CISA Left Plaintext Passwords and Cloud Keys Sitting on Public GitHub
The agency tasked with hardening America's cyber defenses accidentally exposed its own credentials to the open internet — and a private researcher had to find them first.
Written by OutOfToken AI
June 4, 2026 · 4 min read · Synthesized from reporting by TechCrunch Policy · How this works
The Cybersecurity and Infrastructure Security Agency, the federal body responsible for defending critical American infrastructure from digital attacks, suffered an embarrassing and potentially serious security lapse when plaintext passwords and cloud access keys were left exposed in a publicly accessible GitHub repository. The breach was first reported by veteran security journalist Brian Krebs, and the exposed credentials were traced to systems belonging to both CISA and its parent organization, the Department of Homeland Security. No sensitive data appears to have been compromised — but only because a good-faith researcher got there before anyone else did.
A Researcher Finds What CISA Missed
Guillaume Valadon, a security researcher at GitGuardian, discovered the exposed credentials during what appears to be routine scanning of public repositories for leaked secrets — precisely the kind of automated hygiene work that organizations like CISA routinely advise others to perform. Valadon found plaintext credentials embedded in spreadsheet files uploaded to GitHub, credentials that granted access to internal CISA systems and DHS cloud infrastructure. GitGuardian's tooling is specifically designed to catch this category of mistake, and the irony of a commercial security firm catching a lapse at the government's top cybersecurity agency is not lost on the industry. Valadon disclosed the findings responsibly, and CISA has since launched an internal investigation into how the credentials ended up in a public repository in the first place.
Scope of the Exposure
According to Krebs's reporting, the exposed credentials were not trivial: they covered access to systems operated by CISA itself and by DHS, meaning the blast radius of a malicious discovery could have extended deep into federal government infrastructure. Cloud keys in particular are high-value targets — they can grant persistent, scalable access to cloud environments far beyond what a single compromised password might offer. The fact that these credentials were sitting in a spreadsheet uploaded to a public-facing GitHub repository suggests a workflow failure somewhere in CISA's development or administrative pipeline, where someone moved sensitive configuration data through an insecure channel without triggering any internal detection.
"The agency that tells critical infrastructure operators to rotate credentials and audit repository access left its own cloud keys sitting in a public GitHub spreadsheet — discoverable by anyone with a browser."
The Institutional Optics Are Brutal
CISA publishes guidance, issues binding operational directives, and runs awareness campaigns specifically warning federal agencies and private operators about the dangers of hardcoded credentials and misconfigured repositories. Its Known Exploited Vulnerabilities catalog, Secure by Design initiative, and repeated advisories on secrets management make this incident a reputational wound as much as a technical one. The agency has confirmed it is investigating and has stated that no sensitive data was accessed as a result of the exposure. But the absence of confirmed damage does not erase the underlying process failure — and for an agency that derives much of its authority from perceived competence, the gap between its public posture and internal practice will invite scrutiny from Congress, oversight bodies, and the security community alike.
CISA will survive this incident operationally, but the reputational calculus is harder to fix. The episode illustrates that no organization — regardless of mandate or expertise — is immune to the mundane mistakes that cause most real-world breaches. What it demands now is a transparent post-mortem: how the credentials were uploaded, why internal scanning failed to catch them, and what structural changes will prevent a recurrence. Anything less, from an agency that holds the rest of the country to exactly that standard, would be its own kind of breach.
Editorial Note
This incident aligns with Brian Krebs's established track record of breaking cybersecurity stories with verifiable sources. CISA has a documented history of security incidents involving exposed credentials in public repositories. However, the full scope and impact details would require confirmation from CISA's official statement or independent verification of the specific GitHub repository and exposed credentials.
Claim Tracker
AI-assessed
Reported by Brian Krebs and confirmed by GitGuardian security researcher Guillaume Valadon
Claim made in article but assessment methodology and scope of audit not detailed
Attribution provided but not independently verified in article
Characterization of discovery as 'routine' is not substantiated with timeline or process details
Specific systems and access levels not enumerated; scope of access not detailed
Ask AI about this story
// discussion
sign in to join the discussion