
An extortion group called Icarus reportedly broke into Klue’s systems using a credential issued back in 2022, exposing keys to customers’ cloud services and enabling data theft for extortion.
In the cloud, identity is the perimeter — a single leaked or stale key can be escalated into control of an entire environment.
Our analysis
The real story is not a zero-day — it is a governance failure. A 2022 credential still working in 2026 tells you everything: stale, long-lived, over-privileged credentials are the most common and least glamorous way cloud environments fall. Once inside, extortion crews head straight for customer keys because that maximises leverage. This is a preventable class of breach, and it is squarely within your control.
What you should do
- Rotate credentials on a schedule and replace long-lived static keys with short-lived tokens.
- Enforce least privilege and review IAM for unused or over-scoped access.
- Monitor for anomalous use of old credentials and impossible-travel sign-ins.
- Run periodic cloud configuration reviews and assumed-breach tests to find these paths before attackers do.
How AgentOffense helps: our cloud configuration review and AWS penetration testing map the privilege paths a stale credential could take, while an assumed breach assessment quantifies the blast radius.
Source: TechCrunch.
How one stale credential becomes total access
Cloud breaches rarely start with a zero-day. They start with a credential — leaked in an old breach, committed to a repo, or left in a config — that was never rotated. Once inside, attackers exploit over-broad IAM permissions to move from a single identity to the entire account: reading data, creating new access, and disabling logging.
The lesson is that identity, not the network perimeter, is the real boundary in the cloud. Least-privilege and ruthless credential rotation are what shrink the blast radius when — not if — a key leaks.
What this means for your business
A years-old credential breaching a cloud provider in 2026 is a stark lesson: stale, un-rotated keys are a standing invitation. In the cloud, one leaked credential often equals full account access because of over-broad permissions.
How to reduce your exposure
- Rotate credentials and keys on a schedule; kill long-lived static secrets.
- Apply least-privilege IAM and remove unused roles and access.
- Enforce MFA everywhere and monitor for anomalous credential use.
- Audit your cloud configuration against real attack paths.
Find over-permissive access before attackers do with cloud configuration review and identity & access testing — get a fixed-price quote.