logo

Attackers are expanding access through Amazon Cognito

ID: 5571c9e8-c811-5005-8d13-870d03cff16a

STIX ID: report--5571c9e8-c811-5005-8d13-870d03cff16a

Feed Name: Expel Blog

Threat Score
70/100

Date Published: 2024-01-04

Date Updated: 2026-04-27

Author: Andrew Bentle; Tucker Moran

...
...

Expel observed attackers exploiting misconfigured Amazon Cognito deployments that exposed identity pool IDs and allowed token-exchange for temporary AWS credentials, enabling direct CLI/programmatic access to the AWS control plane; the report describes the attack flow, SOC findings (hundreds of API calls, attempts across ~50 services, many AccessDenied responses), detection indicators (Cognito-assumed role names, ASIA access key prefixes, unusual User-Agent values), and mitigations (harden Cognito IAM policies and avoid exposing identity pool IDs).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.