Join our Newsletter — 33% off our NHI Course
Home› NHI Breaches› Mobile Apps Hard-Coded AWS Keys 2022: What Symantec…
Breach analysis Incident: 1 Sep 2022

Mobile Apps Hard-Coded AWS Keys 2022: What Symantec Found in 1,859 Android and iOS Apps

← All NHI breaches
By Lalit Choda, NHI Mgmt Group Updated 8 October 2026 9 min read
Category: NHI
Attack route: Leaked secret Identities: Cloud credential
On this page

On 1 September 2022, Symantec published research showing that 1,859 publicly available mobile apps, about 98% of them on iOS, contained hard-coded Amazon Web Services credentials. Symantec says 77% of those apps held valid AWS access tokens for private cloud services, and 47% held valid tokens that gave full access to private files in Amazon S3, often millions of them. Over half the apps shared the same tokens with other apps, which Symantec traced to shared libraries and third-party software development kits (SDKs). In one case an identity SDK used by five banking apps exposed more than 300,000 biometric fingerprints; in another a token meant for a translation service opened every AWS service of a B2B intranet provider serving over 15,000 companies. Symantec notified the organisations in its case studies. It reported the exposure and the risk, not any malicious use of the keys.

Key takeaways

  • Symantec found hard-coded AWS credentials in 1,859 publicly available Android and iOS apps, about 98% of them iOS apps, according to its 1 September 2022 research.
  • Symantec says 77% of the apps contained valid AWS access tokens and 47% held valid tokens with full access to private S3 files; 53% used tokens also found in other apps.
  • Shared tokens came from the supply chain: third-party SDKs and libraries, including an identity SDK that exposed more than 300,000 biometric fingerprints across five banking apps.
  • This was research into exposed credentials, not a reported attack: Symantec notified the case-study organisations and did not report any misuse.
  • The identity lesson: a cloud key shipped inside an app belongs to everyone who downloads it, so mobile apps should receive short-lived, narrowly scoped credentials from a backend rather than carry static keys.

At a glance

OrganisationsDevelopers of 1,859 unnamed Android and iOS apps, including a B2B intranet and communications provider, five mobile banking apps using a digital identity SDK and 16 online gambling apps
WhenPublished by Symantec on 1 September 2022
AttackerNone known. Found by Symantec researchers
Entry pointAWS access credentials hard-coded in mobile app code, SDKs and shared libraries
Identities abusedAWS access tokens, some with access to all of an organisation's AWS services and some with read/write root account credentials
ImpactValid credentials exposed to anyone who downloaded the apps, reaching private S3 data, biometric records and full cloud infrastructure; no confirmed misuse
CategoryNHI. Incident class: exposure, no confirmed misuse (hard-coded cloud credentials found by researchers)

What happened

Symantec's researcher Kevin Watkins set out the findings in "Mobile App Supply Chain Vulnerabilities Could Endanger Sensitive Business Information". The team identified 1,859 publicly available apps containing hard-coded AWS credentials. "Over three-quarters (77%) of the apps contained valid AWS access tokens allowing access to private AWS cloud services," Symantec wrote. Close to half, 47%, held valid tokens that also gave full access to numerous, often millions of, private files in Amazon S3 buckets.

The study's main point was where the keys came from. "We discovered that over half (53%) of the apps were using the same AWS access tokens found in other apps," Symantec said, often apps from different developers and companies. It traced these to shared libraries, third-party SDKs and other shared components, which means an app's makers may not have known the credential was there. Developers embed keys for ordinary reasons, Symantec explained: to download or upload large assets, read configuration files, register devices or call authenticated services such as translation. Some keys had no clear purpose and sat in dead or test code.

Three case studies showed what the keys could reach. A B2B intranet and communications platform shipped a mobile SDK with cloud keys meant for a translation service; instead, "anyone with the token had full unfettered access to all the B2B company's AWS cloud services", exposing data for more than 15,000 medium and large companies. An outsourced digital identity SDK used by several iOS banking apps exposed credentials through which, Symantec said, "In total, over 300,000 biometric digital fingerprints were leaked across five mobile banking apps using the SDK." And a vulnerable library in 16 online gambling apps exposed full infrastructure, with read/write root account credentials across AWS services.

Symantec said the organisations in its case studies had been notified. Dick O'Brien, principal editor on Symantec's Threat Hunter team, told The Register that most cases came down to a lack of awareness, along with some developer sloppiness: "For the most part, it's driven by a degree of ignorance in terms of what you're exposing." Symantec's advice focused on adding security scanning to the app development lifecycle and checking what outsourced developers and SDKs put into each release.

Timeline

DateEvent
2022Symantec researchers analyse publicly available mobile apps and identify 1,859 with hard-coded AWS credentials.
1 September 2022Symantec publishes its research; The Register and The Hacker News report it the same day.

How it happened: the identity attack path

  1. Keys embedded for convenience. Developers or SDK makers put AWS access credentials into app code so the app could fetch assets, store data or call cloud services directly.
  2. Shared components spread them. The same tokens travelled through libraries and SDKs into apps from different developers, so 53% of affected apps shared tokens with others.
  3. Published to app stores. Each app download delivered the credentials to the user's device, where they can be extracted from the app package.
  4. Over-broad permissions. Many tokens reached far more than their purpose required, such as all AWS services or full S3 access instead of one bucket.
  5. Exposure of data and infrastructure. Valid tokens put private files, biometric records and in some cases root-level cloud access within reach of anyone who extracted them.

Impact

  • Confirmed exposure: 1,859 apps with hard-coded AWS credentials, 77% with valid tokens and 47% with full access to private S3 files, according to Symantec.
  • Case studies: data on more than 15,000 companies behind one SDK, more than 300,000 biometric fingerprints across five banking apps, and root credentials in 16 gambling apps.
  • Misuse: none reported. Symantec described the risk and notified case-study organisations; it did not report attackers using the keys.
  • Potential: attackers could read or change cloud data, steal personal and biometric records or take over cloud infrastructure until the keys were revoked.

What this means for NHI governance

Every hard-coded AWS key in these apps is a non-human identity, and shipping it inside an app means giving it to every person who downloads the app. Symantec's figures show how often those identities were both valid and over-privileged: a token needed for translation that opened every AWS service, or root credentials sitting in gambling apps. Once a key is in a published binary, there is no way to take it back except to revoke it.

The supply chain angle makes ownership harder. When over half the affected apps share tokens with other apps, the credential often belongs to an SDK vendor, not the app maker, and neither may be tracking it. The fix is architectural: apps should get short-lived, narrowly scoped credentials from a backend, through services such as Amazon Cognito or a token-vending API, and organisations should know which third-party components carry credentials into their releases. The same pattern appears in Cybernews's 2025 study of iOS apps. Our API Key Management Guide and Cloud Workload Identity Guide cover these controls.

Recommendations

  • Revoke and rotate any cloud key found in a shipped app. A key in a published binary is public; revoke it first, then fix the app. See the Leaked Credential Response Playbook.
  • Never ship long-lived cloud credentials in mobile apps. Issue short-lived, scoped credentials from a backend for each session instead. See our Cloud Workload Identity Guide.
  • Scope every key to its single purpose. A token for a translation service should not reach S3 or other services, and root account keys should not exist for app use. See our API Key Management Guide.
  • Scan app builds and SDKs for secrets before release. Add secrets scanning to the mobile build pipeline, including third-party components. See our Secrets Management Guide.
  • Hold SDK suppliers to account for credential handling. Ask outsourced developers and SDK vendors what credentials they embed and require scanning reports with each release. See our Third-Party Access Guide.
  • Monitor cloud keys for unexpected use. Alert when app credentials are used from unusual locations or call services outside their purpose.

Frequently asked questions

How many mobile apps had hard-coded AWS credentials in Symantec's study?

Symantec found 1,859 publicly available apps, about 98% of them iOS apps, with hard-coded AWS credentials. It said 77% contained valid access tokens and 47% held tokens with full access to private S3 files.

Were the exposed AWS keys used by attackers?

Symantec did not report any malicious use. Its research described the exposure and the risk, and it notified the organisations in its case studies. Keys in published apps should still be treated as compromised and revoked.

Why do mobile apps contain AWS keys?

Symantec says developers embed keys to download or upload assets, read configuration files, register devices or call services such as translation, and sometimes leave them in dead or test code. Many keys arrived through third-party SDKs and libraries.

iOS Apps Leaking Hard-Coded Secrets 2025 · Toyota T-Connect Key Exposure 2022 · Football Australia AWS Keys Exposure 2024 · API Key Management Guide · Cloud Workload Identity Guide

How NHI Mgmt Group can help

Credentials in client software are among the hardest non-human identities to see, because they leave the organisation with every release. We help teams find embedded keys, replace them with short-lived credentials and bring SDK suppliers into their NHI governance. See our NHI and AI agent security training.

References

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Written and reviewed by Lalit Choda, NHI Mgmt Group. Last updated 8 October 2026.
Based on the public sources listed under References. Details may change as investigations continue.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org