Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys
Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and...
Service
Benchmark your AWS estate against AWS's own reference architecture — with guardrails ready to deploy.
AWS environments that grew without guardrails tend to share the same weaknesses: long-lived access keys, root credentials, logging gaps and over-permissioned roles. Attackers increasingly go from a leaked key to administrator access in minutes.
Companies with 1–50 AWS accounts and no dedicated cloud security engineer.
A read-only cross-account role using AWS managed SecurityAudit and ViewOnlyAccess policies, deployed by your team.
Yes — and we'll show you whether moving to a multi-account structure is worth it for your size.
Research reported by ITPro in 2026 found that more than 9,300 AWS access keys publicly exposed between August 2022 and August 2026 were still active and...
Thousands of exposed AWS access keys remain active years after leaking. Here is how to find, disable and replace long-lived keys in your accounts.
In early February 2026, researchers described an AWS intrusion in which an attacker went from stolen credentials to administrative privileges in under ten...