AWSCIO BriefingsRetrospectives

CIO Brief: When Your Security Vendor Loses Its Cloud Keys

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2019, written in 2026 with the benefit of hindsight.

The short version: In 2019, Imperva — a company that sells security protection — disclosed that customer data was exposed after an attacker stole a cloud access key from one of its systems. Security vendors hold sensitive data about you, and they can be breached like anyone else.

Why vendor key hygiene matters to you

Your security vendors often hold some of your most sensitive information: API keys, certificates, configuration details, user accounts. When they are breached, you must act quickly to rotate what they held.

The business impact

  • Exposure of credentials that could be used against your systems.
  • Urgent rotation work across teams.
  • Loss of trust in a provider you rely on for protection.

Questions to ask your team

  • What secrets and credentials do our security vendors hold for us?
  • How quickly could we rotate them if a vendor were breached?
  • Do our own systems still use long-lived cloud access keys like the one stolen here?
  • Do we ask vendors how they protect our data and keys?

What good looks like

An inventory of credentials shared with vendors, a rotation runbook, a preference for vendors that integrate with short-lived credentials, and your own environment free of long-lived keys.

The decision

Ask your team to count the long-lived cloud access keys in your own environment. If the number isn't small and shrinking, make replacing them a priority — it is the same weakness that exposed Imperva's customers.

imperva breach 2019 impactImperva AWS key2019

More on this story