A contractor for the Cybersecurity & Infrastructure Security Agency (CISA) leaked credentials to several highly privileged AWS GovCloud accounts and internal CISA systems on a public GitHub repository. The leak included files detailing how CISA builds, tests, and deploys software internally, and represents one of the most egregious government data leaks in recent history. The repository was taken offline after the leak was reported, but the exposed AWS keys remained valid for another 48 hours. CISA is investigating the incident and has stated that there is no indication that any sensitive data was compromised.