In stunning display of stupid, secret CISA credentials found in public GitHub repo

Ars Technica News

Summary

A public GitHub repository named 'Private-CISA' exposed plaintext passwords, SSH keys, and tokens belonging to CISA, allowing high-privilege access to AWS GovCloud accounts. The breach was discovered by GitGuardian and reported by Brian Krebs, following a previous incident where the acting CISA director leaked government documents via ChatGPT.

<p>Security researcher Brian Krebs <a href="https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/">brings us the news</a> that America's <a href="https://www.cisa.gov/">Cybersecurity &amp; Infrastructure Agency</a> (CISA) has had a large store of plaintext passwords, SSH private keys, tokens, and "other sensitive CISA assets" exposed in a public GitHub repo since at least November 2025.</p> <p>The now-offline public repo—named, somewhat aspirationally, "Private-CISA"—was brought to Krebs' attention by GitGuardian's <a href="https://blog.gitguardian.com/author/guillaumevaladon/">Guillaume Valadon</a>, who was alerted to the repo's presence by GitGuardian's public code scans. Krebs says that Valadon approached him after receiving no responses from the Private-CISA repo's owner.</p> <p>In an email to Krebs, Valadon claimed that the repo's commit logs show that GitHub's default protections against committing secrets—protections designed to protect unwitting or unskilled developers against exactly this kind of stupidness—had been disabled by the repo's administrator.</p><p><a href="https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/">Read full article</a></p> <p><a href="https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/#comments">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 05/19/26, 09:57 PM

# In stunning display of stupid, secret CISA credentials found in public GitHub repo Source: [https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/](https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/) Security researcher Brian Krebs[brings us the news](https://krebsonsecurity.com/2026/05/cisa-admin-leaked-aws-govcloud-keys-on-github/)that America’s[Cybersecurity & Infrastructure Agency](https://www.cisa.gov/)\(CISA\) has had a large store of plaintext passwords, SSH private keys, tokens, and “other sensitive CISA assets” exposed in a public GitHub repo since at least November 2025\. The now\-offline public repo—named, somewhat aspirationally, “Private\-CISA”—was brought to Krebs’ attention by GitGuardian’s[Guillaume Valadon](https://blog.gitguardian.com/author/guillaumevaladon/), who was alerted to the repo’s presence by GitGuardian’s public code scans\. Krebs says that Valadon approached him after receiving no responses from the Private\-CISA repo’s owner\. In an email to Krebs, Valadon claimed that the repo’s commit logs show that GitHub’s default protections against committing secrets—protections designed to protect unwitting or unskilled developers against exactly this kind of stupidness—had been disabled by the repo’s administrator\. Testing by[Seralys founder Philippe Caturegli](https://seralys.com/about/)showed that this was not a joke or hoax and that he was able to use the credentials in the Private\-CISA repo to gain access to multiple Amazon Web Services GovCloud accounts “at a high privilege level\.” Krebs notes that the repo appeared to be managed by Virginia\-based[Nightwing](https://nightwing.com/), a CISA contractor\. Nightwing has so far not commented publicly, instead referring questions back to CISA\. This isn’t the first time CISA has screwed up—in fact, it’s not even the first time*this year*\. In January,[polygraph\-failing](https://www.politico.com/news/2025/12/21/cisa-acting-director-madhu-gottumukkala-polygraph-investigation-00701996)acting CISA Director Madhu Gottumukkala[uploaded sensitive government documents to ChatGPT](https://arstechnica.com/tech-policy/2026/01/us-cyber-defense-chief-accidentally-uploaded-secret-government-info-to-chatgpt/)after demanding and receiving an exemption to the agency policy that prohibited ChatGPT’s use by CISA personnel\. Gottumukkala was[removed from his role in February](https://www.cybersecuritydive.com/news/cisa-acting-director-removed-madhu-gottumukkala/813378/)\.

Similar Articles

CISA Admin Leaked AWS GovCloud Keys on Github

Krebs on Security

A CISA contractor leaked highly privileged AWS GovCloud credentials and internal system passwords on a public GitHub repository, representing one of the most egregious government data leaks in recent history.

U.S. Cybersecurity Agency Leaves Its Digital Keys Out in Public on GitHub

Hacker News Top

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) exposed its cloud storage credentials in plain text on a public GitHub repository named 'Private-CISA' for about six months, until the leak was fixed over the weekend. No evidence of compromise has been found, but the incident underscores ongoing turmoil within the agency.

Lawmakers Demand Answers as CISA Tries to Contain Data Leak

Krebs on Security

Lawmakers demand answers after a CISA contractor intentionally exposed AWS GovCloud keys and other secrets on a public GitHub repository, raising concerns about the agency's security culture amid staffing disruptions.

Lessons Learned from CISA’s Recent GitHub Leak

Krebs on Security

CISA's postmortem on a GitHub leak of internal credentials highlights critical incident response failures, including delayed key rotation and ignored automated alerts, offering key lessons for security teams.