Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys
Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and valid — including 526 AWS root keys and 817 keys linked to companies.
What the research found
- Thousands of AWS access keys exposed in public locations — code repositories, websites and other sources — hadn't been revoked, sometimes years after exposure.
- Hundreds were root account keys, which grant unrestricted access to an AWS account.
- Hundreds could be tied to identifiable organizations.
Other 2026 reporting described campaigns abusing exposed long-term keys, including the Crimson Collective group targeting AWS environments via exposed keys and IAM misconfigurations, and the TruffleNet campaign using stolen credentials to abuse Amazon SES for business email compromise.
Why it matters
Leaked keys are only dangerous while they work. The finding suggests many organizations:
- Don't know their keys were exposed.
- Don't receive or act on provider notifications.
- Still create root access keys, which AWS has recommended against for years.
- Don't rotate or expire keys.
Combined with AI-assisted attackers who move from key to admin in minutes, an active leaked key is an open door.
What to do now
- Delete all root access keys and use centralized root access management in AWS Organizations.
- Find and deactivate IAM user keys older than 90 days or unused.
- Make sure AWS notifications about exposed keys reach a monitored inbox.
- Enable secret scanning across repositories.
- Replace keys with roles and federation.
Sources
- How to Find, Disable and Replace Long-Lived AWS Access Keys How-To & Hardening
- Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries Detection & Response
- CIO Brief: Old Leaked Keys Are Still Open Doors CIO Briefings