The US federal cybersecurity agency, CISA, has admitted it lacked a prepared response plan when an investigative reporter alerted the organisation in May to a contractor’s public exposure of sensitive government login credentials.
An Unprepared Defence: Building the Playbook on the Fly
CISA, the Homeland Security unit responsible for defending federal networks and safeguarding critical infrastructure, revealed on Friday in a postmortem report that its staff had to build an incident playbook from scratch during the early stages of the breach. The agency emphasised the critical importance of preparing response strategies for all anticipated scenarios beforehand, rather than scrambling to improvise under pressure during an active security event.
It remains unclear how much this lack of preparation delayed CISA’s response, as a spokesperson did not immediately respond to requests for comment.
How the GitHub Leak Was Discovered
The security failure came to light after independent cybersecurity journalist Brian Krebs reported in May that a security researcher with the cyber firm GitGuardian had discovered numerous exposed passwords. These credentials had been uploaded to a public GitHub repository by an employee working for a CISA contractor.
The Escalation Process
According to Krebs, the researcher initially attempted to alert the contractor directly but received no response. The repository was only taken offline, and the exposed credentials revoked and replaced, after Krebs escalated the matter directly to CISA to prevent potential exploitation.
CISA confirmed that no customer or mission-critical data was compromised during the incident. While expressing gratitude to both the researcher and the reporter, the agency acknowledged that its channels for receiving external vulnerability reports were not well-defined, promising that updates have since been implemented to streamline this communication process.
Systemic Vulnerabilities and Workforce Cuts
This operational lapse coincides with a period of significant instability for the agency. CISA has operated without a permanent director since the start of President Donald Trump’s second term in January 2025. Furthermore, the organisation has been severely impacted by budget cuts, furloughs, and layoffs, which have affected approximately a third of its workforce since the administration took office.
