← Retour au blog
tech 23 May 2026

Data Leak: Lawmakers Demand Answers from CISA

CISA is under increasing pressure after a contractor exposed AWS GovCloud keys on GitHub. Lawmakers demand answers as the agency struggles to contain the leak.

Article inspired by the original source
Lawmakers Demand Answers as CISA Tries to Contain Data Leak ↗ krebsonsecurity.com

Introduction

Data leaks are not only a nightmare for private companies but also for government agencies. Recently, the US Cybersecurity & Infrastructure Security Agency (CISA) found itself in a troubling situation: a contractor inadvertently published AWS GovCloud keys and other sensitive information on a public GitHub account. This has led lawmakers to demand firm answers from the agency.

The Incident in Detail

On May 18, 2026, KrebsOnSecurity reported that a CISA contractor, with administrative access to the agency's code development platform, created a public GitHub profile called "Private-CISA." This profile contained plaintext credentials to internal CISA systems. According to experts, the commit logs for the repository showed that the contractor had disabled GitHub's built-in protection against publishing sensitive credentials in public repositories.

Political Reactions

Senator Maggie Hassan expressed serious concerns in a letter to CISA's Acting Director Nick Andersen. She emphasized that this incident raises grave questions about CISA's internal policies, especially at a time of significant cybersecurity threats against U.S. critical infrastructure.

Implications for Security Culture

This incident occurred against the backdrop of major internal disruptions at CISA, which lost more than a third of its workforce and almost all of its senior leaders. Representative Bennie Thompson highlighted that this incident might reflect a weakened security culture within the agency.

Containment Measures

Currently, CISA is working to invalidate the leaked credentials and contain the breach. However, the lack of clear answers about the duration of the data exposure concerns experts. The agency stated that there is no indication that any sensitive data was compromised.

Lessons to Learn

This incident underscores the need for government agencies to strengthen their internal security policies, especially when managing contractors. The importance of continuous monitoring and training of teams is crucial to prevent such errors in the future.

Conclusion

As CISA continues to deal with the fallout from this data leak, it is essential to learn lessons to strengthen security practices. Decision-makers must ensure that strict protocols are in place to prevent such incidents from recurring.

Let's discuss your project in 15 minutes.

CISA data leak cybersecurity AWS GovCloud GitHub
Deepthix newsletter · 100% AI · every Monday 8am

An AI agent reads tech for you.

Our AI agent scans ~200 sources per week and ships the best articles to your inbox Monday 8am. Free. One click to unsubscribe.

Visit the newsletter page →

Want to automate your operations?

Let's talk about your project in 15 minutes.

Book a call