HomeAlertsCASE-5502
Back to Alerts

AWS IAM access key committed to public GitHub repo by Riley Nguyen

CriticalAI ReadyMatters AI already took action automatically. Review and confirm, or override.User: r.nguyen@acme-corp.comDetected: 18 min ago
True positiveAutomated containment applied

r.nguyen@acme-corp.com pushed a commit to github.com/acme-corp/data-pipeline (public repo) at 10:52 containing a live AWS IAM access key (AKIA…) in a .env file. GitHub Advanced Security detected the secret within 4 seconds via pattern match (AKIA[0-9A-Z]{16}) with checksum validation — 97% confidence. The key was immediately revoked via the AWS IAM API before any external actor could use it. CloudTrail shows 0 API calls against the key between push and revocation (4-second window). Riley's commit was blocked from the remote and a new pre-commit hook has been deployed.

WHY FLAGGED
Live AWS IAM key (AKIA…) committed to a public repo — verified active via AWS STS GetCallerIdentity
Pattern match: AKIA[0-9A-Z]{16} — GitHub Advanced Security confidence 97%
Public repository — zero access controls, key visible to the open internet within seconds
Alert Info
Assigned to
Unassigned
Alert ID
CASE-5502
AI Investigation
Automated containment applied
Alerts
1 linked
Detection
Datastore types
GitHub, S3
Policy
Risk type
Credential Misuse
User
User
Riley Nguyenr.nguyen@acme-corp.com
Employee ID
ACME007723
Department
Engineering
Employment
Active
Ask Matters AI
Hi, I'm Matters AI. Ask me about your alerts, cases, or policies.