In a public postmortem, the US Cybersecurity and Infrastructure Security Agency said it began responding on May 15, 2026, after a reporter asked about internal CISA AWS GovCloud keys and other information in a public GitHub repository.
CISA said it did not have a dedicated reporting route for researchers to flag issues involving its own infrastructure, and it did not have a GitHub-and-cloud incident-response playbook ready for this type of exposure. The agency developed that playbook during the response, rotated credentials and tightened controls on uploads to public code repositories.
The official account is available in CISA’s postmortem. A June 11 Senate oversight letter records the reported exposure of credentials and the questions sent to the agency.
Why the missing playbook matters
The episode shows why reporting channels and rehearsed response procedures need to exist before an incident. CISA’s acknowledgement supports that narrow operational lesson. It does not, by itself, establish that the agency had “no playbook” for incident response generally, or that staffing and leadership changes caused this particular exposure.
Correction, October 2, 2026: An earlier headline said CISA had no director, no playbook and a third fewer staff, and the article linked those conditions to the incident. The available evidence supports a narrower finding: CISA lacked a dedicated reporting route and a GitHub-and-cloud response playbook for this exposure. The unsupported staffing and causal claims have been removed, and direct official and congressional sources have been added.