U.S. Cyber Agency Admits It Wasn't Ready for a Security Breach

The U.S. government's main cybersecurity agency, CISA, admitted this month that it didn't have a plan ready when someone accidentally exposed sensitive government passwords on GitHub in May 2026. CISA had to make up its response as it went along instead of following a prepared procedure.
A contractor working for CISA uploaded digital credentials—essentially digital keys that unlock access to government computer systems—to a public GitHub repository, a code-sharing website. A security company called GitGuardian noticed the exposed credentials and tipped off a cybersecurity journalist named Brian Krebs. CISA only learned about the problem after Krebs contacted them directly to report it. The agency then took down the exposed credentials and replaced them with new ones.
No sensitive government data was stolen in the breach. CISA also acknowledged that it made it too hard for security researchers to report problems they discovered. The agency said it has since made those reporting channels clearer.
The admission is embarrassing for a specific reason. CISA's job is to help the rest of the U.S. government and private companies protect themselves against cyberattacks. For years, CISA has told other organizations to prepare incident response plans ahead of time—plans that spell out exactly what to do when a breach happens. It turns out CISA didn't follow its own advice. When the breach occurred, the agency had to create its response plan from scratch.
Exposed credentials through code-sharing websites happen regularly. Companies have built entire tools just to catch and prevent this kind of mistake. That GitGuardian—a firm designed specifically to find these leaks—found CISA's mistake is unsurprising. What is surprising is that CISA didn't catch it first with its own tools.
Since the beginning of 2025, CISA has faced serious staffing problems. The agency lost about one-third of its employees due to budget cuts and layoffs. For much of this year, the agency was so short-staffed it had to furlough most of its workers temporarily. CISA has also not had a permanent leader since January 2025. It is not clear from CISA's report whether these staffing problems contributed to the lack of a response plan, but the timing is notable.
One positive sign: CISA was willing to publish a honest report about what went wrong. Many organizations hide their mistakes; CISA published this report for the public to read. That approach is something CISA has recommended to other organizations for years. Whether CISA actually fixes the problems it identified—by writing those plans and testing them before the next incident—will be the real test of whether it learned anything from this breach.


