CISA Exposed Credentials in Public GitHub Repository
A federal cybersecurity agency left plaintext passwords and cloud keys in a spreadsheet uploaded to a public GitHub repository. An independent researcher identified the exposure and reported it after the contractor did not respond.
9to5mac.comA federal cybersecurity agency left plaintext passwords and cloud keys in a spreadsheet uploaded to a public GitHub repository. An independent researcher identified the exposure and reported it after the contractor did not respond.
GitGuardian security researcher Guillaume Valadon found reams of exposed plaintext credentials listed in spreadsheets, which had been made publicly accessible in a GitHub repository by an employee working for a CISA contractor. Valadon told Krebs that the exposed credentials were used for accessing systems belonging to CISA and its parent agency, the Department of Homeland Security.
Valadon said the credentials included access tokens, cloud keys, and other sensitive files. Valadon told Krebs that he tested some of the keys to verify that they were valid. He then reported the lapse to Krebs because the CISA contractor who maintained the GitHub environment did not respond to their alerts.
It is not clear if anyone found or used the credentials other than Valadon.
When reached by TechCrunch, a CISA spokesperson did not immediately comment or say if the agency has any evidence of a breach stemming from this exposure. TechCrunch asked if the agency has revoked and replaced the exposed credentials following the incident.
While the incident was traced back to an employee working for a CISA contractor, CISA is ultimately responsible for the security of its own network and systems, including contractors who work for the agency. The security lapse is particularly embarrassing for CISA because the U.S. government agency is responsible for cybersecurity across the civilian federal network.
The organization also advises on best cybersecurity practices, which includes storing passwords in secured password managers and not in unprotected spreadsheets.
Key Facts
Potential Impact
- 01
Agency may need to revoke and replace exposed credentials.
- 02
Contractor practices for storing credentials may be reviewed.
Transparency Panel
Related Stories
EuronewsWorld Urban Forum 2026 Draws 57,000 Participants from 176 Countries
The 13th World Urban Forum concluded with discussions on housing, climate resilience and urban governance. Organisers reported that the sessions informed future strategic priorities.
theverge.comTrump Mobile website still lists T1 phone as American-made
The product page for the T1 phone continues to describe the device as American-made. The Verge reported that the site may conflict with FTC advertising rules. The phone was announced in June 2025.
France 24EU Discusses Readiness for Artificial Intelligence Changes
A France 24 program examined whether European Union policies can address the effects of artificial intelligence. The discussion covered potential impacts across daily life and economic sectors.