READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

CISA Admits It Had No Incident Response Playbook When a Contractor Exposed Government Credentials on GitHub

CISA Admits It Had No Incident Response Playbook When a Contractor Exposed Government Credentials on GitHub
The federal agency responsible for defending U.S. government networks had to write its own emergency response plan mid-crisis after a contractor employee posted sensitive credentials to a public GitHub repository. A journalist, not an internal process, caught the exposure. CISA has now published a postmortem acknowledging the gap.

The Agency That Protects Federal Networks Didn't Have a Plan for Its Own Breach

CISA, the Homeland Security unit charged with defending federal networks and helping protect critical infrastructure, published a postmortem report Friday acknowledging that when a May security incident hit, its staff had to build a response playbook during the incident itself.

It's one of the most basic tenets of cybersecurity: you write the playbook before the fire, not while your hands are burning.

How the Incident Unfolded

According to independent cybersecurity journalist Brian Krebs, a security researcher at cyber firm GitGuardian discovered reams of exposed passwords sitting in a publicly accessible GitHub repository. A CISA contractor employee had uploaded them.

The researcher tried to alert the contractor directly. No response. The contractor didn't act.

Krebs then contacted CISA. Only after that call did the agency take the repository offline and revoke and replace all the exposed credentials.

CISA confirmed in its postmortem that no customer or mission data was exposed, and credited both the researcher and Krebs for flagging the problem.

What CISA's Own Report Says

CISA said its channels for security researchers to report potential incidents were not well defined at the time. It has since made changes to streamline how researchers can contact the agency. The report also stated plainly that organizations should prepare playbooks for all anticipated needs rather than improvising in real time, a standard the agency itself failed to meet.

CISA did not disclose how long the missing playbook delayed its response. A spokesperson did not respond to TechCrunch's request for comment on that specific question.

The Broader Staffing Context

CISA has been operating without a permanent director since President Donald Trump's second term began in January 2025. Beyond the leadership vacuum, the agency has absorbed cuts, furloughs, and layoffs affecting roughly a third of its workforce since Trump took office, according to TechCrunch.

Critics of those cuts have argued that gutting CISA's headcount while the threat environment from China, Russia, and ransomware gangs remains at elevated levels is operationally reckless. The missing playbook, a basic administrative document, is the kind of thing that tends to fall through the cracks when an agency is running on reduced staff and interim leadership.

The Strongest Defense of the Current Situation

A fair counter-argument: no sensitive mission data was confirmed exposed. CISA moved quickly once notified, revoked all affected credentials, and published a public postmortem with specific corrective actions. Behavior that many agencies skip entirely. The fact that CISA is acknowledging the gap, naming the failure, and documenting reforms is more transparency than most federal bureaucracies offer after an embarrassing incident.

But it does not explain why an agency whose entire institutional purpose is cybersecurity readiness was caught without a cybersecurity incident response plan.

A Contractor Accountability Gap

The incident also surfaces an ongoing problem in federal contracting: a contractor employee posted credentials publicly, the contractor didn't respond when a researcher flagged it, and the whole chain collapsed until a journalist stepped in.

CISA's postmortem focused on the agency's own gaps, but the contractor's failure to respond to the initial researcher alert is unaddressed in what TechCrunch reported. Federal contractor accountability for basic security hygiene is a recurring weak point across agencies, and this incident illustrates exactly how that gap plays out in practice.

What Happens Next

CISA says it has improved its researcher-contact channels and will prioritize building playbooks ahead of anticipated incidents. What remains unanswered is whether the agency's staffing level, reduced by roughly a third, is adequate to execute that kind of systematic preparedness work, and whether the absence of a permanent director is contributing to the administrative gaps the postmortem identified. Until a director is confirmed and the workforce picture stabilizes, those questions stay open.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchUS cybersecurity agency CISA had to build its incident playbook during the incident, agency reveals