Password spraying campaign targets AWS root user accounts across 150+ organizations
Datadog documents a password-spraying campaign hitting AWS root accounts across 150+ organisations — a reminder that the most privileged cloud identity is often the least protected.
Summary written by editorial AI · Source link below
Datadog Security Research observed a password spraying campaign attempting to authenticate as the AWS root user across more than 150 organizations.
Editorial Analysis
AWS root accounts carry unrestricted power and are frequently exempt from conditional-access policies; large-scale spraying campaigns exploit this systemic gap.
Enforce hardware MFA on every AWS root account, enable root-login CloudTrail alerts, and restrict root credentials to physical safes or secrets vaults.
Attackers are systematically spraying passwords against the most powerful AWS account type across hundreds of organisations — root-account MFA enforcement is non-negotiable.
Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.
External link — opens at Datadog Security Labs in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner2d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d