Threat Intelligence

Massive AWS key exposure and a wave of data breaches raise alarm

⏱️ 4 min read📅 8/28/2026👁️ 5 views

Credential sprawl hits the cloud hard

Truffle Security’s latest scan turned up more than 700 active corporate AWS keys that grant full‑account control, uncovered while reviewing 10,616 exposed keys collected between 2022 and 2026.

Intruder’s broader sweep of 3.5 million hosts found 28,000 exposed Git repositories, leaking over 400 AWS keys, 107 Stripe keys, 123 OpenAI keys, 80 Telegram tokens and 17 GitHub personal‑access tokens.

Why it matters

Full‑account keys are the master keys of the cloud; anyone who gets hold of them can spin up resources, exfiltrate data or launch ransomware from the victim’s own environment. The sheer volume suggests that many organizations still treat cloud credentials like static passwords.

Mobile banking under AI‑enhanced assault

Zimperium catalogued 30 mobile‑malware families that are now targeting more than 800 banking and fintech apps across 44 EMEA countries. Their report notes a rise in the use of AI to automate parts of the attack chain, though the extent of AI involvement remains an observation rather than a measured fact.

Synthetic data masks the true scope of a breach

Troy Hunt’s analysis of the Carhartt incident shows that roughly half of the 24.8 million email addresses claimed in the breach were synthetic benchmark data, not real customers.

Paylogix hit by ransomware

Paylogix confirmed that attackers stole files in November, exposing social‑security numbers, financial, health‑insurance, medical, passport and taxpayer‑ID data for at least 67,789 people in South Carolina, New Hampshire and Vermont. The Akira ransomware group claimed credit for the theft.

Manchester Airports Group breach

Hackers accessed personal data of about 8.7 million MAG customers – email addresses, phone numbers, vehicle registrations and postcodes. The attackers demanded a ransom; MAG refused to pay and reported that airport operations continued uninterrupted.

Log4j alert deemed a "known security non‑finding"

Developers of Apache Log4j 2 described the recent vulnerability as a "known security non‑finding" and said exploitation requires very specific circumstances.

Minimus winds down after a funding round

Minimus announced it is winding down operations after raising $51 million in 2025 and being acquired by Echo.

U.S. sanctions on Iranian MOIS‑linked actors

The U.S. Treasury sanctioned three Iranian individuals – Keyvan Fayyaz Ghareh Blagh, Saber Shahbazi Balujeh and Mohammad Reza Kadkhoda’i – tied to the Ministry of Intelligence and Security, and added four of the 17 Iranian cyber actors previously charged by the FBI to the sanctions list.

Defensive steps

  • Rotate all exposed cloud keys immediately and replace them with short‑lived credentials where possible.
  • Enforce least‑privilege policies; no service account should have full‑account rights unless absolutely necessary.
  • Deploy automated monitoring for anomalous key usage and integrate alerts with your SIEM.
  • Audit public repositories for accidental credential leaks; treat Git as a potential attack surface.
  • Patch Log4j installations to the latest version, even if the vendor downplays the risk.
  • For mobile app teams, incorporate anti‑tampering checks and consider AI‑driven detection tools, keeping in mind that the AI claim is not yet quantified.
#AWS#credential leaks#data breach#ransomware#sanctions