CISA Breached by its Own Blind Spot

CISA Was Breached by Its Own Blind Spot — Here's What MSPs Should Take From It

July 24, 20262 min read

In May 2026, a contractor working with the Cybersecurity and Infrastructure Security Agency uploaded a copy of CISA's build and deployment repository to a personal GitHub account. Buried inside were live AWS GovCloud access keys, administrator credentials, and other secrets tied to CISA's own coding systems.

On July 9, CISA published its own forensic report — "Lessons from CISA's Cyber Incident" — walking through what happened and what it's changing.

The good news first: CISA's own logging caught it. Forensic analysis confirmed none of the leaked credentials were ever used outside CISA's environment, and no customer or mission data was exposed. Zero-trust architecture and solid logging did their job.

But the report is candid about what didn't go well. CISA had no playbook for a GitHub-specific credential leak and had to build one mid-incident. It didn't have a simple way for outside researchers to report vulnerabilities in its own systems — the researcher who found this one, GitGuardian's Guillaume Valadon, called it one of the worst credential exposures he'd seen. And CISA's controls on what could be pushed to public repositories weren't tight enough to stop a contractor from doing exactly that.

In response, CISA rotated every secret tied to the exposed environment, tightened its ability to monitor and restrict uploads to public code repositories, committed to building incident playbooks in advance rather than during a crisis, and said it will make it easier for outside researchers to flag vulnerabilities affecting CISA itself.

Here's the part worth sitting with: this is the agency that writes the playbook on credential hygiene for the rest of the federal government. A contractor with legitimate access made an ordinary mistake — pushing infrastructure code to a personal repo — and it still took real cleanup to contain.

If that can happen inside the agency that sets the standard, it can happen inside your client's environment. The failure mode here wasn't exotic. It was a contractor with too much standing access, secrets sitting in a repo instead of a vault, and no monitoring on where code and credentials could travel.

For MSPs, the checklist writes itself: Are privileged credentials rotated on a schedule, or only after something goes wrong? Do you have monitoring in place for code or secrets leaving your environment through personal accounts? Is there an incident playbook for a leaked-credential scenario sitting ready, or would your team be building it live under pressure like CISA did?

When was the last time you rotated privileged credentials for a client — was it scheduled, or did someone have to remember?

Source: CISA, "Lessons from CISA's Cyber Incident," July 9, 2026. https://www.cisa.gov/news-events/news/lessons-cisas-cyber-incident

Larry French

Larry French

Larry has been in the IT industry for over 30 years starting while serving in the US Navy in 1994 as a part time computer technician in Virginia Beach, Virginia.

LinkedIn logo icon
Back to Blog