CIO Brief: Old Leaked Keys Are Still Open Doors

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

The short version: Research reported in 2026 found more than 9,300 AWS access keys that had leaked publicly over four years were still working — including hundreds of "root" keys that give total control of a cloud account. Old leaks don't expire on their own.

Why leaked keys stay dangerous

A cloud access key is like a permanent password for software. If it's posted publicly by mistake — in code, a website or a document — anyone who finds it can use it until it's deactivated. Many organizations never find out, or don't act on notifications.

The business impact

  • Total account takeover with root keys.
  • Data theft, crypto mining and email fraud using stolen keys.
  • Silent exposure that can last years.

Questions to ask your team

  • How many long-lived cloud access keys do we have, and how old are they?
  • Do any of our AWS accounts have root access keys?
  • Who receives AWS notifications about exposed credentials, and what happens next?
  • Do we scan our code and documents for leaked keys?

What good looks like

No root keys, very few long-lived keys (replaced by temporary access), automated scanning for leaks, and a defined response when a provider reports an exposed key.

The decision

Ask for the number of active root and long-lived access keys across your AWS accounts. The target is zero root keys and a steadily shrinking number of the rest.

Sources

  1. Source
exposed aws access keys impact9,300 exposed AWS keys still active2026

More on this story