AWS Automatically Quarantines Exposed IAM Keys Within 10 Seconds of GitHub Leak
AWS quarantined a leaked IAM key 10 seconds after Unit 42 published it to public GitHub.
Palo Alto Networks Unit 42 published a controlled test showing AWS attached the AWSCompromisedKeyQuarantineV3 policy 10 seconds after an IAM access key was pushed to a public GitHub repository on December 19, 2025. GitHub secret scanning reported the secret, and CloudTrail recorded AttachUserPolicy at 18:50:15 UTC, though the event attributed the action to the affected user. The managed deny policy, evolved from a 2020 original through V2 and V3, blocks selected high-risk actions across services including IAM, S3, Lambda, Bedrock, and SageMaker without revoking the key. AWS still expects administrators to rotate or deactivate exposed keys and hunt surrounding CloudTrail activity.