AWS Breach at a SaaS Company (Incident)
ID: 1856303b-a889-56b6-843a-74b707ee5c08
STIX ID: report--1856303b-a889-56b6-843a-74b707ee5c08
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2025-04-15
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
An attacker who obtained leaked AWS IAM keys with AdministratorAccess compromised a SaaS company's single-account AWS environment, exfiltrated data, deleted critical resources and backups, erased logs, and caused a week-long production outage; poor architectural choices (single account, internet-exposed RDS) and weak log protection enabled extensive lateral movement and undetected destructive activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
