| I would normally say that "That must be a coincidence", but I had a client account compromise as well. And it was very strange: Client was a small org, and two very old IAM accounts had suddenly had recent (yesterday) console log ins and password changes. I'm investigating the extent of the compromise, but so far it seems all they did was open a ticket to turn on SES production access and increase the daily email limit to 50k. These were basically dormant IAM users from more than 5 years ago, and it's certainly odd timing that they'd suddenly pop on this particular day. |
Receive an email that says AWS is experiencing an outage. Log into your console to view the status, authenticate through a malicious wrapper, and compromise your account security.