Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› CISA Private-CISA GitHub Leak 2026: How a Contractor’s…
Breach analysis Incident: 13 Nov 2025

CISA Private-CISA GitHub Leak 2026: How a Contractor’s Public Repository Exposed AWS GovCloud Admin Keys for Six Months

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 29 September 2026 8 min read
On this page

For six months, from 13 November 2025 to 15 May 2026, a public GitHub repository called "Private-CISA" exposed credentials and internal files belonging to the US Cybersecurity and Infrastructure Security Agency. It was maintained by an employee of Nightwing, a CISA contractor. It held a file named "importantAWStokens" with administrative credentials to three AWS GovCloud accounts, a spreadsheet of plaintext passwords for dozens of internal CISA systems, credentials for CISA's internal Artifactory build repository, and details of how CISA builds and deploys software. The contractor had disabled GitHub's protection that blocks secrets from being pushed to public repositories. After GitGuardian researcher Guillaume Valadon flagged it, the repository came down, but the AWS keys stayed valid for about 48 more hours. CISA says there is "no indication that any sensitive data was compromised". Even so, Valadon called it "the worst leak that I've witnessed in my career".

Key takeaways

  • The "Private-CISA" repository was created on 13 November 2025 and stayed public until 15 May 2026. The Cloud Security Alliance says it held 844 MB of CISA DevSecOps material.
  • Exposed machine credentials included administrative keys for three AWS GovCloud accounts, Artifactory credentials, and Entra ID SAML certificates. Plaintext passwords for dozens of internal systems followed a guessable pattern: the platform name plus the current year.
  • Commit history shows the contractor disabled GitHub's default protection against publishing secrets. Researchers think the repository was used to sync files between a work laptop and a home computer.
  • Seralys founder Philippe Caturegli validated that the keys could authenticate to the three GovCloud accounts at a high privilege level. The keys remained valid for about 48 hours after the repository was taken down.
  • CISA says it found no indication that sensitive data was compromised. The case is still a warning about long-lived keys, disabled guardrails and contractor-held credentials.

At a glance

OrganisationsCybersecurity and Infrastructure Security Agency (CISA); Nightwing (contractor whose employee maintained the repository)
WhenRepository public from 13 November 2025; flagged and taken offline 15 May 2026; AWS keys valid until about 48 hours later
AttackerNone known. The exposure was found by GitGuardian researcher Guillaume Valadon and reported by KrebsOnSecurity
Entry pointA public GitHub repository used by a contractor, with GitHub's secret push protection disabled
Identities abusedAdministrative AWS GovCloud credentials, Artifactory credentials, Entra ID SAML certificates, and plaintext passwords for internal CISA systems
ImpactSix months of public exposure of high-privilege government cloud credentials and internal build pipeline details; CISA reports no indication of compromise
CategoryNHI. Incident class: exposure (admin keys publicly exposed and validated as working; no confirmed misuse)

What happened

On 15 May 2026, Guillaume Valadon of GitGuardian, which scans public code for exposed secrets, contacted KrebsOnSecurity about a repository whose owner was not responding to alerts. The repository, "Private-CISA", held what Krebs describes as "a vast number of internal CISA/DHS credentials and files, including cloud keys, tokens, plaintext passwords, logs and other sensitive CISA assets". Valadon said the commit logs showed the administrator had disabled GitHub's default setting that blocks secrets from being published. He summed it up: "Passwords stored in plain text in a csv, backups in git, explicit commands to disable GitHub secrets detection feature."

One file, "importantAWStokens", held the administrative credentials to three AWS GovCloud servers. Another, "AWS-Workspace-Firefox-Passwords.csv", listed plaintext usernames and passwords for dozens of internal CISA systems, including one that appears to be CISA's secure development environment. Philippe Caturegli, founder of Seralys, said he validated that the exposed credentials "could authenticate to three AWS GovCloud accounts at a high privilege level". He added that plaintext Artifactory credentials would be "a prime place to move laterally", because an attacker could backdoor packages used in every build. The Cloud Security Alliance describes the repository as 844 MB of CISA DevSecOps infrastructure, including Kubernetes manifests, GitHub Actions workflows, ArgoCD application files, Terraform code and Entra ID SAML certificates. Many internal passwords followed a guessable pattern: the platform name followed by the current year.

The repository was created on 13 November 2025 and was committed to regularly. Caturegli suspects the contractor used it "to synchronize files between a work laptop and a home computer". It was maintained by an employee of Nightwing, a government contractor in Dulles, Virginia, which declined to comment. The account was taken offline shortly after Krebs and Seralys notified CISA, but Caturegli said the AWS keys stayed valid for another 48 hours. A CISA spokesperson said: "Currently, there is no indication that any sensitive data was compromised as a result of this incident."

Timeline

DateEvent
13 November 2025The "Private-CISA" repository is created; regular commits follow.
15 May 2026GitGuardian's Guillaume Valadon flags the repository; it is taken offline the same day after CISA is notified.
17 May 2026Exposed AWS GovCloud keys remain valid until about 48 hours after takedown (Caturegli, via KrebsOnSecurity).
19 May 2026eSecurity Planet reports the leak; CISA says it is investigating.
26 May 2026The Cloud Security Alliance publishes its analysis of the exposure.

How it happened: the identity attack path

  1. Privileged credentials held by a contractor. A contractor with an administrative role in CISA's DevSecOps environment kept administrative cloud keys and internal passwords in files.
  2. A personal sync workflow. The files were synced through a GitHub repository, apparently to move work between devices.
  3. Guardrails switched off. GitHub's protection against pushing secrets was deliberately disabled, so nothing stopped the credentials going public.
  4. Six months of exposure. The repository stayed public for six months while alerts went unanswered.
  5. Slow revocation. Removing the repository did not revoke the keys. They stayed valid for about two more days, a window for anyone who had already copied them.

Impact

  • Exposed: administrative credentials to three AWS GovCloud accounts, Artifactory credentials, Entra ID SAML certificates, plaintext passwords for dozens of internal systems, and CISA's build and deployment configurations.
  • Confirmed misuse: none reported. CISA says there is no indication that sensitive data was compromised.
  • Risk: the GovCloud and Artifactory credentials could have enabled cloud takeover or supply chain tampering by anyone who found the repository during the six months it was public.

What this means for NHI and AI agent security

The Private-CISA leak is a catalogue of non-human identity failures in one place. There were long-lived administrative cloud keys, credentials stored in plaintext files, the same secrets reused across devices through a personal workflow, a disabled secret-scanning guardrail, a contractor holding the keys to the build pipeline, and keys that were not revoked when the exposure was found. None of this needed an attacker. The agency responsible for defending US federal networks exposed its own machine identities through ordinary practices that were never caught.

The fix is not just more scanning. It is removing the long-lived keys that make scanning necessary. Workload identity, short-lived cloud credentials and vault-issued secrets mean that a copied file holds nothing that still works. Organisations should also treat contractor-held credentials as part of their own estate, with ownership, expiry and monitoring. Our NHI Ownership Guide and Third-Party Access Guide cover both.

Recommendations

  • Replace static cloud admin keys. Use federated, short-lived credentials for administrative cloud access and remove long-lived access keys. See our Cloud Workload Identity Guide.
  • Enforce secret scanning and push protection. Make push protection mandatory in your GitHub organisation, prevent users from disabling it, and monitor contractors' public repositories for your secrets. See our Secrets Management Guide.
  • Revoke first, clean up second. When a secret is exposed, revoke and rotate it immediately. Removing the file is not enough. Use our Leaked Credential Response Playbook.
  • Govern contractor-held credentials. Assign an owner, an expiry and monitoring to every credential issued to a contractor, and review them regularly. See our Third-Party Access Guide.
  • Protect build infrastructure credentials. Treat Artifactory, CI and deployment credentials as tier-zero, with strong authentication and no plaintext storage. See our CI/CD Pipeline Identity Security Guide.
  • Ban guessable password patterns. Passwords built from a system name and the year are cracked quickly once any are known.

Frequently asked questions

What was exposed in the CISA GitHub leak?

A public repository named "Private-CISA" exposed administrative credentials to three AWS GovCloud accounts, plaintext passwords for dozens of internal CISA systems, Artifactory credentials, Entra ID SAML certificates, and configuration files describing how CISA builds and deploys software.

Was CISA hacked?

No attack has been reported. CISA says there is no indication that any sensitive data was compromised. However, the credentials were public for six months and remained valid for about 48 hours after the repository was removed, so misuse cannot be ruled out from public information.

How did the credentials end up on GitHub?

Researchers believe a Nightwing contractor used the repository to sync files between a work laptop and a home computer. Commit history shows GitHub's secret-blocking protection had been disabled.

ShinyHunters FBI breach claim 2026 · Home Depot year-long token exposure · 17,000 secrets exposed in public GitLab repositories · Public Sector Identity Security Guide · Guide to the Secret Sprawl Challenge

How NHI Mgmt Group can help

Securing Non-Human Identities (NHIs), including AI agents, is becoming increasingly crucial as long-lived keys and plaintext secrets keep turning up in public repositories. Our NHI Foundation Level Training Course gives teams the practical grounding to find, rotate and replace them.

References

Explore further

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 29 September 2026.
    Based on the public sources listed under References. Details may change as investigations continue.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org