CIO Brief: Old Leaked Keys Are Still Open Doors
The short version: Research reported in 2026 found more than 9,300 AWS access keys that had leaked publicly over four years were still working — including hundreds of "root" keys that give total control of a cloud account. Old leaks don't expire on their own.
Why leaked keys stay dangerous
A cloud access key is like a permanent password for software. If it's posted publicly by mistake — in code, a website or a document — anyone who finds it can use it until it's deactivated. Many organizations never find out, or don't act on notifications.
The business impact
- Total account takeover with root keys.
- Data theft, crypto mining and email fraud using stolen keys.
- Silent exposure that can last years.
Questions to ask your team
- How many long-lived cloud access keys do we have, and how old are they?
- Do any of our AWS accounts have root access keys?
- Who receives AWS notifications about exposed credentials, and what happens next?
- Do we scan our code and documents for leaked keys?
What good looks like
No root keys, very few long-lived keys (replaced by temporary access), automated scanning for leaks, and a defined response when a provider reports an exposed key.
The decision
Ask for the number of active root and long-lived access keys across your AWS accounts. The target is zero root keys and a steadily shrinking number of the rest.
Sources
- Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys Incident Teardowns
- How to Find, Disable and Replace Long-Lived AWS Access Keys How-To & Hardening
- Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries Detection & Response