CISA Admits It Had No Incident Response Plan When Contractor Exposed Government Credentials

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has disclosed that it lacked a prepared response plan when a security incident unfolded in May 2026, forcing staff to build one on the fly while simultaneously managing the crisis.

The incident began when independent cybersecurity journalist Brian Krebs reported that a security researcher at cyber firm GitGuardian had discovered reams of exposed passwords stored in a publicly accessible GitHub repository. The credentials had been uploaded by an employee of a CISA contractor and included sensitive keys for accessing U.S. government systems. The researcher had attempted to alert the contractor directly but received no response. Only after Krebs contacted CISA did the agency take the repository offline and revoke and replace all exposed credentials.

In a post-mortem report published Friday, CISA acknowledged that its staff “had to spend time building [a playbook] during the early stages of the incident.” The agency said it “missed” an opportunity to prepare ahead of time and stressed the importance of having playbooks ready for “all anticipated needs” before an incident occurs. CISA did not specify how much the missing plan delayed its response.

The agency stated that no customer or mission data was exposed and thanked the researcher and journalist for their assistance. CISA also acknowledged that its channels for security researchers to report potential incidents “were not well defined” and said it has since made changes to improve that process.

The disclosure comes as CISA has faced significant internal disruption. The agency has been without a permanent director since January 2025, when President Donald Trump began his second term, and has seen cuts, furloughs, and layoffs affecting roughly a third of its workforce. The lack of a response playbook at an agency responsible for defending federal networks and critical infrastructure may raise questions about its operational readiness during a period of reduced staffing.

Source: TechCrunch

This article was generated by AI and cites original sources.
Scroll to Top