Policy & Regulation
CISA faces security lapse after contractor exposes credentials
CISA may have avoided a major breach after a contractor accidentally exposed plaintext credentials and cloud keys for US civilian federal network systems on GitHub.
The Cybersecurity and Infrastructure Security Agency (CISA), the US government body responsible for protecting civilian federal networks, may have escaped a sizable security breach after a contractor exposed sensitive access details. Guillaume Valadon, a security researcher at GitGuardian, identified exposed plaintext credentials listed in spreadsheets within a public GitHub repository. According to Valadon, these credentials were used for accessing systems belonging to CISA and its parent agency, the Department of Homeland Security. The exposed files included access tokens, cloud keys, and other sensitive files, some of which Valadon tested to verify they were valid. Valadon reported the lapse to independent security reporter Brian Krebs, who first broke the story, after the CISA contractor maintaining the GitHub environment failed to respond to alerts. In response, CISA spokesperson Marco DiSandro stated that the agency is aware of the exposure and is continuing to investigate, but added that there is “no indication that any sensitive data was compromised as a result of this incident.”
The incident represents a significant security lapse for CISA, which is tasked with defending the US civilian federal network and advising other organizations on cybersecurity best practices. The agency, which routinely warns organizations against storing passwords in unencrypted spreadsheets, found itself vulnerable to the very practices it counsels against. Although the exposure originated from an employee working for an external contractor, CISA remains ultimately responsible for the security of its own network and systems, including those managed by third-party contractors. The fact that the contractor exposed reams of passwords and cloud keys to the open web highlights the persistent risks that third-party vendors pose to federal infrastructure, even when the agency itself did not directly leak the data.
This security lapse comes at a time of transition and internal instability for the agency. CISA has been operating without a permanent director since January 20, 2025, when former director Jen Easterly stepped down. Furthermore, the agency has experienced significant resource constraints, losing a third of its workforce to cuts, furloughs, and layoffs since the change in administration.
Why it matters
The security lapse is particularly embarrassing for CISA because the U.S. government agency is responsible for cybersecurity across the civilian federal network and advises on best cybersecurity practices. The incident underscores the critical vulnerability that third-party contractors represent to federal defense frameworks.