81% of all breaches now originate from compromised credentials mainly acquired from 3rd party data breaches or data leaks. Most organizations believe that 2FA and SSO are the answer but this proves that 2FA/SSO are not enough.
Folks should be using short lived aws tokens to avoid the possibility of having tokens in source control: http://docs.aws.amazon.com/IAM/latest/UserGuide/id_credentia...
Along with never committing secrets to source control, implementing 3rd party data breach and data leak monitoring is necessary as recommended in NIST 800-63B