Incident report: stolen AWS access keys
ID: 22508c3f-912c-5332-80d2-f8345b7e16ff
STIX ID: report--22508c3f-912c-5332-80d2-f8345b7e16ff
Feed Name: Expel Blog
Date Published: 2023-01-06
Date Updated: 2026-04-27
Author: Myles Satterfield; Tyler Wood; Teauna Thompson; Tyler Collins; Ian Cooper; Nathan Sorrel
This report describes an incident where stolen long-term AWS access keys—discovered in a publicly exposed Postman project—were used from a hosting-provider IP and multiple access keys to access a customer’s AWS account, primarily targeting Amazon SES APIs; the SOC detected the activity via anomalous aws-cli user agents and IP enrichment, remediated by disabling keys and resetting credentials, and produced hunting/detection guidance (e.g., alert on multiple GetCallerIdentity calls from the same IP across different access keys and monitoring email-related API calls).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
