party, no matter how serious they claim to be, you inherit their entire supply chain. CISA entrusts to Nightwing, Nightwing employs someone, that someone pushes to GitHub. The weak link compromises the entire chain in an instant. That’s bad enough on its own, but add the IA threat surge, and you’ve potentially got a backdoor into more confidential systems.
Let’s get back to you. You have a personal GitHub repo? You’ve ever pasted an API key into a commit for “quick testing” before forgetting to remove it from history? You use a cloud-owned password manager for creds that open your infrastructure? You trust a SaaS editor under foreign jurisdiction to keep your secrets securely encrypted for you? The CISA radar is you in miniature, but with fewer zeros on the consequences.
The MacSouverain angle doesn’t change by a millimeter from the first article. Keep your secrets with you. On your machine, in your local vault, under your key. You can delegate the formatting, syncing, encrypted backup. You don’t delegate security itself. Because the day your provider screws up, and they will, you want the blast radius to stop at them.
What you do now
1. Inventory what you’re currently entrusting to a cloud third party.
Grab a sheet of paper. Passwords, emails, contacts, files, notes, photo backups. For each one, write where it’s stored and who has the decryption key. If the answer to “who has the key” is “the provider, or one of their subcontractors,” you’re in exactly the same position as CISA. You’re trusting a chain you don’t control a link of.
2. Choose your cloud providers based on “end-to-end encrypted, key on client side”.
For what you have to put in the cloud (multi-device sync, sharing, backup), only accept providers who can’t read your content, even if they wanted to or were asked to.
For email and storage: Proton or Tuta, European jurisdiction, end-to-end encrypted by default. For VPN: Mullvad or Proton VPN, no logs. The difference from AWS, Google Drive, iCloud non-ADP: you don’t have to take the provider’s word for it, the architecture makes unauthorized access technically impossible.
3. What happens at your place stays at your place.
Whatever you can keep local, keep it local. Photos, archives, sensitive documents, backups: an encrypted APFS external drive at home, plus a second encrypted copy you store with a friend or in a safe. If you need to sync files between your own devices without going through a third party, Syncthing does direct P2P between your devices, period. You don’t go to the cloud by default, you go there deliberately. The CISA rule applies in miniature to everyone: the day your provider screws up, and they will, you want the blast radius to stop at them, not take you down with them.
Sources
- CISA Admin Leaked AWS GovCloud Keys on GitHub, Krebs on Security, May 22, 2026 (primary source)
- CISA Security Leak, Schneier on Security, May 22, 2026 (commented repost)
- GitGuardian, scanner of secrets in public repos
See also
What are those tech terms? Check the glossary.