
Federal Cybersecurity Agency Accidentally Exposed Its Own Passwords Online
CISA, the government agency responsible for protecting against cyber threats, accidentally posted passwords and security keys in a public location online.
Source
TechCrunch Security
Original headline: US cyber agency CISA exposed reams of passwords and cloud keys to the open web
Plain-English summary by GetCyberRight. Read the full report at the source above.
The Cybersecurity and Infrastructure Security Agency, known as CISA, made a significant mistake by uploading a spreadsheet containing plaintext passwords and cloud security keys to GitHub, a public website where code is shared. Independent journalist Brian Krebs discovered and reported the exposure.
This is particularly concerning because CISA is the federal agency responsible for helping protect the United States from cybersecurity threats. This incident directly affected CISA's own systems, not individual family accounts. However, it matters to families because it shows that even cybersecurity experts make basic mistakes.
Stay one step ahead of scammers
Weekly cybersecurity briefings for families. No spam, just the threats that matter and what to do about them.
If the agency tasked with protecting our national cybersecurity infrastructure can accidentally expose passwords, it highlights how easily this can happen to anyone. It also potentially puts government systems at risk, which could affect public services.
- Never store passwords in regular documents, spreadsheets, or notes on your computer. Use a dedicated password manager instead.
- Review what you have saved in cloud storage services like Google Drive, Dropbox, or OneDrive. Make sure no documents contain passwords or sensitive information.
- Check your sharing settings on cloud documents to ensure nothing is set to public access when it should be private. The bigger lesson here is that human error causes many security breaches. Even security professionals make mistakes, so do not feel bad about needing help with digital security. Focus on building simple habits: use a password manager, enable two-factor authentication, and regularly review what information you are storing online and who can access it. Simple systems that are easy to follow work better than complex ones you might forget to maintain.
Curated from trusted cybersecurity sources by GetCyberRight
Source: TechCrunch SecurityStay ahead of cyber threats
Get our free weekly digest. Real threats, plain language, what to do about them. No spam, ever.
More articles

Europol Asks Public to Help Locate Convicted Criminals Still on the Run
European authorities launched a campaign seeking public help to find fugitives who were convicted of serious crimes but never served their prison sentences.
2 min read
European Police Ask Public to Help Locate Convicted Criminals
Law enforcement across Europe has launched a campaign asking citizens to help find fugitives who have been sentenced to prison but remain at large.
1 min readToday’s reminder to terminate employees’ credentials when their employment ends
Failure to terminate an employee’s credentials when their employment ended and failure to use unique and protected login credentials for work left a city at risk of having its water utility totally co
1 min readWhen Employees Leave, Companies Must Remove Their Access: A Water Utility's Close Call
A city's water system was nearly compromised because a former employee still had login access. This reminds families to secure their own shared accounts too.
2 min read