frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Ask HN: Our AWS account got compromised after their outage

294•kinj28•16h ago•67 comments

Did people in the 90s worry about the efficiency of the internet

9•burgiee•8h ago•8 comments

Ask HN: What are people doing to get off of VMware?

188•jwithington•2d ago•162 comments

Ask HN: How to stop an AWS bot sending 2B requests/month?

282•lgats•5d ago•181 comments

HTTP error codes illustrated with stills from Columbo

8•ColinWright•17h ago•5 comments

Walrus: A High Performance Storage Engine built from first principles

8•nubskr•20h ago•0 comments

Claude output matching copyrighted StackOverflow code

4•randsp•22h ago•4 comments

Ask HN: How does one build large front end apps without a framework like React?

106•thepianodan•4d ago•186 comments

Ask HN: Why is Bowker's monopoly on ISBNs in the USA legal?

17•blindprogrammer•1d ago•12 comments

Programming language agnosticism is the only way to move forward in life

29•amano-kenji•3d ago•20 comments

Ask HN: What are you working on? (October 2025)

346•david927•1w ago•1049 comments

Warning: Gmail client Show Original can omit lines of the original

18•chrisjj•2d ago•2 comments

Ask HN: Abandoned/dead projects you think died before their time and why?

362•ofalkaed•1w ago•890 comments

Ask HN: Best way to make a documentation website for an open-source project?

5•mudge•2d ago•5 comments

Ask HN: Why isn't Amazon.com impacted by AWS outages?

5•trevoragilbert•1d ago•11 comments

Ask HN: DOS Based "Multitaskers"

5•alexshendi•3d ago•2 comments

Ask HN: Web app freezes, but not when Chrome is recording. How to debug?

6•febed•5d ago•2 comments

Ask HN: SQL using relational theory books?

6•shivajikobardan•3d ago•3 comments

Ask HN: Testing AST or assembly output for a compiler

2•backslash_16•1d ago•2 comments

Ask HN: Those who applied to the OpenAI Grove program, did you ever hear back?

23•heywoods•2d ago•8 comments

Ask HN: What level of news do you need and not need?

10•bwb•1d ago•12 comments

Ask HN: Is there an open source HN?

10•shafkathullah•2d ago•9 comments

Ask HN: New YouTube player not working in Firefox

3•gethly•1d ago•11 comments

Ask HN: I have a CS degree but taught for 5 years– how can I get back into tech?

4•padzochambers•1d ago•17 comments

Ask HN: Estimation of copyright material used by LLM

5•megamix•3d ago•8 comments

You've reached the end!

Open in hackernews

Ask HN: Our AWS account got compromised after their outage

292•kinj28•16h ago
Could there be any link between the two events?

Here is what happened:

Some 600 instances were spawned within 3 hours before AWS flagged it off and sent us a health event. There were numerous domains verified and we could see SES quota increase request was made.

We are still investigating the vulnerability at our end. our initial suspect list has 2 suspects. api key or console access where MFA wasn’t enabled.

Comments

bdcravens•16h ago
Any chance you did something crazy while troubleshooting downtime (before you knew it was an AWS issue)? I've had to deal with a similar situation, and in my case, I was lazy and pushed a key to a public repo. (Not saying you are, just saying in my case it was a leaked API key)
klysm•16h ago
Sounds like a coincidence to me
yfiapo•16h ago
Highly likely to be coincidence. Typically an exposed access key. Exposed password for non-MFA protected console access happens but is less common.
ThreatSystems•16h ago
Cloudtrail events should be able to demonstrate WHAT created the EC2s. Off the top of my head I think it's the runinstance event.
sylens•15h ago
RunInstances
ThreatSystems•15h ago
I'm officially off of AWS so don't have any consoles to check against, but back on a laptop.

Based on docs and some of the concerns about this happening to someone else, I would probably start with the following:

1. Check who/what created those EC2s[0] using the console to query: eventSource:ec2.amazonaws.com eventName:RunInstances

2. Based on the userIdentity field, query the following actions.

3. Check if someone manually logged into Console (identity dependent) [1]: eventSource:signin.amazonaws.com userIdentity.type:[Root/IAMUser/AssumedRole/FederatedUser/AWSLambda] eventName:ConsoleLogin

4. Check if someone authenticated against Security Token Service (STS) [2]: eventSource:sts.amazonaws.com eventName:GetSessionToken

5. Check if someone used a valid STS Session to AssumeRole: eventSource:sts.amazonaws.com eventName:AssumeRole userIdentity.arn (or other identifier)

6. Check for any new IAM Roles/Accounts made for persistence: eventSource:iam.amazonaws.com (eventName:CreateUser OR eventName:DeleteUser)

7. Check if any already vulnerable IAM Roles/Accounts modified to be more permissive [3]: eventSource:iam.amazonaws.com (eventName:CreateRole OR eventName:DeleteRole OR eventName:AttachRolePolicy OR eventName:DetachRolePolicy)

8. Check for any access keys made [4][5]: eventSource:iam.amazonaws.com (eventName:CreateAccessKey OR eventName:DeleteAccessKey)

9. Check if any production / persistent EC2s have had their IAMInstanceProfile changed, to allow for a backdoor using EC2 permissions from a webshell/backdoor they could have placed on your public facing infra. [6]

etc. etc.

But if you have had a compromise based on initial investigations, probably worth while getting professional support to do a thorough audit of your environment.

[0] https://docs.aws.amazon.com/awscloudtrail/latest/userguide/c...

[1] https://docs.aws.amazon.com/awscloudtrail/latest/userguide/c...

[2] https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-...

[3] https://docs.aws.amazon.com/awscloudtrail/latest/userguide/s...

[4] https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credenti...

[5] https://research.splunk.com/sources/0460f7da-3254-4d90-b8c0-...

[6] https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_R...

jinen83•13h ago
this is helpful. i will look for the logs.

Also some more observations below:

1) some 20 organisations were created within our Root all with email id with same domain (co.jp) 2) attacker had created multiple fargate templates 3) they created resources in 16-17 AWS regions 4) they requested to raise SES,WS Fargate Resource Rate Quota Change was requested, sage maker Notebook maintenance - we have no need of using these instances (recd an email from aws for all of this) 5) in some of the emails i started seeing a new name added (random name @outlook.com)

ThreatSystems•13h ago
It does sound like you've been compromised by an outfit that has got automation to run these types of activities across compromised accounts. A Reddit post[0] from 3 years ago seems to indicate similar activities.

Do what you can to triage and see what's happened. But I would strongly recommend getting a professional outfit in ASAP to remediate (if you have insurance notify them of the incident as well - as often they'll be able to offer services to support in remediating), as well as, notify AWS that an incident has occurred.

[0] https://www.reddit.com/r/aws/comments/119admy/300k_bill_afte...

sousastep•16h ago
couple folks on reddit said while they were refreshing during the outage, they were briefly logged in as a whole different user
afandian•15h ago
Got references? This is crazy.
blast•10h ago
I saw a link to https://old.reddit.com/r/webdev/comments/1obtbmg/aws_site_re... at one point but then it was deleted
duk3luk3•9h ago
This isn't about an aws account, this is about the auth inside the project that user is running.
perpil•9h ago
This is not about the AWS Console. It is talking about the customer's site hosted on CloudFront. It is possible to cross wires with user sessions when using CloudFront if you haven't set caching granular enough to be specific to an end user. This scenario is customer error, not AWS.
fulafel•1h ago
I'd argue it's a classic footgun and a flaw of CloudFront (they should at least warn about it much more).
__turbobrew__•15h ago
Maybe dynamodb was inconsistent for a period and as that backs IAM credentials were scrambled? Do you have references to this, because if it is true that is really really bad.
CaptainOfCoit•14h ago
> couple folks on reddit said while they were refreshing during the outage, they were briefly logged in as a whole different user

Didn't ChatGPT have a similar issue recently? Would sound awfully similar.

sunaookami•13h ago
Steam also had this, classic caching issue.
mbo•12h ago
This happened to me on Twitter maybe like, 9 years ago? What's the mechanism of action that causes this to happen?
howinator•10h ago
The easiest way to do this is to misconfigure your CDN so that it caches set-cookie headers.
liviux•14h ago
A friend of a friend knows a friend who logged in to Netflix root account. Source: trust me bro
gwbas1c•14h ago
Years ago I worked for a company where customers started seeing other customers' data.

The cause was a bad hire decided to do a live debugging session in the production environment. (I stress bad hire because after I interviewed them, my feedback was that we shouldn't hire them.)

It was kind of a mess to track down and clean up, too.

TZubiri•3h ago
A security incident like this would dwarf in comparision to partial unavailability of services.
itsnowandnever•15h ago
i cant imagine it's related. if it is related, hello Bloomberg News or whoever will be reading this thread because that would be a catastrophic breach of customer trust that would likely never fully return
jddj•14h ago
You say that, but azure and okta have had a handful of these and life over there has more or less gone on.

Inertia is a hell of a drug

testfrequency•9h ago
Similarly, everyone is back to using CS and their stock is just fine
timdev2•15h ago
I would normally say that "That must be a coincidence", but I had a client account compromise as well. And it was very strange:

Client was a small org, and two very old IAM accounts had suddenly had recent (yesterday) console log ins and password changes.

I'm investigating the extent of the compromise, but so far it seems all they did was open a ticket to turn on SES production access and increase the daily email limit to 50k.

These were basically dormant IAM users from more than 5 years ago, and it's certainly odd timing that they'd suddenly pop on this particular day.

tcdent•14h ago
Smells like a phishing attack to me.

Receive an email that says AWS is experiencing an outage. Log into your console to view the status, authenticate through a malicious wrapper, and compromise your account security.

SoftTalker•14h ago
Good point. Phishers would certainly take advantage of a widely reported outage to send emails related to "recovering your services."

Even cautious people are more vulnerable to phishing when the message aligns with their expectations and they are under pressure because services are down.

Always, always log in through bookmarked links or typing them manually. Never use a link in an email unless it's in direct response to something you initiated and even then examine it carefully.

roblabla•10h ago
You can also use phishing-resistant login/2FA like passkeys/FIDO keys, where it is available (and I'm pretty sure amazon supports it), to minimize the risk of accidentally login into a phishing website while under pressure.
SoftTalker•9h ago
They probably support it but how many accounts have not configured it? I'd bet it's a lot.
akerl_•9h ago
If my memory is correct, AWS supports FIDO for web login but not for the API, so you either have to restrict access to FIDO and then use the web UI for everything done as that user, or have a separate non-FIDO MFA device (without FIDO's phishing resistance) for terminal/API interactions.
jorvi•5h ago
You can generate temporary AWS keys for privileged users: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_credenti...

Of course, as always, PEBKAC. You will have to strictly follow protocol, and not every team is willing to jump through annoying hoops every day.

akerl_•5h ago
Can you actually generate temporary AWS STS credentials via FIDO MFA?

Again, last I looked, FIDO MFA credentials cannot be used for API calls, which you'd need to make for STS credential generation.

jorvi•5h ago
You don't put the temporary credentials behind FIDO because they're temporary anyway. You put FIDO on the main account that has the privilege to generate the temporary credentials.

So in the off chance that you get a phishing mail, you generate temporary credentials to take whatever actions it wants, attempt to log in with those credentials, get phished, but they only have access to API for 900s (or whatever you put as the timeout, 900s is just the minimum).

900s won't stop them from running amok, but it caps the amok at 900s.

akerl_•4h ago
You aren't grokking what I'm saying. AWS does not allow FIDO2 as an MFA method for API calls.

So if your MFA device for your main account is a FIDO2 device, you either:

1. Don't require MFA to generate temporary credentials. Congrats, your MFA is now basically theater.

2. Do require MFA to generate temporary credentials. Congrats, the only way to generate temporary credentials is to instead use a non-FIDO MFA device on the main account.

Nobody is getting a phishing email, going to the terminal, generating STS credentials, and then feeding those into the phish. The phish is punting them to a fake AWS webpage. Temporary credentials are a mitigation for session token theft, not for phishing.

computerfriend•2h ago
I think you're not grokking it.

Require FIDO2-based MFA to log into AWS via Identity Center, then run aws sso login to generate temporary credentials which will be granted only if the user can pass the FIDO2 challenge.

The literal API calls aren't requesting a FIDO2 challenge each time, just like the console doesn't require it for every action. It's session based.

plaidfuji•8h ago
What if the outage and phishing attack were coordinated at a higher level? There’s a scary thought.
BikiniPrince•8h ago
Bezos will get to Mars at any cost!
Scoundreller•8h ago
A phisher that did their homework would send out a tone deaf email with a subject line like this that aws sent me during their outage:

> You could win $5,000 in AWS credits at Innovate

timdev2•14h ago
These were accounts that shouldn't have had console access in the first place, and were never used by humans to log in AFAICT. I don't know exactly what they were originally for, but they were named like "foo-robots", were very old.

At first I thought maybe some previous dev had set passwords for troubleshooting, saved those passwords in a password manager, and then got owned all these years later. But that's really, really, unlikely. And the timing is so curious.

portaouflop•9h ago
Why keep accounts like this around anyway? Sounds like a breach was just waiting to happen…
Avicebron•9h ago
A cost center like security? Are you crazy..
highfrequencyy•6h ago
I second this, pretty much immediately after my organization got hit with a wave of phishing emails.
jbverschoor•1h ago
Or maybe it wasn't DNS, but they simply pulled the plug bc of some breach?
LeonardoTolstoy•7h ago
Almost this exact thing happened to me about a year ago. Very old account login, SES access with request to raise the email limit. We were only quickly tipped off because they had to open a ticket to get the limit raised.

If you haven't check newly made Roles as well. We quashed the compromised users pretty quickly (including my own, the origin we figured out), but got a little lucky because I just started cruising the Roles and killing anything less than a month old or with admin access.

To play devil's advocate a bit. In our case we are pretty sure my key actually did get compromised although we aren't precisely sure how (probably a combination of me being dumb and my org being dumb and some guy putting two and two together). But we did trace the initial users being created to nearly a month prior to the actual SES request. It is entirely possible whomever did your thing had you compromised for a bit, and then once AWS went down they decided that was the perfect time to attack, when you might not notice just-another-AWS-thing happening.

CaptainOfCoit•14h ago
Is it possible that people who already managed to get access (that they confirmed) has been waiting for any hiccups in AWS infrastructure in order to hide among the chaos when it happens? So maybe the access token was exposed weeks/months ago, but instead of going ahead directly, idle until there is something big going on.

Certainly feels like an strategy I'd explore if I was on that side of the aisle.

jinen83•13h ago
I am from the same team & i can concur with what you are saying. I did see a warning about the same key that was used in todays exploit about 2 years ago from some random person in an email. but there was no exploutation till yesterday.
LeonardoTolstoy•7h ago
This is it. I had the same thing happen to me a year ago and there was a month between the original access to our system and the attack. And similarly they waited until a perceived lull in what might be org diligence (just prior to thanksgiving) to attack.
iainctduncan•13h ago
Absolutely. I'm in diligence and we are hearing about attackers even laying the ground work and then waiting for company sales. The sophisticated ones are for sure smart enough to take advantage of this kind of thing and to even be prepping in advance and waiting for golden opportunities.
shadowpho•9h ago
Wouldn’t this be a terrible time because everyone is looking/logging into AWS?

If my company used AWS I would be hyper aware about anything that it’s doing right now

LorenPechtel•7h ago
I think the idea is that after an outage you would expect unusual patterns and thus not be sensitive to them.
AtNightWeCode•14h ago
Not uncommon that machines get exposed during trouble-shooting. Just look at the Crowdstrike incident just the other year. People enabled RDP on a lot machines to "implement the fix" and now many of these machines are more vulnerable than if if they never installed that garbage security software in the first place.
geor9e•14h ago
If I was a burgler holding a stolen key to a house, waiting to pick a good day, a city-wide blackout would probably feel like a good day.
what•9h ago
That’s likely a pretty bad day to burgle. People are probably going to be at home. You should wait for garbage day and see who hasn’t put their bins out.
bthrn•8h ago
This guy burgles
rcbdev•3h ago
Sir, you must be confused. This is not reddit.com.
brador•12h ago
Lot of keys and passwords being panic entered on insecure laptops yesterday.

Do not discount the possibility of regular malware.

tylergetsay•10h ago
Or the keys were long compromised and yesterday someone opened permissions on them in order to mitigate
uoflcards22•9h ago
https://www.reddit.com/r/webdev/comments/1obtbmg/aws_site_re...
•8h ago
kondro•9h ago
us-east-1 is unimaginably large. The last public info I saw said it had 159 datacenters. I wouldn't be surprised if many millions of accounts are primarily located there.

While this could possibly be related to the downtime, I think this is probably an unfortunate case of coincidence.

Scramblejams•3h ago
159! Staggering. Got a source?
kondro•3h ago
Sorry, 158: https://baxtel.com/data-center/aws-us-east-n-virginia
didip•8h ago
During time of panic, that’s when people are most vulnerable to phishing attacks.

Total password reset and tell your AWS representative. They usually let it slide on good faith.

mr_windfrog•3h ago
Considering AWS’s position as the No.1 cloud provider worldwide, their operational standards are extremely high. If something like this happened right after an outage, coincidence is the most plausible explanation rather than incompetence.
jmward01•3h ago
If I were an attacker I would choose when to attack and a major disruption happening leaving your logging is in chaos seems like it could be a good time. Is it possible you had been compromised for a while and they took that moment to take advantage of it? Or, similarly, they took that moment to use your resources for a different attack that was spurred by the outage?
defraudbah•1h ago
weird, can you send me your API key so I can verify it's not in the list of compromised credentials?