The attacker used the stolen key to create a new access key, attached it to an existing IAM user, and began reconnaissance: listing IAM roles, enumerating S3 buckets, and describing EC2 instances.
It’s no secret that developers often inadvertently expose AWS access keys online and we know that these keys are being scraped and misused by attackers before organizations get a chance to revoke them ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results